CVE-2023-52449
- EPSS 0.24%
- Veröffentlicht 22.02.2024 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:39:47
In the Linux kernel, the following vulnerability has been resolved: mtd: Fix gluebi NULL pointer dereference caused by ftl notifier If both ftl.ko and gluebi.ko are loaded, the notifier of ftl triggers NULL pointer dereference when trying to access...
CVE-2023-52451
- EPSS 0.24%
- Veröffentlicht 22.02.2024 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:39:47
In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/memhp: Fix access beyond end of drmem array dlpar_memory_remove_by_index() may access beyond the bounds of the drmem lmb array when the LMB lookup fails to match an...
CVE-2023-52436
- EPSS 0.3%
- Veröffentlicht 20.02.2024 21:15:08
- Zuletzt bearbeitet 15.08.2026 13:17:39
In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. This eliminates the fragile assumption that the unused xattr space ...
CVE-2023-52439
- EPSS 0.3%
- Veröffentlicht 20.02.2024 21:15:08
- Zuletzt bearbeitet 04.08.2026 10:18:27
In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 ------------------------------------------------------- uio_unregister_device uio_open idev = idr_find() device_unregister...
CVE-2023-52435
- EPSS 0.23%
- Veröffentlicht 20.02.2024 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:39:45
In the Linux kernel, the following vulnerability has been resolved: net: prevent mss overflow in skb_segment() Once again syzbot is able to crash the kernel in skb_segment() [1] GSO_BY_FRAGS is a forbidden value, but unfortunately the following co...
CVE-2024-25744
- EPSS 0.28%
- Veröffentlicht 12.02.2024 05:15:07
- Zuletzt bearbeitet 07.05.2025 22:15:17
In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c.
CVE-2023-52429
- EPSS 0.25%
- Veröffentlicht 12.02.2024 03:15:32
- Zuletzt bearbeitet 04.11.2025 19:16:23
dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in alloc_targets) allocate more than INT_MAX bytes, and crash, because of a missing check for struct dm_ioctl.target_count.
CVE-2024-25739
- EPSS 0.25%
- Veröffentlicht 12.02.2024 03:15:32
- Zuletzt bearbeitet 12.05.2026 12:16:18
create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and crash, because of a missing check for ubi->leb_size.
CVE-2024-25740
- EPSS 0.21%
- Veröffentlicht 12.02.2024 03:15:32
- Zuletzt bearbeitet 07.05.2025 21:16:03
A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.
CVE-2024-1151
- EPSS 0.27%
- Veröffentlicht 11.02.2024 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:49:54
A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many fram...