CVE-2021-38199
- EPSS 1.25%
- Veröffentlicht 08.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:38
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during tru...
CVE-2021-38204
- EPSS 0.33%
- Veröffentlicht 08.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:39
drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.
CVE-2021-38205
- EPSS 0.33%
- Veröffentlicht 08.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:39
drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).
CVE-2021-38207
- EPSS 3.35%
- Veröffentlicht 08.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:39
drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.
CVE-2021-38208
- EPSS 0.49%
- Veröffentlicht 08.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:40
net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NULL pointer dereference and BUG) by making a getsockname call after a certain type of failure of a bind call.
CVE-2021-38160
- EPSS 0.4%
- Veröffentlicht 07.08.2021 04:15:06
- Zuletzt bearbeitet 05.05.2025 14:12:40
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is...
CVE-2021-3655
- EPSS 0.31%
- Veröffentlicht 05.08.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:22:05
A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
CVE-2021-3679
- EPSS 0.73%
- Veröffentlicht 05.08.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:08
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw ...
CVE-2021-34556
- EPSS 0.42%
- Veröffentlicht 02.08.2021 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:10:40
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory l...
CVE-2021-35477
- EPSS 0.46%
- Veröffentlicht 02.08.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:21
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a st...