imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2022-1116
Alta 7.8

Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions.

linux linux_kernel · netapp h300s_firmware · netapp h410s_firmware · netapp h500s_firmware · e altri 1
0.01EPSS
CVE-2016-5243
Media 5.5

The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.

linux linux_kernel
0.01EPSS
CVE-2016-2550
Media 5.5

The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging incorrect tracking of descriptor ownership and sending each descriptor over a UNIX socket before closing it. NOTE: …

linux linux_kernel
0.01EPSS
CVE-2013-4513
Media 4.9

Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted write operation.

linux linux_kernel
0.01EPSS
CVE-2011-2700
Bassa 2.1

Multiple buffer overflows in the si4713_write_econtrol_string function in drivers/media/radio/si4713-i2c.c in the Linux kernel before 2.6.39.4 on the N900 platform might allow local users to cause a denial of service or have unspecified other impact via a craf…

linux linux_kernel
0.01EPSS
CVE-2005-0180
Bassa 3.6

Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy…

linux linux_kernel
0.01EPSS
CVE-2023-53116
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid potential UAF in nvmet_req_complete() An nvme target ->queue_response() operation implementation may free the request passed as argument. Such implementation potentially could r…

linux linux_kernel
0.01EPSS
CVE-2022-48711
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: tipc: improve size validations for received domain records The function tipc_mon_rcv() allows a node to receive and process domain_record structs from peer nodes to track their views of the …

linux linux_kernel
0.01EPSS
CVE-2018-6554
Media 5.5

Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (memory consumption) by repeatedly binding an AF_IRDA socket.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2011-2928
Media 4.9

The befs_follow_link function in fs/befs/linuxvfs.c in the Linux kernel before 3.1-rc3 does not validate the length attribute of long symlinks, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) by accessing a long s…

linux linux_kernel
0.01EPSS
CVE-2010-2960
Alta 7.8

The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or …

canonical ubuntu_linux · linux linux_kernel · suse suse_linux_enterprise_desktop · suse suse_linux_enterprise_server
0.01EPSS
CVE-2009-3638
Alta 7.2

Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl f…

linux linux_kernel
0.01EPSS
CVE-2008-1294
Bassa 2.1

Linux kernel 2.6.17, and other versions before 2.6.22, does not check when a user attempts to set RLIMIT_CPU to 0 until after the change is made, which allows local users to bypass intended resource limits.

linux linux_kernel
0.01EPSS
CVE-2025-39682
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next recor…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2018-25020
Alta 7.8

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c…

linux linux_kernel · netapp cloud_backup · netapp h300e_firmware · netapp h300s_firmware · e altri 6
0.01EPSS
CVE-2014-5472
Media 4.0

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.

linux linux_kernel
0.01EPSS
CVE-2014-5471
Media 4.0

Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 ima…

linux linux_kernel
0.01EPSS
CVE-2012-3510
Media 5.6

Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKST…

linux linux_kernel
0.01EPSS
CVE-2022-48673
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix possible access to freed memory in link clear After modifying the QP to the Error state, all RX WR would be completed with WC in IB_WC_WR_FLUSH_ERR status. Current implementatio…

linux linux_kernel
0.01EPSS
CVE-2022-40133
Media 6.3

A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account o…

linux linux_kernel
0.01EPSS
CVE-2019-19535
Media 4.6

In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_fd.c driver, aka CID-30a8beeb3042.

debian debian_linux · linux linux_kernel · opensuse leap · oracle sd-wan_edge
0.01EPSS
CVE-2019-19532
Media 6.8

In the Linux kernel before 5.3.9, there are multiple out-of-bounds write bugs that can be caused by a malicious USB device in the Linux kernel HID drivers, aka CID-d9d4b1e46d95. This affects drivers/hid/hid-axff.c, drivers/hid/hid-dr.c, drivers/hid/hid-emsff.c…

linux linux_kernel
0.01EPSS
CVE-2018-5873
Alta 7.0

An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Andr…

google android · linux linux_kernel
0.01EPSS
CVE-2015-8970
Media 5.5

crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference a…

linux linux_kernel
0.01EPSS
CVE-2008-5029
Media 4.9

The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sen…

linux linux_kernel
0.01EPSS