CVE-2024-22099
- EPSS 0.06%
- Veröffentlicht 25.01.2024 07:15:08
- Zuletzt bearbeitet 05.06.2025 20:15:24
NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kerne...
CVE-2024-22705
- EPSS 0.02%
- Veröffentlicht 23.01.2024 11:15:09
- Zuletzt bearbeitet 05.06.2025 20:15:25
An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mish...
CVE-2023-51042
- EPSS 0.03%
- Veröffentlicht 23.01.2024 11:15:08
- Zuletzt bearbeitet 21.11.2024 08:37:45
In the Linux kernel before 6.4.12, amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free.
- EPSS 0.01%
- Veröffentlicht 23.01.2024 11:15:08
- Zuletzt bearbeitet 21.11.2024 08:37:45
In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload.
CVE-2023-46343
- EPSS 0.01%
- Veröffentlicht 23.01.2024 10:15:10
- Zuletzt bearbeitet 17.06.2025 14:15:27
In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.
CVE-2024-23849
- EPSS 0.02%
- Veröffentlicht 23.01.2024 09:15:36
- Zuletzt bearbeitet 04.11.2025 19:16:54
In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access.
CVE-2024-23850
- EPSS 0.04%
- Veröffentlicht 23.01.2024 09:15:36
- Zuletzt bearbeitet 04.11.2025 19:16:55
In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation.
CVE-2024-23851
- EPSS 0.03%
- Veröffentlicht 23.01.2024 09:15:36
- Zuletzt bearbeitet 04.11.2025 19:16:55
copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, and crash, because of a missing param_kernel->data_size check. This is related to ctl_ioctl.
CVE-2024-23848
- EPSS 0.01%
- Veröffentlicht 23.01.2024 09:15:35
- Zuletzt bearbeitet 30.05.2025 15:15:38
In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.
CVE-2023-39197
- EPSS 0.04%
- Veröffentlicht 23.01.2024 03:15:11
- Zuletzt bearbeitet 21.11.2024 08:14:53
An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information via the DCCP protocol.