- EPSS 0.13%
- Veröffentlicht 18.12.2018 22:29:04
- Zuletzt bearbeitet 21.11.2024 03:53:31
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container ...
CVE-2018-20169
- EPSS 0.1%
- Veröffentlicht 17.12.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:00
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
CVE-2018-18397
- EPSS 0.07%
- Veröffentlicht 12.12.2018 10:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:52
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that fil...
CVE-2018-9568
- EPSS 0.47%
- Veröffentlicht 06.12.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:15:43
In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Androi...
CVE-2018-19854
- EPSS 0.09%
- Veröffentlicht 04.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:41
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sens...
CVE-2018-19824
- EPSS 0.06%
- Veröffentlicht 03.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:37
In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c.
CVE-2018-14646
- EPSS 0.04%
- Veröffentlicht 26.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:29
The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the net/netlink/af_netlink.c file. A local attacker could exploit this when a net namespace with a netnsid is assi...
CVE-2018-16862
- EPSS 0.03%
- Veröffentlicht 26.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data ...
CVE-2018-19406
- EPSS 0.11%
- Veröffentlicht 21.11.2018 00:29:01
- Zuletzt bearbeitet 21.11.2024 03:57:51
kvm_pv_send_ipi in arch/x86/kvm/lapic.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where the apic map is uninitialized.
CVE-2018-19407
- EPSS 0.08%
- Veröffentlicht 21.11.2018 00:29:01
- Zuletzt bearbeitet 21.11.2024 03:57:51
The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where ioapic is uninitialized.