CVE-2017-7889
- EPSS 0.03%
- Veröffentlicht 17.04.2017 00:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access re...
CVE-2017-7616
- EPSS 0.05%
- Veröffentlicht 10.04.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap op...
CVE-2017-7618
- EPSS 0.24%
- Veröffentlicht 10.04.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.
CVE-2017-2671
- EPSS 0.51%
- Veröffentlicht 05.04.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (pani...
CVE-2016-10318
- EPSS 0.57%
- Veröffentlicht 04.04.2017 16:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a diff...
CVE-2014-9922
- EPSS 0.07%
- Veröffentlicht 04.04.2017 05:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a large filesystem stack that includes an overlayfs layer, related to fs/ecryptfs/main.c and fs/overlayfs/super.c.
- EPSS 1.35%
- Veröffentlicht 04.04.2017 05:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
CVE-2017-7374
- EPSS 0.32%
- Veröffentlicht 31.03.2017 20:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryptio...
CVE-2017-2647
- EPSS 0.04%
- Veröffentlicht 31.03.2017 04:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_sea...
CVE-2017-7346
- EPSS 0.1%
- Veröffentlicht 30.03.2017 23:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call...