CVE-2016-0821
- EPSS 0.38%
- Veröffentlicht 12.03.2016 21:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a pois...
CVE-2016-0728
- EPSS 3.65%
- Veröffentlicht 08.02.2016 03:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and us...
CVE-2016-0723
- EPSS 0.38%
- Veröffentlicht 08.02.2016 03:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGE...
CVE-2015-8785
- EPSS 0.57%
- Veröffentlicht 08.02.2016 03:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov.
CVE-2015-8767
- EPSS 0.39%
- Veröffentlicht 08.02.2016 03:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.
- EPSS 0.4%
- Veröffentlicht 08.02.2016 03:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then us...
- EPSS 0.52%
- Veröffentlicht 08.02.2016 03:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted ...
CVE-2015-7566
- EPSS 1.84%
- Veröffentlicht 08.02.2016 03:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by ins...
CVE-2015-8539
- EPSS 0.42%
- Veröffentlicht 08.02.2016 03:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/ke...
CVE-2015-7550
- EPSS 0.41%
- Veröffentlicht 08.02.2016 03:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel before 4.3.4 does not properly use a semaphore, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified ...