CVE-2023-38432
- EPSS 0.07%
- Veröffentlicht 18.07.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:13:33
An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.
CVE-2023-38409
- EPSS 0.01%
- Veröffentlicht 17.07.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:13:30
An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_...
CVE-2023-21255
- EPSS 0.1%
- Veröffentlicht 13.07.2023 00:15:24
- Zuletzt bearbeitet 13.02.2025 17:16:02
In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-21400
- EPSS 0.04%
- Veröffentlicht 13.07.2023 00:15:24
- Zuletzt bearbeitet 13.02.2025 17:16:02
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exp...
CVE-2023-3106
- EPSS 0.01%
- Veröffentlicht 12.07.2023 09:15:14
- Zuletzt bearbeitet 21.11.2024 08:16:28
A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of...
CVE-2023-3108
- EPSS 0.01%
- Veröffentlicht 11.07.2023 16:15:12
- Zuletzt bearbeitet 06.03.2025 16:15:42
A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.
CVE-2023-3269
- EPSS 0.24%
- Veröffentlicht 11.07.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:16:52
A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to exec...
CVE-2023-32250
- EPSS 0.11%
- Veröffentlicht 10.07.2023 16:15:52
- Zuletzt bearbeitet 21.11.2024 08:02:58
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an o...
CVE-2023-32254
- EPSS 0.07%
- Veröffentlicht 10.07.2023 16:15:52
- Zuletzt bearbeitet 21.11.2024 08:02:59
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an...
CVE-2023-37453
- EPSS 0.02%
- Veröffentlicht 06.07.2023 17:15:14
- Zuletzt bearbeitet 05.05.2025 16:15:42
An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c.