CVE-2020-25285
- EPSS 0.05%
- Veröffentlicht 13.09.2020 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:17:51
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.
CVE-2020-25220
- EPSS 0.12%
- Veröffentlicht 10.09.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:17:41
The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.
- EPSS 0.04%
- Veröffentlicht 09.09.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:39
In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_connt...
- EPSS 0.08%
- Veröffentlicht 09.09.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:39
A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b...
CVE-2020-3702
- EPSS 0.3%
- Veröffentlicht 08.09.2020 10:15:16
- Zuletzt bearbeitet 21.11.2024 05:31:36
u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon A...
CVE-2020-14356
- EPSS 0.82%
- Veröffentlicht 19.08.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:05
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
CVE-2020-16166
- EPSS 1.68%
- Veröffentlicht 30.07.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:53
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c...
CVE-2020-15393
- EPSS 0.09%
- Veröffentlicht 29.06.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:05:28
In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.
CVE-2020-0543
- EPSS 0.48%
- Veröffentlicht 15.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:53:42
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-10732
- EPSS 0.04%
- Veröffentlicht 12.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:57
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.