CVE-2017-1000111
- EPSS 0.06%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 13.05.2026 00:24:29
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...
CVE-2017-12154
- EPSS 0.04%
- Veröffentlicht 26.09.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omits the "use TPR shadow" vmcs12 control, which allow...
CVE-2017-12153
- EPSS 0.02%
- Veröffentlicht 21.09.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be i...
CVE-2017-14340
- EPSS 0.04%
- Veröffentlicht 15.09.2017 11:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesystem has a realtime device, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via vectors rel...
CVE-2017-14489
- EPSS 0.27%
- Veröffentlicht 15.09.2017 10:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (panic) by leveraging incorrect length validation.
- EPSS 3.03%
- Veröffentlicht 12.09.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remot...
CVE-2017-14156
- EPSS 0.09%
- Veröffentlicht 05.09.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading locations ...
CVE-2017-14140
- EPSS 0.07%
- Veröffentlicht 05.09.2017 06:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The move_pages system call in mm/migrate.c in the Linux kernel before 4.12.9 doesn't check the effective uid of the target process, enabling a local attacker to learn the memory layout of a setuid executable despite ASLR.
CVE-2017-14106
- EPSS 0.08%
- Veröffentlicht 01.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code pat...
CVE-2017-14051
- EPSS 0.12%
- Veröffentlicht 31.08.2017 04:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An integer overflow in the qla2x00_sysfs_write_optrom_ctl function in drivers/scsi/qla2xxx/qla_attr.c in the Linux kernel through 4.12.10 allows local users to cause a denial of service (memory corruption and system crash) by leveraging root access.