Linux

Linux Kernel

16949 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.08%
  • Veröffentlicht 27.11.2017 19:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system c...

Exploit
  • EPSS 2.15%
  • Veröffentlicht 24.11.2017 10:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM...

  • EPSS 0.53%
  • Veröffentlicht 22.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting when a SCSI I/O vector has small consecutive buffers belonging to the same page. The bio_add_pc_page function merges them int...

  • EPSS 0.45%
  • Veröffentlicht 22.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application...

  • EPSS 0.39%
  • Veröffentlicht 15.11.2017 21:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occur...

  • EPSS 0.47%
  • Veröffentlicht 15.11.2017 21:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possi...

  • EPSS 1.59%
  • Veröffentlicht 14.11.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out of bound memory read is used as a function pointer could lead to code execution in the kernel.This issue is rated as high because i...

  • EPSS 0.48%
  • Veröffentlicht 07.11.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted U...

  • EPSS 0.4%
  • Veröffentlicht 07.11.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The hdpvr_probe function in drivers/media/usb/hdpvr/hdpvr-core.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (improper error handling and system crash) or possibly have unspecified other impact via a crafted US...

  • EPSS 0.4%
  • Veröffentlicht 07.11.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The ims_pcu_get_cdc_union_desc function in drivers/input/misc/ims-pcu.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (ims_pcu_parse_cdc_data out-of-bounds read and system crash) or possibly have unspecified othe...