Debian

Debian 12 (bookworm)

11227 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 27.12.2012 11:47:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.

  • EPSS 1.26%
  • Veröffentlicht 21.12.2012 11:47:36
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.

  • EPSS 0.08%
  • Veröffentlicht 21.12.2012 11:47:36
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 21.12.2012 11:47:36
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The tcp_illinois_info function in net/ipv4/tcp_illinois.c in the Linux kernel before 3.4.19, when the net.ipv4.tcp_congestion_control illinois setting is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) by read...

  • EPSS 0.06%
  • Veröffentlicht 21.12.2012 11:47:36
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by us...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 21.12.2012 11:47:35
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from kernel stack memory via a uname system call in conjunction with a UNAME26 personality.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 04.10.2012 03:28:35
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 03.10.2012 11:02:57
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Ava...

  • EPSS 2.03%
  • Veröffentlicht 03.10.2012 11:02:57
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of n...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 03.10.2012 11:02:56
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via ...