- EPSS 9.42%
- Veröffentlicht 05.08.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that leverages simultaneous execution of the inotify_han...
CVE-2017-7541
- EPSS 0.04%
- Veröffentlicht 25.07.2017 04:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The brcmf_cfg80211_mgmt_tx function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.12.3 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a ...
CVE-2017-7542
- EPSS 0.07%
- Veröffentlicht 21.07.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (integer overflow and infinite loop) by leveraging the ability to open a raw socket.
CVE-2017-11472
- EPSS 0.07%
- Veröffentlicht 20.07.2017 04:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass ...
CVE-2017-11473
- EPSS 0.09%
- Veröffentlicht 20.07.2017 04:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table.
CVE-2017-1000363
- EPSS 0.54%
- Veröffentlicht 17.07.2017 13:18:18
- Zuletzt bearbeitet 13.05.2026 00:24:29
Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, wher...
CVE-2017-11176
- EPSS 20.81%
- Veröffentlicht 11.07.2017 23:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possi...
CVE-2017-10911
- EPSS 0.05%
- Veröffentlicht 05.07.2017 01:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized paddin...
CVE-2017-10810
- EPSS 0.83%
- Veröffentlicht 04.07.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.
CVE-2017-8797
- EPSS 30.42%
- Veröffentlicht 02.07.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The NFSv4 server in the Linux kernel before 4.11.3 does not properly validate the layout type when processing the NFSv4 pNFS GETDEVICEINFO or LAYOUTGET operand in a UDP packet from a remote attacker. This type value is uninitialized upon encountering...