CVE-2022-0171
- EPSS 0.16%
- Veröffentlicht 26.08.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:04
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Vi...
- EPSS 0.56%
- Veröffentlicht 26.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:41
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant wi...
- EPSS 0.03%
- Veröffentlicht 25.08.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:01:59
A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an...
CVE-2022-2978
- EPSS 0.08%
- Veröffentlicht 24.08.2022 16:15:12
- Zuletzt bearbeitet 21.11.2024 07:02:01
A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentiall...
CVE-2021-3714
- EPSS 0.07%
- Veröffentlicht 23.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:13
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via a local exploitation mechanism. The same technique can be used if an attacker can upload page sized files and ...
CVE-2022-2873
- EPSS 0.04%
- Veröffentlicht 22.08.2022 15:15:15
- Zuletzt bearbeitet 21.11.2024 07:01:51
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to cra...
CVE-2022-26373
- EPSS 0.11%
- Veröffentlicht 18.08.2022 20:15:11
- Zuletzt bearbeitet 05.05.2025 17:18:03
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
CVE-2022-2503
- EPSS 0.01%
- Veröffentlicht 12.08.2022 11:15:07
- Zuletzt bearbeitet 21.11.2024 07:01:07
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads currently allow users with root privileges to switch...
CVE-2022-20368
- EPSS 0.05%
- Veröffentlicht 11.08.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:42:40
Product: AndroidVersions: Android kernelAndroid ID: A-224546354References: Upstream kernel
CVE-2022-20369
- EPSS 0.04%
- Veröffentlicht 11.08.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:42:41
In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...