Linux

Linux Kernel

14023 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 08.02.2016 03:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_v...

  • EPSS 0.03%
  • Veröffentlicht 08.02.2016 03:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Linux kernel before 4.4.1 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by sending each descriptor over a UNIX socket before closing it, related to net/unix/af_unix.c and net/unix/garbage.c...

  • EPSS 63.46%
  • Veröffentlicht 28.12.2015 11:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via...

  • EPSS 0.02%
  • Veröffentlicht 28.12.2015 11:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection ...

  • EPSS 2.04%
  • Veröffentlicht 28.12.2015 11:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users to cause a denial of service (NULL function pointer...

  • EPSS 0.04%
  • Veröffentlicht 28.12.2015 11:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.

  • EPSS 0.04%
  • Veröffentlicht 28.12.2015 11:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket t...

  • EPSS 0.09%
  • Veröffentlicht 28.12.2015 11:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

  • EPSS 0.04%
  • Veröffentlicht 28.12.2015 11:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted applic...

  • EPSS 0.08%
  • Veröffentlicht 28.12.2015 11:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.