← Back

Linux Kernel

linux_kernel

Vendor: Linux • 14,504 CVEs

CVEs (14,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linux
1Linux Kernel
Apr 23, 2026
Feb 24, 2007
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (memory consumption) and possibly bypass memory limits or cause other processes to be killed by creat...Show more
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (memory consumption) and possibly bypass memory limits or cause other processes to be killed by creating a large number of posix timers, which are allocated in kernel memory but are not treated as part of the process' memory.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Feb 20, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer.
1Linux
1Linux Kernel
Apr 23, 2026
Feb 15, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
Linux kernel 2.6.x before 2.6.20 allows local users to read unreadable binaries by using the interpreter (PT_INTERP) functionality and triggering a core dump, a variant of CVE-2004-1073.
1Linux
1Linux Kernel
Apr 23, 2026
Feb 7, 2007
N/A· v4
N/A· v3
1.9 LOW· v2
umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mount...Show more
umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, which might allow the users to obtain sensitive information, including core file contents.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Feb 6, 2007
N/A· v4
N/A· v3
1.9 LOW· v2
The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as o...Show more
The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."Show less
1Linux
1Linux Kernel
Apr 23, 2026
Jan 30, 2007
N/A· v4
N/A· v3
9.4 HIGH· v2
The dev_queue_xmit function in Linux kernel 2.6 can fail before calling the local_bh_disable function, which could lead to data corruption and "node lockups." NOTE: it is not clear whether this issue is exploitable.
1Linux
1Linux Kernel
Apr 23, 2026
Jan 30, 2007
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The aio_setup_ring function in Linux kernel does not properly initialize a variable, which allows local users to cause a denial of service (crash) via an unspecified error path that causes an incorrect free operation.
2Linux
Redhat
3Enterprise Linux
Enterprise Linux DesktopLinux Kernel
Apr 23, 2026
Jan 30, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors.
1Linux
1Linux Kernel
Apr 23, 2026
Jan 12, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified versions of the Linux kernel allow local users to cause a denial of service (unrecoverable zombie process) via a program with certain instructions that prevent init from properly reaping a child whose parent...Show more
Unspecified versions of the Linux kernel allow local users to cause a denial of service (unrecoverable zombie process) via a program with certain instructions that prevent init from properly reaping a child whose parent has died.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Dec 31, 2006
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Linux kernel before 2.6.18, when running on x86_64 systems, does not properly save or restore EFLAGS during a context switch, which allows local users to cause a denial of service (crash) by causing SYSENTER to set an NT...Show more
Linux kernel before 2.6.18, when running on x86_64 systems, does not properly save or restore EFLAGS during a context switch, which allows local users to cause a denial of service (crash) by causing SYSENTER to set an NT flag, which can trigger a crash on the IRET of the next task.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Dec 31, 2006
N/A· v4
N/A· v3
1.7 LOW· v2
The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has unknown attack vect...Show more
The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has unknown attack vectors and results in a system crash.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Dec 20, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.
1Linux
1Linux Kernel
Apr 23, 2026
Dec 19, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in the cmtp_recv_interopmsg function in the Bluetooth driver (net/bluetooth/cmtp/capi.c) in the Linux kernel 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.18.6, and 2.6.19.x, allow remote attackers...Show more
Multiple buffer overflows in the cmtp_recv_interopmsg function in the Bluetooth driver (net/bluetooth/cmtp/capi.c) in the Linux kernel 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.18.6, and 2.6.19.x, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via CAPI messages with a large value for the length of the (1) manu (manufacturer) or (2) serial (serial number) field.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Dec 14, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
The do_coredump function in fs/exec.c in the Linux kernel 2.6.19 sets the flag variable to O_EXCL but does not use it, which allows context-dependent attackers to modify arbitrary files via a rewrite attack during a core...Show more
The do_coredump function in fs/exec.c in the Linux kernel 2.6.19 sets the flag variable to O_EXCL but does not use it, which allows context-dependent attackers to modify arbitrary files via a rewrite attack during a core dump.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Dec 11, 2006
N/A· v4
N/A· v3
4.1 MEDIUM· v2
smbfs in Linux kernel 2.6.8 and other versions, and 2.4.x before 2.4.34, when UNIX extensions are enabled, ignores certain mount options, which could cause clients to use server-specified uid, gid and mode settings.
1Linux
1Linux Kernel
Apr 23, 2026
Dec 6, 2006
N/A· v4
N/A· v3
7.8 HIGH· v2
The tr_rx function in ibmtr.c for Linux kernel 2.6.19 assigns the wrong flag to the ip_summed field, which allows remote attackers to cause a denial of service (memory corruption) via crafted packets that cause the kerne...Show more
The tr_rx function in ibmtr.c for Linux kernel 2.6.19 assigns the wrong flag to the ip_summed field, which allows remote attackers to cause a denial of service (memory corruption) via crafted packets that cause the kernel to interpret another field as an offset.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Dec 2, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer overflow in the get_fdb_entries function in net/bridge/br_ioctl.c in the Linux kernel before 2.6.18.4 allows local users to execute arbitrary code via a large maxnum value in an ioctl request.
1Linux
1Linux Kernel
Apr 23, 2026
Nov 27, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
The ReiserFS functionality in Linux kernel 2.6.18, and possibly other versions, allows local users to cause a denial of service via a malformed ReiserFS file system that triggers memory corruption when a sync is performe...Show more
The ReiserFS functionality in Linux kernel 2.6.18, and possibly other versions, allows local users to cause a denial of service via a malformed ReiserFS file system that triggers memory corruption when a sync is performed.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Nov 22, 2006
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The NTFS filesystem code in Linux kernel 2.6.x up to 2.6.18, and possibly other versions, allows local users to cause a denial of service (CPU consumption) via a malformed NTFS file stream that triggers an infinite loop...Show more
The NTFS filesystem code in Linux kernel 2.6.x up to 2.6.18, and possibly other versions, allows local users to cause a denial of service (CPU consumption) via a malformed NTFS file stream that triggers an infinite loop in the __find_get_block_slow function.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Nov 22, 2006
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The minix filesystem code in Linux kernel 2.6.x before 2.6.24, including 2.6.18, allows local users to cause a denial of service (hang) via a malformed minix file stream that triggers an infinite loop in the minix_bmap f...Show more
The minix filesystem code in Linux kernel 2.6.x before 2.6.24, including 2.6.18, allows local users to cause a denial of service (hang) via a malformed minix file stream that triggers an infinite loop in the minix_bmap function. NOTE: this issue might be due to an integer overflow or signedness error.Show less