Linux

Linux Kernel

12162 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 29.08.2011 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE in...

  • EPSS 2.79%
  • Veröffentlicht 29.08.2011 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small comman...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 29.08.2011 17:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The befs_follow_link function in fs/befs/linuxvfs.c in the Linux kernel before 3.1-rc3 does not validate the length attribute of long symlinks, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) by accessin...

  • EPSS 0.1%
  • Veröffentlicht 28.07.2011 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arra...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 28.07.2011 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple off-by-one errors in the ext4 subsystem in the Linux kernel before 3.0-rc5 allow local users to cause a denial of service (BUG_ON and system crash) by accessing a sparse file in extent format with a write operation involving a block number c...

  • EPSS 0.06%
  • Veröffentlicht 28.07.2011 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to ...

  • EPSS 0.11%
  • Veröffentlicht 18.07.2011 22:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the start_code and end_code fields in ...

  • EPSS 1.22%
  • Veröffentlicht 18.07.2011 22:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause...

  • EPSS 0.05%
  • Veröffentlicht 18.07.2011 19:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool i...

  • EPSS 0.05%
  • Veröffentlicht 18.07.2011 19:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gai...