CVE-2021-3490
- EPSS 27.48%
- Veröffentlicht 04.06.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:39
The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This is...
CVE-2021-3491
- EPSS 0.63%
- Veröffentlicht 04.06.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:40
The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used to create a heap overflow lea...
- EPSS 0.26%
- Veröffentlicht 02.06.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 04:55:58
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat fro...
CVE-2021-3543
- EPSS 0.3%
- Veröffentlicht 01.06.2021 14:15:10
- Zuletzt bearbeitet 21.11.2024 06:21:48
A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privil...
CVE-2021-20239
- EPSS 0.26%
- Veröffentlicht 28.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:11
A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentialit...
CVE-2021-20292
- EPSS 0.85%
- Veröffentlicht 28.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:17
There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to per...
CVE-2021-33200
- EPSS 0.38%
- Veröffentlicht 27.05.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:30
kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege esca...
CVE-2008-2544
- EPSS 0.31%
- Veröffentlicht 27.05.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 00:47:07
Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environment and gain write access to files, he would never have otherwise.
CVE-2021-20177
- EPSS 0.28%
- Veröffentlicht 26.05.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:04
A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kernel before kernel 5.5-rc1 is aff...
CVE-2020-27815
- EPSS 0.79%
- Veröffentlicht 26.05.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:21:51
A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerabil...