CVEs (289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FedoraprojectLinux+3 more30Build Of Quarkus Codeready Linux BuilderCommunications Cloud Native Core Binding Support Function+27 moreNov 21, 2024 Mar 18, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege...Show more |
2Linux Netapp14A400 Firmware Aff 8300 FirmwareAff 8700 Firmware+11 moreNov 21, 2024 Mar 18, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d...Show more |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreNov 21, 2024 Mar 18, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quot...Show more |
3Debian LinuxNetapp10Active Iq Unified Manager Debian LinuxH300e Firmware+7 moreNov 21, 2024 Mar 16, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access. |
3Debian LinuxNetapp10Active Iq Unified Manager Debian LinuxH300e Firmware+7 moreNov 21, 2024 Mar 12, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device. |
7Fedoraproject LinuxNetapp+4 more29Codeready Linux Builder Enterprise LinuxEnterprise Linux Eus+26 moreNov 6, 2025 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values....Show more |
5Debian FedoraprojectLinux+2 more23Codeready Linux Builder Debian LinuxEnterprise Linux+20 moreNov 21, 2024 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memo...Show more |
3Fedoraproject LinuxNetapp10Fedora H300e FirmwareH300s Firmware+7 moreNov 21, 2024 Mar 10, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the syste...Show more |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 25, 2025 Mar 6, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters. |
4Fedoraproject LinuxNetapp+1 more13Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+10 moreNov 21, 2024 Mar 4, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash...Show more |
5Canonical DebianFedoraproject+2 more12Debian Linux FedoraH300e Firmware+9 moreNov 21, 2024 Mar 3, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with th...Show more |
6Canonical DebianFedoraproject+3 more37Bootstrap Os Codeready Linux BuilderCodeready Linux Builder For Power Little Endian+34 moreJun 3, 2026 Mar 3, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to esca...Show more |
3Linux NetappRedhat323scale Api Management Build Of QuarkusCodeready Linux Builder Eus+29 moreNov 21, 2024 Mar 3, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in ne...Show more |
5Debian LinuxNetapp+2 more18Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+15 moreNov 21, 2024 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can s...Show more |
6Apple DebianFedoraproject+3 more35Active Iq Unified Manager Bootstrap OsClustered Data Ontap+32 moreMay 5, 2025 Feb 26, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
2Linux Netapp17Bootstrap Os Cloud Volumes Ontap MediatorE Series Santricity Os Controller+14 moreNov 21, 2024 Feb 26, 2022 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate...Show more |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreNov 21, 2024 Feb 18, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user coul...Show more |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreMay 12, 2026 Feb 18, 2022 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker wi...Show more |
5Debian FedoraprojectLinux+2 more21Active Iq Unified Manager Aff A700s FirmwareAff Baseboard Management Controller Firmware+18 moreNov 21, 2024 Feb 18, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remo...Show more |
2Linux Netapp9Baseboard Management Controller Firmware H300e FirmwareH300s Firmware+6 moreNov 21, 2024 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located...Show more |