Linux

Linux Kernel

14023 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 14.7%
  • Veröffentlicht 01.08.2014 11:13:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an assoc...

  • EPSS 1.03%
  • Veröffentlicht 19.07.2014 19:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.

Exploit
  • EPSS 1.14%
  • Veröffentlicht 09.07.2014 11:07:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain p...

  • EPSS 14.14%
  • Veröffentlicht 03.07.2014 04:22:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.

  • EPSS 8.6%
  • Veröffentlicht 03.07.2014 04:22:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a cra...

  • EPSS 10.11%
  • Veröffentlicht 03.07.2014 04:22:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers...

  • EPSS 0.05%
  • Veröffentlicht 03.07.2014 04:22:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory b...

  • EPSS 0.07%
  • Veröffentlicht 03.07.2014 04:22:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from ke...

  • EPSS 0.07%
  • Veröffentlicht 03.07.2014 04:22:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and ...

  • EPSS 0.04%
  • Veröffentlicht 03.07.2014 04:22:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial of service (integer overflow an...