Linux

Linux Kernel

18376 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.49%
  • Veröffentlicht 14.05.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:07:40

The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass pe...

  • EPSS 0.35%
  • Veröffentlicht 05.05.2009 20:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:41

The selinux_ip_postroute_iptables_compat function in security/selinux/hooks.c in the SELinux subsystem in the Linux kernel before 2.6.27.22, and 2.6.28.x before 2.6.28.10, when compat_net is enabled, omits calls to avc_has_perm for the (1) node and (...

  • EPSS 0.49%
  • Veröffentlicht 05.05.2009 20:30:00
  • Zuletzt bearbeitet 16.06.2026 23:07:27

Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel before 2.6.30-rc4 allows local users to gain privileges via a PTRACE_ATTACH ptrace call during an exec system call that is launching a setuid application, related to ...

  • EPSS 4.27%
  • Veröffentlicht 27.04.2009 18:00:00
  • Zuletzt bearbeitet 16.06.2026 23:07:16

Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB mount request.

  • EPSS 0.39%
  • Veröffentlicht 24.04.2009 15:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:43

The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows ...

  • EPSS 0.41%
  • Veröffentlicht 22.04.2009 15:30:00
  • Zuletzt bearbeitet 16.06.2026 23:07:03

fs/nfs/client.c in the Linux kernel before 2.6.23 does not properly initialize a certain structure member that stores the maximum NFS filename length, which allows local users to cause a denial of service (OOPS) via a long filename, related to the en...

  • EPSS 1.26%
  • Veröffentlicht 22.04.2009 15:30:00
  • Zuletzt bearbeitet 16.06.2026 23:07:03

The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies ...

  • EPSS 0.39%
  • Veröffentlicht 22.04.2009 15:30:00
  • Zuletzt bearbeitet 16.06.2026 23:07:04

The kill_something_info function in kernel/signal.c in the Linux kernel before 2.6.28 does not consider PID namespaces when processing signals directed to PID -1, which allows local users to bypass the intended namespace isolation, and send arbitrary...

Exploit
  • EPSS 3.19%
  • Veröffentlicht 22.04.2009 15:30:00
  • Zuletzt bearbeitet 16.06.2026 23:07:06

The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system...

Exploit
  • EPSS 3.17%
  • Veröffentlicht 08.04.2009 01:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:53

Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.