CVE-2015-8970
- EPSS 0.04%
- Veröffentlicht 28.11.2016 03:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer der...
CVE-2015-8952
- EPSS 0.08%
- Veröffentlicht 16.10.2016 21:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mbcache feature in the ext2 and ext4 filesystem implementations in the Linux kernel before 4.6 mishandles xattr block caching, which allows local users to cause a denial of service (soft lockup) via filesystem operations in environments that use ...
CVE-2016-6198
- EPSS 0.04%
- Veröffentlicht 06.08.2016 20:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related t...
CVE-2016-6197
- EPSS 0.06%
- Veröffentlicht 06.08.2016 20:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of serv...
CVE-2016-2854
- EPSS 0.35%
- Veröffentlicht 02.05.2016 10:59:34
- Zuletzt bearbeitet 06.05.2026 22:30:45
The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
CVE-2016-2853
- EPSS 0.22%
- Veröffentlicht 02.05.2016 10:59:33
- Zuletzt bearbeitet 06.05.2026 22:30:45
The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
CVE-2015-8839
- EPSS 0.04%
- Veröffentlicht 02.05.2016 10:59:22
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user's file after unsynchronized h...
CVE-2015-1350
- EPSS 0.07%
- Veröffentlicht 02.05.2016 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a...
CVE-2015-8553
- EPSS 0.27%
- Veröffentlicht 13.04.2016 15:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.
CVE-2013-7445
- EPSS 1.13%
- Veröffentlicht 16.10.2015 01:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an applicati...