CVE-2021-45485
- EPSS 0.44%
- Veröffentlicht 25.12.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:32:18
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among ma...
CVE-2021-45486
- EPSS 0.02%
- Veröffentlicht 25.12.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:32:18
In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small.
CVE-2021-45480
- EPSS 0.04%
- Veröffentlicht 24.12.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:17
An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances.
CVE-2021-45469
- EPSS 0.07%
- Veröffentlicht 23.12.2021 19:15:12
- Zuletzt bearbeitet 21.11.2024 06:32:16
In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.
- EPSS 0.26%
- Veröffentlicht 22.12.2021 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:31:28
A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.
CVE-2021-45095
- EPSS 0.04%
- Veröffentlicht 16.12.2021 04:15:06
- Zuletzt bearbeitet 21.11.2024 06:31:56
pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.
CVE-2021-0920
- EPSS 0.91%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 23.10.2025 14:53:26
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVE-2018-25020
- EPSS 0.16%
- Veröffentlicht 08.12.2021 05:15:07
- Zuletzt bearbeitet 21.11.2024 04:03:22
The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/...
CVE-2021-43975
- EPSS 0.02%
- Veröffentlicht 17.11.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:07
In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value.
CVE-2021-43976
- EPSS 0.05%
- Veröffentlicht 17.11.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:07
In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).