CVE-2017-1000111
- EPSS 0.37%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 13.05.2026 00:24:29
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...
- EPSS 20.8%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 13.05.2026 00:24:29
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from...
CVE-2017-1000253
- EPSS 10.7%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 21.04.2026 18:00:48
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4f...
CVE-2017-14991
- EPSS 0.41%
- Veröffentlicht 04.10.2017 01:29:03
- Zuletzt bearbeitet 13.05.2026 00:24:29
The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized kernel heap-memory locations via an SG_GET_REQUEST_TABLE ioctl call for /dev/sg0.
CVE-2017-14954
- EPSS 1.01%
- Veröffentlicht 02.10.2017 01:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted syst...
CVE-2017-1000252
- EPSS 0.45%
- Veröffentlicht 26.09.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and hypervisor hang or crash) via an out-of bounds guest_irq value, related to arch/x86/kvm/vmx.c and virt/kvm/eventfd.c.
CVE-2017-12154
- EPSS 0.51%
- Veröffentlicht 26.09.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omits the "use TPR shadow" vmcs12 control, which allow...
CVE-2015-5327
- EPSS 1.63%
- Veröffentlicht 25.09.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Out-of-bounds memory read in the x509_decode_time function in x509_cert_parser.c in Linux kernels 4.3-rc1 and after.
CVE-2017-12153
- EPSS 0.47%
- Veröffentlicht 21.09.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be i...
- EPSS 0.42%
- Veröffentlicht 20.09.2017 08:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cycle Count Re...