Novell

Suse Linux Enterprise Debuginfo

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.25%
  • Veröffentlicht 31.01.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 02:35:42

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecifie...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 27.06.2016 10:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames...

  • EPSS 0.1%
  • Veröffentlicht 23.05.2016 10:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have...

  • EPSS 0.37%
  • Veröffentlicht 23.05.2016 10:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer...

  • EPSS 0.52%
  • Veröffentlicht 23.05.2016 10:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.

  • EPSS 0.51%
  • Veröffentlicht 23.05.2016 10:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.

  • EPSS 0.04%
  • Veröffentlicht 23.05.2016 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTIN...

  • EPSS 0.16%
  • Veröffentlicht 02.05.2016 10:59:39
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB...

  • EPSS 0.02%
  • Veröffentlicht 02.05.2016 10:59:37
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data e...

  • EPSS 0.02%
  • Veröffentlicht 02.05.2016 10:59:36
  • Zuletzt bearbeitet 12.04.2025 10:46:40

drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoin...