CVE-2018-12233
- EPSS 2.34%
- Veröffentlicht 12.06.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:49
In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability can be triggered b...
CVE-2018-1000200
- EPSS 0.49%
- Veröffentlicht 05.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:55
The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM) killing of large mlocked processes. The issue arises from an oom killed process's final thread calling exit_mmap(), which calls m...
CVE-2018-11508
- EPSS 1.72%
- Veröffentlicht 28.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:30
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
CVE-2018-11506
- EPSS 0.39%
- Veröffentlicht 28.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:30
The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes...
CVE-2018-11412
- EPSS 16.35%
- Veröffentlicht 24.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:18
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a d...
CVE-2018-1000199
- EPSS 1.22%
- Veröffentlicht 24.05.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:39:55
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptra...
CVE-2018-1108
- EPSS 1.8%
- Veröffentlicht 21.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:11
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
CVE-2017-18270
- EPSS 0.42%
- Veröffentlicht 18.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:44
In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
CVE-2018-11232
- EPSS 0.4%
- Veröffentlicht 18.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:57
The etm_setup_aux function in drivers/hwtracing/coresight/coresight-etm-perf.c in the Linux kernel before 4.10.2 allows attackers to cause a denial of service (panic) because a parameter is incorrectly used as a local variable.
CVE-2018-1087
- EPSS 0.77%
- Veröffentlicht 15.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS ...