CVE-2015-8830
- EPSS 0.05%
- Published 02.05.2016 10:59:20
- Last modified 12.04.2025 10:46:40
Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec. NOTE: this vulnerability exists because of ...
CVE-2015-8746
- EPSS 1.87%
- Published 02.05.2016 10:59:19
- Last modified 12.04.2025 10:46:40
fs/nfs/nfs4proc.c in the NFS client in the Linux kernel before 4.2.2 does not properly initialize memory for migration recovery operations, which allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) via crafted ...
CVE-2015-8324
- EPSS 0.08%
- Published 02.05.2016 10:59:18
- Last modified 12.04.2025 10:46:40
The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a craft...
CVE-2015-8019
- EPSS 0.05%
- Published 02.05.2016 10:59:17
- Last modified 12.04.2025 10:46:40
The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified oth...
CVE-2015-4178
- EPSS 0.04%
- Published 02.05.2016 10:59:16
- Last modified 12.04.2025 10:46:40
The fs_pin implementation in the Linux kernel before 4.0.5 does not ensure the internal consistency of a certain list data structure, which allows local users to cause a denial of service (system crash) by leveraging user-namespace root access for an...
CVE-2015-4177
- EPSS 0.04%
- Published 02.05.2016 10:59:15
- Last modified 12.04.2025 10:46:40
The collect_mounts function in fs/namespace.c in the Linux kernel before 4.0.5 does not properly consider that it may execute after a path has been unmounted, which allows local users to cause a denial of service (system crash) by leveraging user-nam...
CVE-2015-4176
- EPSS 0.05%
- Published 02.05.2016 10:59:13
- Last modified 12.04.2025 10:46:40
fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory.
CVE-2015-4170
- EPSS 0.06%
- Published 02.05.2016 10:59:12
- Last modified 12.04.2025 10:46:40
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread...
CVE-2015-2686
- EPSS 0.04%
- Published 02.05.2016 10:59:11
- Last modified 12.04.2025 10:46:40
net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom system calls, which allows local users to gain privileges by leveraging a subsystem that uses the copy_from_iter function in the ...
CVE-2015-2672
- EPSS 0.04%
- Published 02.05.2016 10:59:10
- Last modified 12.04.2025 10:46:40
The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and consequently does not provide any protection against instruction faulting, which allows local users t...