CVE-2020-36516
- EPSS 0.04%
- Published 26.02.2022 04:15:06
- Last modified 21.11.2024 05:29:43
An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.
CVE-2021-45485
- EPSS 0.52%
- Published 25.12.2021 02:15:06
- Last modified 21.11.2024 06:32:18
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among ma...
- EPSS 0.04%
- Published 03.09.2021 01:15:07
- Last modified 21.11.2024 06:24:14
A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
CVE-2021-22555
- EPSS 82.42%
- Published 07.07.2021 12:15:08
- Last modified 07.10.2025 01:00:02
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
CVE-2019-25045
- EPSS 0.15%
- Published 07.06.2021 20:15:07
- Last modified 21.11.2024 04:39:49
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
CVE-2020-35508
- EPSS 0.05%
- Published 26.03.2021 17:15:12
- Last modified 21.11.2024 05:27:27
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass chec...
CVE-2020-15436
- EPSS 0.12%
- Published 23.11.2020 21:15:11
- Last modified 21.11.2024 05:05:33
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
CVE-2020-13143
- EPSS 2.98%
- Published 18.05.2020 18:15:11
- Last modified 21.11.2024 05:00:44
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753...
CVE-2020-12888
- EPSS 0.1%
- Published 15.05.2020 18:15:13
- Last modified 21.11.2024 05:00:29
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
CVE-2020-12771
- EPSS 0.06%
- Published 09.05.2020 21:15:11
- Last modified 21.11.2024 05:00:15
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.