CVE-2006-5331
- EPSS 0.43%
- Veröffentlicht 29.10.2017 06:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The altivec_unavailable_exception function in arch/powerpc/kernel/traps.c in the Linux kernel before 2.6.19 on 64-bit systems mishandles the case where CONFIG_ALTIVEC is defined and the CPU actually supports Altivec, but the Altivec support was not d...
CVE-2017-15649
- EPSS 0.96%
- Veröffentlicht 19.10.2017 22:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) t...
- EPSS 0.38%
- Veröffentlicht 16.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clie...
CVE-2017-15299
- EPSS 0.53%
- Veröffentlicht 14.10.2017 23:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have un...
CVE-2017-12192
- EPSS 0.45%
- Veröffentlicht 12.10.2017 00:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 does not properly consider that a key may be possessed but negatively instantiated, which allows local users to cause a denial...
CVE-2017-15274
- EPSS 0.45%
- Veröffentlicht 12.10.2017 00:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction with a nonzero length value, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted ...
CVE-2017-1000111
- EPSS 0.37%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 13.05.2026 00:24:29
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...
- EPSS 20.8%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 13.05.2026 00:24:29
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from...
CVE-2017-1000253
- EPSS 10.7%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 21.04.2026 18:00:48
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4f...
CVE-2017-14991
- EPSS 0.41%
- Veröffentlicht 04.10.2017 01:29:03
- Zuletzt bearbeitet 13.05.2026 00:24:29
The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized kernel heap-memory locations via an SG_GET_REQUEST_TABLE ioctl call for /dev/sg0.