CVE-2021-3564
- EPSS 0.03%
- Veröffentlicht 08.06.2021 12:15:11
- Zuletzt bearbeitet 21.11.2024 06:21:51
A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux ke...
CVE-2020-36386
- EPSS 0.23%
- Veröffentlicht 07.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:23
An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf.
CVE-2020-36387
- EPSS 0.06%
- Veröffentlicht 07.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:23
An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_func and ctx reference holding, aka CID-6d816e088c35.
CVE-2018-25015
- EPSS 0.07%
- Veröffentlicht 07.06.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 04:03:21
An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8.
CVE-2019-25045
- EPSS 0.07%
- Veröffentlicht 07.06.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:49
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
CVE-2020-36385
- EPSS 0.06%
- Veröffentlicht 07.06.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:22
An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.
CVE-2021-3489
- EPSS 0.08%
- Veröffentlicht 04.06.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:39
The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code executio...
CVE-2021-3490
- EPSS 3.7%
- Veröffentlicht 04.06.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:39
The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This is...
CVE-2021-3491
- EPSS 0.06%
- Veröffentlicht 04.06.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:40
The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used to create a heap overflow lea...
- EPSS 0.05%
- Veröffentlicht 02.06.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 04:55:58
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat fro...