CVE-2023-31436
- EPSS 0.04%
- Veröffentlicht 28.04.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 08:01:51
qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.
CVE-2023-0458
- EPSS 0.14%
- Veröffentlicht 26.04.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:13
A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend ...
CVE-2023-0045
- EPSS 0.28%
- Veröffentlicht 25.04.2023 23:15:09
- Zuletzt bearbeitet 13.02.2025 17:15:52
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctr...
CVE-2023-2269
- EPSS 0.03%
- Veröffentlicht 25.04.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:58:16
A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.
CVE-2023-31085
- EPSS 0.01%
- Veröffentlicht 24.04.2023 06:15:08
- Zuletzt bearbeitet 21.11.2024 08:01:23
An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2. There is a divide-by-zero error in do_div(sz,mtd->erasesize), used indirectly by ctrl_cdev_ioctl, when mtd->erasesize is 0.
CVE-2023-31083
- EPSS 0.01%
- Veröffentlicht 24.04.2023 06:15:07
- Zuletzt bearbeitet 03.11.2025 22:16:17
An issue was discovered in drivers/bluetooth/hci_ldisc.c in the Linux kernel 6.2. In hci_uart_tty_ioctl, there is a race condition between HCIUARTSETPROTO and HCIUARTGETPROTO. HCI_UART_PROTO_SET is set before hu->proto is set. A NULL pointer derefere...
CVE-2023-31084
- EPSS 0.01%
- Veröffentlicht 24.04.2023 06:15:07
- Zuletzt bearbeitet 18.03.2025 20:15:19
An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test...
CVE-2023-1998
- EPSS 0.11%
- Veröffentlicht 21.04.2023 15:15:07
- Zuletzt bearbeitet 13.02.2025 17:16:01
The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud provider, the k...
CVE-2023-2194
- EPSS 0.02%
- Veröffentlicht 20.04.2023 21:15:09
- Zuletzt bearbeitet 23.04.2025 17:16:29
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of ...
CVE-2023-2177
- EPSS 0.01%
- Veröffentlicht 20.04.2023 21:15:08
- Zuletzt bearbeitet 18.03.2025 20:15:19
A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If stream_in allocation is failed, stream_out is freed which would further be accessed. A local user could use this flaw to crash the ...