cbcvebase.

Linux Kernel vulnerabilities

99 known vulnerabilities affecting linux/kernel.

Total CVEs
99
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH64MEDIUM30LOW4

Vulnerabilities

Page 5 of 5
CVE-2022-3524P4MEDIUMCVSS 5.5vn/a2022-10-16
CVE-2022-3524 [MEDIUM] CWE-404 CVE-2022-3524: A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vul A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211021 was assigned to this
nvd
CVE-2022-38096P4MEDIUMCVSS 5.5≥ v4.20-rc1, < 5.13.0-52*2022-09-09
CVE-2022-38096 [MEDIUM] CWE-476 CVE-2022-38096: A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_exe A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2022-40133P4MEDIUMCVSS 5.5≥ v4.20-rc1, < 5.13.0-52*2022-09-09
CVE-2022-40133 [MEDIUM] CWE-416 CVE-2022-40133: A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/v A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2022-38457P4MEDIUMCVSS 5.5≥ v4.20-rc1, < 5.13.0-52*2022-09-09
CVE-2022-38457 [MEDIUM] CWE-416 CVE-2022-38457: A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/ A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2017-2618P4MEDIUMCVSS 5.5v4.9.102018-07-27
CVE-2017-2618 [MEDIUM] CWE-193 CVE-2017-2618: A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr fil A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
nvd
CVE-2022-36402P4MEDIUMCVSS 5.5≥ v4.3-rc1, < 5.13.0-52*2022-09-16
CVE-2022-36402 [MEDIUM] CWE-118 CVE-2022-36402: An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).
nvd
CVE-2022-3606P4MEDIUMCVSS 5.5vn/a2022-10-19
CVE-2022-3606 [MEDIUM] CWE-404 CVE-2022-3606: A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the f A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to apply a patch to fix this issue. The identifier VDB-211749 was assigned to this vulnerability
nvd
CVE-2022-3595P4MEDIUMCVSS 5.5vn/a2022-10-18
CVE-2022-3595 [MEDIUM] CWE-119 CVE-2022-3595: A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess_free_buffer of the file fs/cifs/sess.c of the component CIFS Handler. The manipulation leads to double free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211364.
nvd
CVE-2022-3543P4MEDIUMCVSS 5.5vn/a2022-10-17
CVE-2022-3543 [MEDIUM] CWE-404 CVE-2022-3543: A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue aff A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function unix_sock_destructor/unix_release_sock of the file net/unix/af_unix.c of the component BPF. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is
nvd
CVE-2022-3544P4MEDIUMCVSS 5.5vn/a2022-10-17
CVE-2022-3544 [MEDIUM] CWE-404 CVE-2022-3544: A vulnerability, which was classified as problematic, was found in Linux Kernel. Affected is the fun A vulnerability, which was classified as problematic, was found in Linux Kernel. Affected is the function damon_sysfs_add_target of the file mm/damon/sysfs.c of the component Netfilter. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211044.
nvd
CVE-2022-3630P4MEDIUMCVSS 5.5vn/a2022-10-21
CVE-2022-3630 [MEDIUM] CWE-404 CVE-2022-3630: A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects some A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects some unknown processing of the file fs/fscache/cookie.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211931.
nvd
CVE-2022-3637P4MEDIUMCVSS 5.5vn/a2022-10-21
CVE-2022-3637 [MEDIUM] CWE-404 CVE-2022-3637: A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability aff A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211936.
nvd
CVE-2022-3646P4MEDIUMCVSS 4.3vn/a2022-10-21
CVE-2022-3646 [MEDIUM] CWE-404 CVE-2022-3646: A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue aff A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211961
nvd
CVE-2009-3624P4MEDIUMCVSS 4.6v2.6.24.7v2.6.25.152009-11-02
CVE-2009-3624 [MEDIUM] CWE-310 CVE-2009-3624: The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of service (OOPS) via vectors involving calls to this function without specifying a keyring by ID, as demo
nvd
CVE-2022-3619P4MEDIUMCVSS 4.3vn/a2022-10-20
CVE-2022-3619 [MEDIUM] CWE-404 CVE-2022-3619: A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability aff A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. VDB-211918 is the identifier assigned to this vulnerabil
nvd
CVE-2022-3629P4LOWCVSS 3.3vn/a2022-10-21
CVE-2022-3629 [LOW] CWE-401 CVE-2022-3629: A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability a A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack is rather high. The exploitation appears to be difficult. It is recommended to apply a patch to fix this issue. VDB-2
nvd
CVE-2022-3624P4LOWCVSS 3.3vn/a2022-10-21
CVE-2022-3624 [LOW] CWE-404 CVE-2022-3624: A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is t A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211928.
nvd
CVE-2022-3633P4LOWCVSS 3.3vn/a2022-10-21
CVE-2022-3633 [LOW] CWE-401 CVE-2022-3633: A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211932.
nvd
CVE-2022-3521P4LOWCVSS 2.5vn/a2022-10-16
CVE-2022-3521 [LOW] CWE-362 CVE-2022-3521: A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability aff A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211018 is the identifier assigned to this vulnerability.
nvd
Linux Kernel vulnerabilities | cvebase