CVE-2015-4178
- EPSS 0.37%
- Veröffentlicht 02.05.2016 10:59:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
The fs_pin implementation in the Linux kernel before 4.0.5 does not ensure the internal consistency of a certain list data structure, which allows local users to cause a denial of service (system crash) by leveraging user-namespace root access for an...
CVE-2015-4177
- EPSS 0.37%
- Veröffentlicht 02.05.2016 10:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
The collect_mounts function in fs/namespace.c in the Linux kernel before 4.0.5 does not properly consider that it may execute after a path has been unmounted, which allows local users to cause a denial of service (system crash) by leveraging user-nam...
CVE-2015-4176
- EPSS 0.36%
- Veröffentlicht 02.05.2016 10:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory.
CVE-2015-4170
- EPSS 0.33%
- Veröffentlicht 02.05.2016 10:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread...
CVE-2015-1350
- EPSS 0.49%
- Veröffentlicht 02.05.2016 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a...
CVE-2014-9717
- EPSS 0.33%
- Veröffentlicht 02.05.2016 10:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneat...
CVE-2012-6701
- EPSS 0.35%
- Veröffentlicht 02.05.2016 10:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec.
CVE-2012-6689
- EPSS 0.31%
- Veröffentlicht 02.05.2016 10:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.
CVE-2016-3672
- EPSS 1.17%
- Veröffentlicht 27.04.2016 17:59:27
- Zuletzt bearbeitet 06.05.2026 22:30:45
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, a...
CVE-2016-3156
- EPSS 0.55%
- Veröffentlicht 27.04.2016 17:59:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses.