imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2011-2493
Bassa 2.1

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel before 2.6.39 does not properly initialize a certain error-report data structure, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext4 filesystem.…

linux linux_kernel
0.00EPSS
CVE-2026-45898
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removing work_list The commit e1168f0 ("RDMA/iwcm: Simplify cm_event_handler()") changed the work submission logic to unconditionally call queue_w…

linux linux_kernel
0.00EPSS
CVE-2024-56718
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: net/smc: protect link down work from execute after lgr freed link down work may be scheduled before lgr freed but execute after lgr freed, which may result in crash. So it is need to hold a …

linux linux_kernel
0.00EPSS
CVE-2023-33952
Media 6.7

A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which ma…

linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_for_real_time · redhat enterprise_linux_for_real_time_for_nfv
0.00EPSS
CVE-2017-10662
Alta 7.8

The sanity_check_raw_super function in fs/f2fs/super.c in the Linux kernel before 4.11.1 does not validate the segment count, which allows local users to gain privileges via unspecified vectors.

linux linux_kernel
0.00EPSS
CVE-2016-8645
Media 5.5

The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of service (system crash) via a crafted application that makes sendto system calls, related to net/ipv4/tcp_ipv4.c and net/ipv6/tcp_ipv6.c.

linux linux_kernel
0.00EPSS
CVE-2006-0744
Media 4.9

Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong …

linux linux_kernel
0.00EPSS
CVE-2024-36962
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Queue RX packets in IRQ handler instead of disabling BHs Currently the driver uses local_bh_disable()/local_bh_enable() in its IRQ handler to avoid triggering net_rx_action() so…

linux linux_kernel
0.00EPSS
CVE-2021-3847
Alta 7.8

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate thei…

fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2019-15090
Media 6.7

An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.

canonical ubuntu_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2019-12382
Media 5.5

An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5. There is an unchecked kstrdup of fwstr, which might allow an attacker to cause a denial of service (NULL pointer dereference and system cras…

linux linux_kernel
0.00EPSS
CVE-2007-6761
Alta 7.8

drivers/media/video/videobuf-vmalloc.c in the Linux kernel before 2.6.24 does not initialize videobuf_mapping data structures, which allows local users to trigger an incorrect count value and videobuf leak via unspecified vectors, a different vulnerability tha…

linux linux_kernel
0.00EPSS
CVE-2015-5697
Bassa 2.1

The get_bitmap_file function in drivers/md/md.c in the Linux kernel before 4.1.6 does not initialize a certain bitmap data structure, which allows local users to obtain sensitive information from kernel memory via a GET_BITMAP_FILE ioctl call.

linux linux_kernel
0.00EPSS
CVE-2026-64232
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings rela…

linux linux_kernel
0.00EPSS
CVE-2026-43233
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() In decode_choice(), the boundary check before get_len() uses the variable `len`, which is still 0 from its initialization at the…

linux linux_kernel
0.00EPSS
CVE-2026-43190
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without valid…

linux linux_kernel
0.00EPSS
CVE-2025-21955
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent connection release during oplock break notification ksmbd_work could be freed when after connection release. Increment r_count of ksmbd_conn to indicate that requests are not …

linux linux_kernel
0.00EPSS
CVE-2025-21954
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently on stable trees we have support for netmem/devmem RX but not TX. It is not safe to forward/redirect an RX unreadable netmem packet into the de…

linux linux_kernel
0.00EPSS
CVE-2025-21946
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds in parse_sec_desc() If osidoffset, gsidoffset and dacloffset could be greater than smb_ntsd struct size. If it is smaller, It could cause slab-out-of-bounds. And whe…

linux linux_kernel
0.00EPSS
CVE-2024-49855
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: nbd: fix race between timeout and normal completion If request timetout is handled by nbd_requeue_cmd(), normal completion has to be stopped for avoiding to complete this requeued request, o…

linux linux_kernel
0.00EPSS
CVE-2022-3643
Media 6.5

Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption in the rest…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2022-3586
Media 5.5

A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unpr…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2011-1012
Media 4.9

The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a denial of service (divide-by-zero error and…

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2006-6054
Media 4.0

The ext2 file system code in Linux kernel 2.6.x allows local users to cause a denial of service (crash) via an ext2 stream with malformed data structures that triggers an error in the ext2_check_page due to a length that is smaller than the minimum.

linux linux_kernel
0.00EPSS
CVE-2025-21927
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu() nvme_tcp_recv_pdu() doesn't check the validity of the header length. When header digests are enabled, a target might send a p…

linux linux_kernel
0.00EPSS