Linux

Linux Kernel

12152 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Published 22.03.2006 20:06:00
  • Last modified 03.04.2025 01:03:51

Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.

  • EPSS 0.17%
  • Published 21.03.2006 18:02:00
  • Last modified 03.04.2025 01:03:51

net/ipv4/af_inet.c in Linux kernel 2.4 does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the (1) getsockname, (2) getpeername, and (3) accept functions, which allows local users to obtain portions of potentially sensitive me...

  • EPSS 0.1%
  • Published 21.03.2006 18:02:00
  • Last modified 03.04.2025 01:03:51

net/ipv4/netfilter/ip_conntrack_core.c in Linux kernel 2.4 and 2.6, and possibly net/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c in 2.6, does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the getsockopt function with SO_ORIGIN...

  • EPSS 3.04%
  • Published 15.03.2006 17:06:00
  • Last modified 03.04.2025 01:03:51

The ip_push_pending_frames function in Linux 2.4.x and 2.6.x before 2.6.16 increments the IP ID field when sending a RST after receiving unsolicited TCP SYN-ACK packets, which allows remote attackers to conduct an Idle Scan (nmap -sI) attack, which b...

  • EPSS 1.5%
  • Published 14.03.2006 02:02:00
  • Last modified 03.04.2025 01:03:51

Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time t...

  • EPSS 0.08%
  • Published 12.03.2006 21:02:00
  • Last modified 03.04.2025 01:03:51

sys_mbind in mempolicy.c in Linux kernel 2.6.16 and earlier does not sanity check the maxnod variable before making certain computations for the get_nodes function, which has unknown impact and attack vectors.

  • EPSS 0.06%
  • Published 09.03.2006 13:06:00
  • Last modified 03.04.2025 01:03:51

The die_if_kernel function in arch/ia64/kernel/unaligned.c in Linux kernel 2.6.x before 2.6.15.6, possibly when compiled with certain versions of gcc, has the "noreturn" attribute set, which allows local users to cause a denial of service by causing ...

  • EPSS 0.11%
  • Published 07.03.2006 02:02:00
  • Last modified 03.04.2025 01:03:51

Linux kernel 2.6 before 2.6.15.5 allows local users to obtain sensitive information via a crafted XFS ftruncate call, which may return stale data.

  • EPSS 0.1%
  • Published 07.03.2006 02:02:00
  • Last modified 03.04.2025 01:03:51

The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).

  • EPSS 0.09%
  • Published 07.03.2006 02:02:00
  • Last modified 03.04.2025 01:03:51

Linux kernel before 2.6.15.5, when running on Intel processors, allows local users to cause a denial of service ("endless recursive fault") via unknown attack vectors related to a "bad elf entry address."