CVE-2009-3725
- EPSS 0.61%
- Veröffentlicht 06.11.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:12:14
The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restric...
- EPSS 4.89%
- Veröffentlicht 04.11.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:49
Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...
CVE-2009-3624
- EPSS 0.37%
- Veröffentlicht 02.11.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:12:02
The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of...
CVE-2009-3623
- EPSS 3.47%
- Veröffentlicht 30.10.2009 20:30:00
- Zuletzt bearbeitet 16.06.2026 23:12:02
The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to...
CVE-2009-3722
- EPSS 2.28%
- Veröffentlicht 30.10.2009 20:30:00
- Zuletzt bearbeitet 16.06.2026 23:12:14
The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege Level (CPL) before accessing a debug register, which allows guest OS users to cause a denial of servi...
CVE-2009-3638
- EPSS 0.51%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 16.06.2026 23:12:04
Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_d...
CVE-2009-3640
- EPSS 0.38%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 16.06.2026 23:12:04
The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denia...
CVE-2009-3620
- EPSS 0.43%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 16.06.2026 23:12:02
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...
CVE-2009-3621
- EPSS 0.99%
- Veröffentlicht 22.10.2009 16:00:00
- Zuletzt bearbeitet 16.06.2026 23:12:02
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...
CVE-2009-2909
- EPSS 0.4%
- Veröffentlicht 20.10.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:28
Integer signedness error in the ax25_setsockopt function in net/ax25/af_ax25.c in the ax25 subsystem in the Linux kernel before 2.6.31.2 allows local users to cause a denial of service (OOPS) via a crafted optlen value in an SO_BINDTODEVICE operation...