imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2024-53185
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix NULL ptr deref in crypto_aead_setkey() Neither SMB3.0 or SMB3.02 supports encryption negotiate context, so when SMB2_GLOBAL_CAP_ENCRYPTION flag is set in the negotiate respo…

linux linux_kernel
0.00EPSS
CVE-2024-50085
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow Syzkaller reported this splat: ================================================================== BUG: KASAN: slab-use-after-fr…

linux linux_kernel
0.00EPSS
CVE-2020-11669
Media 5.5

An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does not have save/restore functionality for PNV_POWERSAVE_AMR, PNV_POWERSAVE_UAMOR, and PNV_POWERSAVE_AMOR, aka CID-53a712bae5dd.

linux linux_kernel · opensuse leap · redhat enterprise_linux
0.00EPSS
CVE-2013-7339
Media 4.7

The rds_ib_laddr_check function in net/rds/ib.c in the Linux kernel before 3.12.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on …

linux linux_kernel
0.00EPSS
CVE-2013-4512
Media 4.7

Buffer overflow in the exitcode_proc_write function in arch/um/kernel/exitcode.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging root privileges for a write operation.

linux linux_kernel
0.00EPSS
CVE-2006-6921
Bassa 2.1

Unspecified versions of the Linux kernel allow local users to cause a denial of service (unrecoverable zombie process) via a program with certain instructions that prevent init from properly reaping a child whose parent has died.

linux linux_kernel
0.00EPSS
CVE-2006-1862
Media 4.9

The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.

linux linux_kernel
0.00EPSS
CVE-2011-4917
Media 5.5

In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.

linux linux_kernel
0.00EPSS
CVE-2021-43057
Alta 7.8

An issue was discovered in the Linux kernel before 5.14.8. A use-after-free in selinux_ptrace_traceme (aka the SELinux handler for PTRACE_TRACEME) could be used by local attackers to cause memory corruption and escalate privileges, aka CID-a3727a8bac0a. This o…

linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · netapp h410c_firmware · e altri 5
0.00EPSS
CVE-2016-2053
Media 4.7

The asn1_ber_decoder function in lib/asn1_decoder.c in the Linux kernel before 4.3 allows attackers to cause a denial of service (panic) via an ASN.1 BER file that lacks a public key, leading to mishandling by the public_key_verify_signature function in crypto…

linux linux_kernel
0.00EPSS
CVE-2013-6432
Media 4.6

The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging un…

linux linux_kernel
0.00EPSS
CVE-2021-47448
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix possible stall on recvmsg() recvmsg() can enter an infinite loop if the caller provides the MSG_WAITALL, the data present in the receive queue is not sufficient to fulfill the req…

linux linux_kernel
0.00EPSS
CVE-2023-30456
Media 6.5

An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.

linux linux_kernel
0.00EPSS
CVE-2017-18222
Alta 7.8

In the Linux kernel before 4.12, Hisilicon Network Subsystem (HNS) does not consider the ETH_SS_PRIV_FLAGS case when retrieving sset_count data, which allows local users to cause a denial of service (buffer overflow and memory corruption) or possibly have unsp…

linux linux_kernel
0.00EPSS
CVE-2017-12153
Media 4.4

A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be issued by a…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2011-2208
Bassa 2.1

Integer signedness error in the osf_getdomainname function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call.

linux linux_kernel
0.00EPSS
CVE-2008-3686
Media 4.9

The rt6_fill_node function in net/ipv6/route.c in Linux kernel 2.6.26-rc4, 2.6.26.2, and possibly other 2.6.26 versions, allows local users to cause a denial of service (kernel OOPS) via IPv6 requests when no IPv6 input device is in use, which triggers a NULL …

linux linux_kernel
0.00EPSS
CVE-2005-0530
Bassa 2.1

Signedness error in the copy_from_read_buf function in n_tty.c for Linux kernel 2.6.10 and 2.6.11rc1 allows local users to read kernel memory via a negative argument.

linux linux_kernel
0.00EPSS
CVE-2024-50241
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure the refcount and async_copies fields are initialized early. cleanup_async_copy() will reference these fields if an error occurs in nfsd4_cop…

linux linux_kernel
0.00EPSS
CVE-2019-19067
Media 4.4

Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failu…

canonical ubuntu_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2009-2849
Media 4.7

The md driver (drivers/md/md.c) in the Linux kernel before 2.6.30.2 might allow local users to cause a denial of service (NULL pointer dereference) via vectors related to "suspend_* sysfs attributes" and the (1) suspend_lo_store or (2) suspend_hi_store functio…

linux linux_kernel
0.00EPSS
CVE-2009-1242
Media 4.9

The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bi…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 1
0.00EPSS
CVE-2023-35829
Alta 7.0

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c.

linux linux_kernel · netapp h300s · netapp h410s · netapp h500s · e altri 1
0.00EPSS
CVE-2021-34693
Media 5.5

net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-8068
Alta 7.8

drivers/net/usb/pegasus.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by le…

linux linux_kernel
0.00EPSS