CVE-2017-6074
- EPSS 5.96%
- Veröffentlicht 18.02.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double...
- EPSS 0.33%
- Veröffentlicht 14.02.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The time subsystem in the Linux kernel through 4.9.9, when CONFIG_TIMER_STATS is enabled, allows local users to discover real PID values (as distinguished from PID values inside a PID namespace) by reading the /proc/timer_list file, related to the pr...
CVE-2017-5970
- EPSS 3.92%
- Veröffentlicht 14.02.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invali...
CVE-2016-10044
- EPSS 0.3%
- Veröffentlicht 07.02.2017 07:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup...
CVE-2010-5328
- EPSS 0.43%
- Veröffentlicht 06.02.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero from reaching the swapper process, which allows local users to cause a denial of service (system crash) by leveraging access to this ...
CVE-2016-10208
- EPSS 0.43%
- Veröffentlicht 06.02.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a craft...
CVE-2017-2583
- EPSS 0.58%
- Veröffentlicht 06.02.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel before 4.9.5 improperly emulates a "MOV SS, NULL selector" instruction, which allows guest OS users to cause a denial of service (guest OS crash) or gain guest O...
CVE-2017-2596
- EPSS 0.4%
- Veröffentlicht 06.02.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mish...
CVE-2017-5549
- EPSS 0.43%
- Veröffentlicht 06.02.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain sensitive i...
CVE-2017-5551
- EPSS 0.4%
- Veröffentlicht 06.02.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 preserves the setgid bit during a setxattr call involving a tmpfs filesystem, which allows local users to gain group privileges by leveraging the existence of a setgid pro...