Linux

Linux Kernel

14575 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 28.11.2016 03:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted appl...

  • EPSS 0.07%
  • Veröffentlicht 28.11.2016 03:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a certain integer variable, which allows local users to obtain sensitive information from kernel stack memory by triggering failure of ...

  • EPSS 0.05%
  • Veröffentlicht 28.11.2016 03:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel through 4.8.11 misuses the kzalloc function, which allows local users to cause a denial of service (integer overflow) or have unspecified other impact by leveraging access to a vfio PCI device fil...

  • EPSS 0.05%
  • Veröffentlicht 28.11.2016 03:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and cause a denial of service (memory corruption) or have unspecified other impact, by leveraging access to a vfio PCI device file fo...

  • EPSS 0.05%
  • Veröffentlicht 28.11.2016 03:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call...

  • EPSS 0.03%
  • Veröffentlicht 28.11.2016 03:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of service (OOPS) by attempting to trigger use of in-kernel hash algorithms for a socket that has received zero bytes of data.

  • EPSS 0.03%
  • Veröffentlicht 28.11.2016 03:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of service (system crash) via a crafted application that makes sendto system calls, related to net/ipv4/tcp_ipv4.c and net/ipv6/tcp_...

  • EPSS 0.93%
  • Veröffentlicht 28.11.2016 03:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary code via crafted fragmented packets.

  • EPSS 0.05%
  • Veröffentlicht 28.11.2016 03:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size, which allows local users to gain privileges or cause a denial of serv...

  • EPSS 0.03%
  • Veröffentlicht 28.11.2016 03:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a certain use of a ModR/M byte in an undefined instruction.