CVE-2021-41073
- EPSS 1.72%
- Veröffentlicht 19.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:23
loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.
- EPSS 0.3%
- Veröffentlicht 03.09.2021 01:15:07
- Zuletzt bearbeitet 13.08.2026 19:32:28
A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
CVE-2021-3541
- EPSS 1.96%
- Veröffentlicht 09.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:48
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
CVE-2021-3612
- EPSS 0.69%
- Veröffentlicht 09.07.2021 11:15:09
- Zuletzt bearbeitet 21.11.2024 06:21:58
An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privi...
CVE-2021-22555
- EPSS 78.68%
- Veröffentlicht 07.07.2021 12:15:08
- Zuletzt bearbeitet 27.10.2025 17:06:32
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
CVE-2021-28691
- EPSS 0.36%
- Veröffentlicht 29.06.2021 12:15:08
- Zuletzt bearbeitet 26.08.2026 17:57:08
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malfor...
CVE-2020-28097
- EPSS 0.52%
- Veröffentlicht 24.06.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:22:21
The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85.
CVE-2020-36387
- EPSS 0.39%
- Veröffentlicht 07.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:23
An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_func and ctx reference holding, aka CID-6d816e088c35.
CVE-2018-25015
- EPSS 0.57%
- Veröffentlicht 07.06.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 04:03:21
An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8.
CVE-2019-25045
- EPSS 0.5%
- Veröffentlicht 07.06.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:49
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.