← Back

Linux Kernel

linux_kernel

Vendor: Linux • 14,504 CVEs

CVEs (14,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
LinuxSuse
4Linux Enterprise Desktop
Linux Enterprise ServerLinux Kernel+1 more
Apr 29, 2026
Sep 29, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspecified other impact v...Show more
Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspecified other impact via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value that triggers a buffer overflow, a different vulnerability than CVE-2010-3084.Show less
3Linux
SuseVmware
4Esx
Linux KernelSuse Linux Enterprise Desktop+1 more
Apr 29, 2026
Sep 24, 2010
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer...Show more
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt function (aka the MCAST_MSFILTER getsockopt support) to control a certain length value, related to a "stack pointer underflow" issue, as exploited in the wild in September 2010.Show less
3Canonical
LinuxSuse
3Linux Enterprise Real Time Extension
Linux KernelUbuntu Linux
Apr 29, 2026
Sep 22, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is...Show more
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE: this vulnerability exists because of a CVE-2007-4573 regression.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Apr 29, 2026
Sep 21, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members,...Show more
The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump operation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2942.Show less
4Canonical
LinuxOpensuse+1 more
6Linux Enterprise Desktop
Linux Enterprise Real Time ExtensionLinux Enterprise Server+3 more
Apr 29, 2026
Sep 21, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow local users to cause a denial of service or possibly have unspecified othe...Show more
Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow local users to cause a denial of service or possibly have unspecified other impact via an unsuccessful attempt to open the /dev/sequencer device.Show less
5Canonical
LinuxOpensuse+2 more
6Esx
Linux KernelOpensuse+3 more
Apr 29, 2026
Sep 21, 2010
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information f...Show more
The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl call.Show less
5Canonical
DebianLinux+2 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 more
Apr 29, 2026
Sep 21, 2010
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of t...Show more
Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call.Show less
6Avaya
CanonicalLinux+3 more
13Aura Communication Manager
Aura Presence ServicesAura Session Manager+10 more
Apr 29, 2026
Sep 21, 2010
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to o...Show more
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.Show less
3Canonical
LinuxSuse
4Linux Kernel
Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL p...Show more
The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function.Show less
5Debian
FedoraprojectLinux+2 more
8Debian Linux
FedoraLinux Enterprise Desktop+5 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attacke...Show more
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a denial of service (system crash) via crafted CAN traffic.Show less
4Canonical
LinuxOpensuse+1 more
6Linux Enterprise Desktop
Linux Enterprise Real Time ExtensionLinux Enterprise Server+3 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by...Show more
The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size.Show less
4Debian
LinuxOpensuse+1 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise High Availability Extension+4 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4...Show more
The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.Show less
7Avaya
CanonicalDebian+4 more
15Aura Communication Manager
Aura Presence ServicesAura Session Manager+12 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial o...Show more
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.Show less
4Canonical
LinuxSuse+1 more
5Esx
Linux KernelSuse Linux Enterprise Desktop+2 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace h...Show more
The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS mounts via vectors involving an add_key call, related to a "cache stuffing" issue and MS-DFS referrals.Show less
3Canonical
LinuxSuse
5Linux Kernel
Suse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+2 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a...Show more
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.Show less
3Avaya
LinuxVmware
9Aura Communication Manager
Aura Presence ServicesAura Session Manager+6 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash)...Show more
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.Show less
4Canonical
LinuxSuse+1 more
6Esx
Linux Enterprise High Availability ExtensionLinux Kernel+3 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Apr 29, 2026
Sep 8, 2010
N/A· v4
4.7 MEDIUM· v3
4.7 MEDIUM· v2
Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecif...Show more
Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, related to the put_tty_queue and __f_setown functions. NOTE: the vulnerability was addressed in a different way in 2.6.32.9.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Sep 7, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary c...Show more
Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary code via a crafted NFSv4 compound WRITE request, related to the read_buf and nfsd4_decode_compound functions.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Sep 7, 2010
N/A· v4
N/A· v3
7.8 HIGH· v2
fs/cifs/cifssmb.c in the CIFS implementation in the Linux kernel before 2.6.34-rc4 allows remote attackers to cause a denial of service (panic) via an SMB response packet with an invalid CountHigh value, as demonstrated...Show more
fs/cifs/cifssmb.c in the CIFS implementation in the Linux kernel before 2.6.34-rc4 allows remote attackers to cause a denial of service (panic) via an SMB response packet with an invalid CountHigh value, as demonstrated by a response from an OS/2 server, related to the CIFSSMBWrite and CIFSSMBWrite2 functions.Show less