CVE-2022-0995
- EPSS 6.2%
- Veröffentlicht 25.03.2022 19:15:10
- Zuletzt bearbeitet 27.08.2026 04:16:39
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of ser...
- EPSS 0.15%
- Veröffentlicht 16.03.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:20:00
In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...
CVE-2021-39698
- EPSS 0.25%
- Veröffentlicht 16.03.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:20:02
In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...
- EPSS 0.37%
- Veröffentlicht 10.03.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:47:52
Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table i...
CVE-2021-20320
- EPSS 0.25%
- Veröffentlicht 18.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:22
A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.
CVE-2022-25265
- EPSS 1.05%
- Veröffentlicht 16.02.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:54
In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable ...
CVE-2021-3773
- EPSS 5.28%
- Veröffentlicht 16.02.2022 19:15:08
- Zuletzt bearbeitet 28.03.2025 15:15:41
A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
CVE-2021-44879
- EPSS 1.23%
- Veröffentlicht 14.02.2022 12:15:15
- Zuletzt bearbeitet 21.11.2024 06:31:39
In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.
CVE-2021-33061
- EPSS 0.28%
- Veröffentlicht 09.02.2022 23:15:15
- Zuletzt bearbeitet 05.05.2025 17:17:05
Insufficient control flow management for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user to potentially enable denial of service via local access.
CVE-2021-33096
- EPSS 0.28%
- Veröffentlicht 09.02.2022 23:15:15
- Zuletzt bearbeitet 05.05.2025 17:17:07
Improper isolation of shared resources in network on chip for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user to potentially enable denial of service via local access.