CVE-2023-23559
- EPSS 0.3%
- Veröffentlicht 13.01.2023 01:15:10
- Zuletzt bearbeitet 05.05.2025 16:15:30
In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.
CVE-2022-3628
- EPSS 0.5%
- Veröffentlicht 12.01.2023 19:15:24
- Zuletzt bearbeitet 08.04.2025 15:15:45
A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious USB device. This can allow a local user to crash the system or escalate their privileges.
CVE-2022-3977
- EPSS 0.25%
- Veröffentlicht 12.01.2023 19:15:24
- Zuletzt bearbeitet 08.04.2025 18:15:44
A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This issue occurs when a user simultaneously calls DROPTAG ioctl and socket close happens, which could allow a local user to crash the s...
CVE-2022-4842
- EPSS 0.2%
- Veröffentlicht 12.01.2023 19:15:24
- Zuletzt bearbeitet 08.04.2025 14:15:30
A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to crash the system.
CVE-2023-23455
- EPSS 0.27%
- Veröffentlicht 12.01.2023 07:15:09
- Zuletzt bearbeitet 20.03.2025 21:15:18
atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification resu...
CVE-2023-23454
- EPSS 0.31%
- Veröffentlicht 12.01.2023 07:15:08
- Zuletzt bearbeitet 20.03.2025 21:15:18
cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than v...
CVE-2022-4543
- EPSS 0.95%
- Veröffentlicht 11.01.2023 15:15:09
- Zuletzt bearbeitet 08.04.2025 20:15:18
A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.
CVE-2022-4696
- EPSS 0.41%
- Veröffentlicht 11.01.2023 13:15:09
- Zuletzt bearbeitet 01.09.2026 18:05:07
There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its referen...
CVE-2022-4379
- EPSS 6.35%
- Veröffentlicht 10.01.2023 22:15:14
- Zuletzt bearbeitet 08.04.2025 19:15:46
A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial
CVE-2022-4382
- EPSS 0.48%
- Veröffentlicht 10.01.2023 22:15:14
- Zuletzt bearbeitet 09.04.2025 16:15:21
A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could be triggered by yanking out a device that is running the gadgetfs side.