CVE-2016-9685
- EPSS 0.39%
- Veröffentlicht 28.12.2016 07:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations.
CVE-2016-9756
- EPSS 0.44%
- Veröffentlicht 28.12.2016 07:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
CVE-2016-9793
- EPSS 1.57%
- Veröffentlicht 28.12.2016 07:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspe...
CVE-2016-9794
- EPSS 0.34%
- Veröffentlicht 28.12.2016 07:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafte...
CVE-2016-9806
- EPSS 0.37%
- Veröffentlicht 28.12.2016 07:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes send...
CVE-2016-9919
- EPSS 5.67%
- Veröffentlicht 08.12.2016 17:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.
CVE-2016-8655
- EPSS 11.13%
- Veröffentlicht 08.12.2016 08:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet...
CVE-2016-9644
- EPSS 1.45%
- Veröffentlicht 28.11.2016 03:59:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platfo...
- EPSS 9.14%
- Veröffentlicht 28.11.2016 03:59:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified...
CVE-2016-9191
- EPSS 0.42%
- Veröffentlicht 28.11.2016 03:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted appl...