CVE-2017-14106
- EPSS 0.45%
- Veröffentlicht 01.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code pat...
CVE-2017-14051
- EPSS 0.37%
- Veröffentlicht 31.08.2017 04:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An integer overflow in the qla2x00_sysfs_write_optrom_ctl function in drivers/scsi/qla2xxx/qla_attr.c in the Linux kernel through 4.12.10 allows local users to cause a denial of service (memory corruption and system crash) by leveraging root access.
- EPSS 9.65%
- Veröffentlicht 29.08.2017 01:35:13
- Zuletzt bearbeitet 13.05.2026 00:24:29
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a denial of service (system crash) or possibly execu...
CVE-2017-13693
- EPSS 0.44%
- Veröffentlicht 25.08.2017 08:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory an...
CVE-2017-13694
- EPSS 0.41%
- Veröffentlicht 25.08.2017 08:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from ke...
CVE-2017-13695
- EPSS 0.44%
- Veröffentlicht 25.08.2017 08:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass...
CVE-2017-12134
- EPSS 0.5%
- Veröffentlicht 24.08.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges ...
CVE-2017-10661
- EPSS 13.38%
- Veröffentlicht 19.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel q...
CVE-2017-10662
- EPSS 0.47%
- Veröffentlicht 19.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The sanity_check_raw_super function in fs/f2fs/super.c in the Linux kernel before 4.11.1 does not validate the segment count, which allows local users to gain privileges via unspecified vectors.
CVE-2017-10663
- EPSS 0.44%
- Veröffentlicht 19.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.