CVE-2019-7308
- EPSS 0.03%
- Published 01.02.2019 22:29:00
- Last modified 21.11.2024 04:47:58
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel a...
CVE-2016-10741
- EPSS 0.07%
- Published 01.02.2019 16:29:00
- Last modified 21.11.2024 02:44:38
In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of ...
CVE-2017-18360
- EPSS 0.08%
- Published 31.01.2019 09:29:00
- Last modified 21.11.2024 03:19:55
In change_port_settings in drivers/usb/serial/io_ti.c in the Linux kernel before 4.11.3, local users could cause a denial of service by division-by-zero in the serial device layer by trying to set very high baud rates.
- EPSS 0.08%
- Published 29.01.2019 16:29:00
- Last modified 21.11.2024 03:53:31
A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory co...
CVE-2019-3819
- EPSS 0.01%
- Published 25.01.2019 18:29:00
- Last modified 21.11.2024 04:42:36
A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up...
CVE-2019-5489
- EPSS 0.21%
- Published 07.01.2019 17:29:00
- Last modified 21.11.2024 04:45:02
The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this af...
CVE-2018-16882
- EPSS 0.11%
- Published 03.01.2019 16:29:00
- Last modified 21.11.2024 03:53:31
A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmap...
CVE-2018-16885
- EPSS 0.1%
- Published 03.01.2019 16:29:00
- Last modified 21.11.2024 03:53:31
A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault...
CVE-2019-3701
- EPSS 0.05%
- Published 03.01.2019 16:29:00
- Last modified 21.11.2024 04:42:21
An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_AD...
CVE-2018-20511
- EPSS 0.08%
- Published 27.12.2018 14:29:00
- Last modified 21.11.2024 04:01:38
An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next f...