cbcvebase.

Linux Kernel vulnerabilities

91 known vulnerabilities affecting linux/kernel.

Total CVEs
91
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH56MEDIUM30LOW4

Vulnerabilities

Page 3 of 5
CVE-2022-3565P3HIGHCVSS 7.8vn/a2022-10-17
CVE-2022-3565 [HIGH] CWE-119 CVE-2022-3565: A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211088.
nvd
CVE-2009-2847P4MEDIUMCVSS 4.9PoCv2.6.24.7v2.6.25.152009-08-18
CVE-2009-2847 [MEDIUM] CVE-2009-2847: The do_sigaltstack function in kernel/signal.c in Linux kernel 2.4 through 2.4.37 and 2.6 before 2.6 The do_sigaltstack function in kernel/signal.c in Linux kernel 2.4 through 2.4.37 and 2.6 before 2.6.31-rc5, when running on 64-bit systems, does not clear certain padding bytes from a structure, which allows local users to obtain sensitive information from the kernel stack via the sigaltstack function.
nvd
CVE-2019-14816P3HIGHCVSS 7.8vall versions up to, excluding 5.32019-09-20
CVE-2019-14816 [HIGH] CWE-122 CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wif There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
nvd
CVE-2019-14814P3HIGHCVSS 7.8vall versions up to, excluding 5.32019-09-20
CVE-2019-14814 [HIGH] CWE-122 CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marve There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
nvd
CVE-2019-14815P3HIGHCVSS 7.8vn/a2019-11-25
CVE-2019-14815 [HIGH] CWE-122 CVE-2019-14815: A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
nvd
CVE-2022-3541P3HIGHCVSS 7.8vn/a2022-10-17
CVE-2022-3541 [HIGH] CWE-119 CVE-2022-3541: A vulnerability classified as critical has been found in Linux Kernel. This affects the function spl A vulnerability classified as critical has been found in Linux Kernel. This affects the function spl2sw_nvmem_get_mac_address of the file drivers/net/ethernet/sunplus/spl2sw_driver.c of the component BPF. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211041 was assigned to this vulnera
nvd
CVE-2022-3625P3HIGHCVSS 7.8vn/a2022-10-21
CVE-2022-3625 [HIGH] CWE-119 CVE-2022-3625: A vulnerability was found in Linux Kernel. It has been classified as critical. This affects the func A vulnerability was found in Linux Kernel. It has been classified as critical. This affects the function devlink_param_set/devlink_param_get of the file net/core/devlink.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211929 was assigned to this vulnerability.
nvd
CVE-2022-3526P3HIGHCVSS 7.5vn/a2022-10-16
CVE-2022-3526 [HIGH] CWE-404 CVE-2022-3526: A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the function macvlan_handle_frame of the file drivers/net/macvlan.c of the component skb. The manipulation leads to memory leak. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is
nvd
CVE-2009-1389P3HIGHCVSS 7.8v2.6.24.7v2.6.25.152009-06-16
CVE-2009-1389 [HIGH] CWE-119 CVE-2009-1389: Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 al Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.
nvd
CVE-2023-6931P3HIGHCVSS 7.0≥ 4.3, < 6.72023-12-19
CVE-2023-6931 [HIGH] CWE-787 CVE-2023-6931: A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component c A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.
nvd
CVE-2023-4622P3HIGHCVSS 7.0≥ 4.2, < 6.1.472023-09-06
CVE-2023-4622 [HIGH] CWE-416 CVE-2023-4622: A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve l A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released b
nvd
CVE-2023-6932P4HIGHCVSS 7.0≥ 2.6.12, < 6.72023-12-19
CVE-2023-6932 [HIGH] CWE-416 CVE-2023-6932: A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achiev A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread. We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.
nvd
CVE-2022-3621P4MEDIUMCVSS 6.5vn/a2022-10-20
CVE-2022-3621 [MEDIUM] CWE-404 CVE-2022-3621: A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the fu A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipulation leads to null pointer dereference. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifi
nvd
CVE-2023-4244P4HIGHCVSS 7.0≥ 0.0, < 6.52023-09-06
CVE-2023-4244 [HIGH] CWE-416 CVE-2023-4244: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability. We reco
nvd
CVE-2022-3649P4HIGHCVSS 7.0vn/a2022-10-21
CVE-2022-3649 [HIGH] CWE-119 CVE-2022-3649: A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the fu A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability i
nvd
CVE-2009-2844P4HIGHCVSS 7.8v2.6.24.7v2.6.25.152009-08-18
CVE-2009-2844 [HIGH] CWE-399 CVE-2009-2844: cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies fu
nvd
CVE-2022-3564P4HIGHCVSS 7.1vn/a2022-10-17
CVE-2022-3564 [HIGH] CWE-119 CVE-2022-3564: A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-2110
nvd
CVE-2021-34981P4MEDIUMCVSS 6.7v4.15.0-118-generic2024-05-07
CVE-2021-34981 [MEDIUM] CWE-415 CVE-2021-34981: Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerability. This vulnerabilit Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists
nvd
CVE-2022-3635P4HIGHCVSS 7.0vn/a2022-10-21
CVE-2022-3635 [HIGH] CWE-119 CVE-2022-3635: A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function tst_timer of the file drivers/atm/idt77252.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. VDB-211934 is the identifier assigned to this vulnerability.
nvd
CVE-2022-3566P4HIGHCVSS 7.1vn/a2022-10-17
CVE-2022-3566 [HIGH] CWE-362 CVE-2022-3566: A vulnerability, which was classified as problematic, was found in Linux Kernel. This affects the fu A vulnerability, which was classified as problematic, was found in Linux Kernel. This affects the function tcp_getsockopt/tcp_setsockopt of the component TCP Handler. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. The identifier VDB-211089 was assigned to this vulnerability.
nvd