Linux

Linux Kernel

14023 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 15.03.2013 20:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not verify that the actual Netlink message length is consistent with a certain header field, which allows local users to obtain sensitive information from kernel heap memory by leveraging the C...

  • EPSS 0.05%
  • Veröffentlicht 06.03.2013 22:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The _xfs_buf_find function in fs/xfs/xfs_buf.c in the Linux kernel before 3.7.6 does not validate block numbers, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impa...

  • EPSS 0.21%
  • Veröffentlicht 01.03.2013 12:37:54
  • Zuletzt bearbeitet 11.04.2025 00:51:21

fs/ext4/extents.c in the Linux kernel before 3.0 does not mark a modified extent as dirty in certain cases of extent splitting, which allows local users to cause a denial of service (system crash) via vectors involving ext4 umount and mount operation...

  • EPSS 0.09%
  • Veröffentlicht 01.03.2013 12:37:54
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The xen_iret function in arch/x86/xen/xen-asm_32.S in the Linux kernel before 3.7.9 on 32-bit Xen paravirt_ops platforms does not properly handle an invalid value in the DS segment register, which allows guest OS users to gain guest OS privileges via...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 01.03.2013 12:37:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 01.03.2013 12:37:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Linux kernel before 2.6.39 does not properly create transparent huge pages in response to a MAP_PRIVATE mmap system call on /dev/zero, which allows local users to cause a denial of service (system crash) via a crafted application.

  • EPSS 0.07%
  • Veröffentlicht 01.03.2013 12:37:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.

  • EPSS 0.23%
  • Veröffentlicht 01.03.2013 12:37:53
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in the Linux kernel before 3.1, allows local users to overwrite arbitrary files via a crafted config file in the current working direc...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 01.03.2013 12:37:47
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.

  • EPSS 0.08%
  • Veröffentlicht 28.02.2013 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapp...