Linux Kernel vulnerabilities
91 known vulnerabilities affecting linux/kernel.
Total CVEs
91
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH56MEDIUM30LOW4
Vulnerabilities
Page 4 of 5
CVE-2023-5197P4MEDIUMCVSS 6.6≥ 5.9, < 6.62023-09-27
CVE-2023-5197 [MEDIUM] CWE-416 CVE-2023-5197: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free.
We recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.
nvd
CVE-2022-3594P4MEDIUMCVSS 5.3vn/a2022-10-18
CVE-2022-3594 [MEDIUM] CWE-404 CVE-2022-3594: A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vul
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The associ
nvd
CVE-2019-19332P4MEDIUMCVSS 6.1v3.13 through 5.42020-01-09
CVE-2019-19332 [MEDIUM] CWE-787 CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the
An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access the '/dev/kvm' device could use this flaw to crash the system, resulting
nvd
CVE-2022-3567P4MEDIUMCVSS 6.4vn/a2022-10-17
CVE-2022-3567 [MEDIUM] CWE-362 CVE-2022-3567: A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability aff
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function inet6_stream_ops/inet6_dgram_ops of the component IPv6 Handler. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211090 is the identifier assigned to this vulnerability.
nvd
CVE-2022-3523P4MEDIUMCVSS 5.3vn/a2022-10-16
CVE-2022-3523 [MEDIUM] CWE-119 CVE-2022-3523: A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unk
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is
nvd
CVE-2022-3435P4MEDIUMCVSS 4.3vn/a2022-10-08
CVE-2022-3435 [MEDIUM] CWE-119 CVE-2022-3435: A vulnerability classified as problematic has been found in Linux Kernel. This affects the function
A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357
nvd
CVE-2022-42432P4MEDIUMCVSS 4.4v6.0-rc22023-03-29
CVE-2022-42432 [MEDIUM] CWE-457 CVE-2022-42432: This vulnerability allows local attackers to disclose sensitive information on affected installation
This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the nft_osf_eval function. The issue results from the
nvd
CVE-2009-2406P4MEDIUMCVSS 6.9v2.6.24.7v2.6.25.152009-07-31
CVE-2009-2406 [MEDIUM] CWE-119 CVE-2009-2406: Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCr
Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to not ensuring that the key signature length in a Tag
nvd
CVE-2022-36280P4MEDIUMCVSS 5.5≥ v3.2-rc1, < 5.13.0-52*2022-09-09
CVE-2022-36280 [MEDIUM] CWE-120 CVE-2022-36280: An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/v
An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2022-40133P4MEDIUMCVSS 5.5≥ v4.20-rc1, < 5.13.0-52*2022-09-09
CVE-2022-40133 [MEDIUM] CWE-416 CVE-2022-40133: A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/v
A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2018-10872P4MEDIUMCVSS 5.5vn/a2018-07-10
CVE-2018-10872 [MEDIUM] CWE-250 CVE-2018-10872: A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch opera
A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, processor does not deliver interrupts and exceptions, they are delivered once the first instruction after the stack switch is executed. An unprivileged system user could use th
nvd
CVE-2022-3563P4MEDIUMCVSS 5.7vn/a2022-10-17
CVE-2022-3563 [MEDIUM] CWE-404 CVE-2022-3563: A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function r
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer dereference. It is recommended to apply a patch to fix this issue. VDB-211086 is the identifier assigne
nvd
CVE-2022-3524P4MEDIUMCVSS 5.5vn/a2022-10-16
CVE-2022-3524 [MEDIUM] CWE-404 CVE-2022-3524: A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vul
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211021 was assigned to this
nvd
CVE-2022-38096P4MEDIUMCVSS 5.5≥ v4.20-rc1, < 5.13.0-52*2022-09-09
CVE-2022-38096 [MEDIUM] CWE-476 CVE-2022-38096: A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_exe
A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2017-2618P4MEDIUMCVSS 5.5v4.9.102018-07-27
CVE-2017-2618 [MEDIUM] CWE-193 CVE-2017-2618: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr fil
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
nvd
CVE-2022-38457P4MEDIUMCVSS 5.5≥ v4.20-rc1, < 5.13.0-52*2022-09-09
CVE-2022-38457 [MEDIUM] CWE-416 CVE-2022-38457: A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/
A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2022-3533P4MEDIUMCVSS 5.7vn/a2022-10-17
CVE-2022-3533 [MEDIUM] CWE-404 CVE-2022-3533: A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the
A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the function parse_usdt_arg of the file tools/lib/bpf/usdt.c of the component BPF. The manipulation of the argument reg_name leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-21
nvd
CVE-2022-36402P4MEDIUMCVSS 5.5≥ v4.3-rc1, < 5.13.0-52*2022-09-16
CVE-2022-36402 [MEDIUM] CWE-118 CVE-2022-36402: An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c
An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2022-3606P4MEDIUMCVSS 5.5vn/a2022-10-19
CVE-2022-3606 [MEDIUM] CWE-404 CVE-2022-3606: A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the f
A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to apply a patch to fix this issue. The identifier VDB-211749 was assigned to this vulnerability
nvd
CVE-2022-3595P4MEDIUMCVSS 5.5vn/a2022-10-18
CVE-2022-3595 [MEDIUM] CWE-119 CVE-2022-3595: A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue
A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess_free_buffer of the file fs/cifs/sess.c of the component CIFS Handler. The manipulation leads to double free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211364.
nvd