CVE-2020-12656
- EPSS 0.33%
- Veröffentlicht 05.05.2020 06:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:00
gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This was disputed with the assertion that the issue do...
CVE-2020-12652
- EPSS 0.33%
- Veröffentlicht 05.05.2020 05:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:59
The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to hold an incorrect lock during the ioctl operation and trigger a race condition, i.e., a "double fetch" vulnerability, aka CID-28d76...
CVE-2020-12654
- EPSS 1.22%
- Veröffentlicht 05.05.2020 05:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:59
An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an incorrect memcpy, aka CID-3a9b153c5591.
CVE-2020-12114
- EPSS 0.42%
- Veröffentlicht 04.05.2020 12:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:16
A pivot_root race condition in fs/namespace.c in the Linux kernel 4.4.x before 4.4.221, 4.9.x before 4.9.221, 4.14.x before 4.14.178, 4.19.x before 4.19.119, and 5.x before 5.3 allows local users to cause a denial of service (panic) by corrupting a m...
CVE-2020-12464
- EPSS 0.8%
- Veröffentlicht 29.04.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:45
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
- EPSS 0.4%
- Veröffentlicht 29.04.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:58:49
In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade...
CVE-2020-0067
- EPSS 0.48%
- Veröffentlicht 17.04.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:52:50
In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Pr...
CVE-2020-11669
- EPSS 0.48%
- Veröffentlicht 10.04.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:21
An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does not have save/restore functionality for PNV_POWERSAVE_AMR, PNV_POWERSAVE_UAMOR, and PNV_POWERSAVE_AMOR, aka CID-53a712bae5dd.
CVE-2020-8832
- EPSS 0.45%
- Veröffentlicht 10.04.2020 00:15:11
- Zuletzt bearbeitet 21.11.2024 05:39:31
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of th...
CVE-2020-8834
- EPSS 0.35%
- Veröffentlicht 09.04.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:32
KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kerne...