CVE-2007-3732
- EPSS 0.38%
- Veröffentlicht 07.11.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 00:33:56
In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in iret_exc calls a C function without ensuring that the segments are set properly. The kernel's %fs needs to be restored before the call in TRACE_IRQS_ON and before enabling interrupts, so that ...
CVE-2019-18806
- EPSS 0.35%
- Veröffentlicht 07.11.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:36
A memory leak in the ql_alloc_large_buffers() function in drivers/net/ethernet/qlogic/qla3xxx.c in the Linux kernel before 5.3.5 allows local users to cause a denial of service (memory consumption) by triggering pci_dma_mapping_error() failures, aka ...
CVE-2019-18805
- EPSS 3.43%
- Veröffentlicht 07.11.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:36
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen...
- EPSS 0.99%
- Veröffentlicht 04.11.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:31
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. ...
CVE-2019-18680
- EPSS 3.64%
- Veröffentlicht 04.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:31
An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c that will cause denial of service, aka CID-91573ae4aed0.
CVE-2019-17666
- EPSS 3.02%
- Veröffentlicht 17.10.2019 02:15:13
- Zuletzt bearbeitet 21.11.2024 04:32:44
rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.
CVE-2019-2215
- EPSS 43.82%
- Veröffentlicht 11.10.2019 19:15:10
- Zuletzt bearbeitet 24.10.2025 14:11:31
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local appli...
CVE-2019-17351
- EPSS 0.41%
- Veröffentlicht 08.10.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:08
An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, ak...
CVE-2019-17133
- EPSS 6.65%
- Veröffentlicht 04.10.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:45
In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
CVE-2019-17075
- EPSS 6.24%
- Veröffentlicht 01.10.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:39
An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single (a DMA function) from a stack variable. This could allow an attacker to trigger a D...