CVE-2022-36879
- EPSS 0.04%
- Veröffentlicht 27.07.2022 04:15:10
- Zuletzt bearbeitet 05.05.2025 16:15:17
An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.
CVE-2020-36558
- EPSS 0.02%
- Veröffentlicht 21.07.2022 04:15:10
- Zuletzt bearbeitet 21.11.2024 05:29:49
A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault.
CVE-2020-36557
- EPSS 0.02%
- Veröffentlicht 21.07.2022 04:15:09
- Zuletzt bearbeitet 21.11.2024 05:29:49
A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lead to a use-after-free.
CVE-2021-33656
- EPSS 0.03%
- Veröffentlicht 18.07.2022 15:15:08
- Zuletzt bearbeitet 02.04.2025 18:33:53
When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.
CVE-2021-33655
- EPSS 0.02%
- Veröffentlicht 18.07.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:09:17
When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.
CVE-2022-2380
- EPSS 0.11%
- Veröffentlicht 13.07.2022 19:15:09
- Zuletzt bearbeitet 23.04.2025 18:15:48
The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel.
CVE-2022-29900
- EPSS 1.41%
- Veröffentlicht 12.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:55
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
CVE-2022-29901
- EPSS 0.07%
- Veröffentlicht 12.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:56
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve ...
CVE-2022-2318
- EPSS 0.1%
- Veröffentlicht 06.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:45
There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges.
CVE-2022-26365
- EPSS 0.04%
- Veröffentlicht 05.07.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:50
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing ...