- EPSS 0.06%
- Veröffentlicht 03.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:58
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kerne...
CVE-2022-0492
- EPSS 5.52%
- Veröffentlicht 03.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:46
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the...
CVE-2021-3772
- EPSS 0.16%
- Veröffentlicht 02.03.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:23
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP ad...
CVE-2021-3715
- EPSS 0.04%
- Veröffentlicht 02.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:13
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local user...
CVE-2020-36516
- EPSS 0.04%
- Veröffentlicht 26.02.2022 04:15:06
- Zuletzt bearbeitet 21.11.2024 05:29:43
An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.
CVE-2022-25636
- EPSS 0.37%
- Veröffentlicht 24.02.2022 15:15:31
- Zuletzt bearbeitet 21.11.2024 06:52:29
net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.
CVE-2022-25375
- EPSS 0.71%
- Veröffentlicht 20.02.2022 20:15:18
- Zuletzt bearbeitet 21.11.2024 06:52:06
An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.
CVE-2022-0646
- EPSS 0.11%
- Veröffentlicht 18.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:39:06
A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to crash the s...
CVE-2021-4090
- EPSS 0.06%
- Veröffentlicht 18.02.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:36:52
An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain acc...
CVE-2021-4093
- EPSS 0.09%
- Veröffentlicht 18.02.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:36:53
A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instru...