CVE-2015-8019
- EPSS 0.38%
- Veröffentlicht 02.05.2016 10:59:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified oth...
CVE-2015-4178
- EPSS 0.37%
- Veröffentlicht 02.05.2016 10:59:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
The fs_pin implementation in the Linux kernel before 4.0.5 does not ensure the internal consistency of a certain list data structure, which allows local users to cause a denial of service (system crash) by leveraging user-namespace root access for an...
CVE-2015-4177
- EPSS 0.37%
- Veröffentlicht 02.05.2016 10:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
The collect_mounts function in fs/namespace.c in the Linux kernel before 4.0.5 does not properly consider that it may execute after a path has been unmounted, which allows local users to cause a denial of service (system crash) by leveraging user-nam...
CVE-2015-4176
- EPSS 0.36%
- Veröffentlicht 02.05.2016 10:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory.
CVE-2015-4170
- EPSS 0.33%
- Veröffentlicht 02.05.2016 10:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread...
CVE-2015-2686
- EPSS 0.39%
- Veröffentlicht 02.05.2016 10:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom system calls, which allows local users to gain privileges by leveraging a subsystem that uses the copy_from_iter function in the ...
CVE-2015-2672
- EPSS 0.37%
- Veröffentlicht 02.05.2016 10:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and consequently does not provide any protection against instruction faulting, which allows local users t...
CVE-2015-1573
- EPSS 0.37%
- Veröffentlicht 02.05.2016 10:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the ...
CVE-2015-1350
- EPSS 0.49%
- Veröffentlicht 02.05.2016 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a...
CVE-2014-9717
- EPSS 0.33%
- Veröffentlicht 02.05.2016 10:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneat...