CVE-2018-1000200
- EPSS 0.08%
- Veröffentlicht 05.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:55
The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM) killing of large mlocked processes. The issue arises from an oom killed process's final thread calling exit_mmap(), which calls m...
CVE-2018-11508
- EPSS 1.54%
- Veröffentlicht 28.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:30
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
CVE-2018-11506
- EPSS 0.08%
- Veröffentlicht 28.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:30
The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes...
CVE-2018-11412
- EPSS 11.2%
- Veröffentlicht 24.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:18
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a d...
CVE-2018-1000199
- EPSS 0.48%
- Veröffentlicht 24.05.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:39:55
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptra...
CVE-2018-3639
- EPSS 48.65%
- Veröffentlicht 22.05.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:48
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access vi...
CVE-2018-1108
- EPSS 0.46%
- Veröffentlicht 21.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:11
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
CVE-2017-18270
- EPSS 0.07%
- Veröffentlicht 18.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:44
In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
CVE-2018-1087
- EPSS 0.03%
- Veröffentlicht 15.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS ...
CVE-2018-1118
- EPSS 0.11%
- Veröffentlicht 10.05.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:13
Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel ...