Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-42358 Infinite Loop vulnerability in Msweet Pdfio
PDFio is a simple C library for reading and writing PDF files.
local
low complexity
msweet CWE-835
5.5
2024-07-29 CVE-2024-41088 Infinite Loop vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: can: mcp251xfd: fix infinite loop when xmit fails When the mcp251xfd_start_xmit() function fails, the driver stops processing messages, and the interrupt routine does not return, running indefinitely even after killing the running application. Error messages: [ 441.298819] mcp251xfd spi2.0 can0: ERROR in mcp251xfd_start_xmit: -16 [ 441.306498] mcp251xfd spi2.0 can0: Transmit Event FIFO buffer not empty.
local
low complexity
linux CWE-835
5.5
2024-07-23 CVE-2024-40060 Infinite Loop vulnerability in Wcharczuk Go-Chart
go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.
network
low complexity
wcharczuk CWE-835
7.5
2024-07-16 CVE-2022-48840 Infinite Loop vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: iavf: Fix hang during reboot/shutdown Recent commit 974578017fc1 ("iavf: Add waiting so the port is initialized in remove") adds a wait-loop at the beginning of iavf_remove() to ensure that port initialization is finished prior unregistering net device.
local
low complexity
linux CWE-835
5.5
2024-07-16 CVE-2022-48862 Infinite Loop vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: vhost: fix hung thread due to erroneous iotlb entries In vhost_iotlb_add_range_ctx(), range size can overflow to 0 when start is 0 and last is ULONG_MAX.
local
low complexity
linux CWE-835
5.5
2024-07-12 CVE-2024-40995 Infinite Loop vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() syzbot found hanging tasks waiting on rtnl_lock [1] A reproducer is available in the syzbot bug. When a request to add multiple actions with the same index is sent, the second request will block forever on the first request.
local
low complexity
linux CWE-835
5.5
2024-07-01 CVE-2024-36990 Infinite Loop vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the admin or power Splunk roles could send a specially crafted HTTP POST request to the datamodel/web REST endpoint in Splunk Enterprise, potentially causing a denial of service.
network
low complexity
splunk CWE-835
6.5
2024-06-21 CVE-2024-36288 Infinite Loop vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated.
local
low complexity
linux CWE-835
5.5
2024-06-20 CVE-2021-47617 Infinite Loop vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: PCI: pciehp: Fix infinite loop in IRQ handler upon power fault The Power Fault Detected bit in the Slot Status register differs from all other hotplug events in that it is sticky: It can only be cleared after turning off slot power.
local
low complexity
linux CWE-835
5.5
2024-06-13 CVE-2024-5949 Infinite Loop vulnerability in Deepseaelectronics Dse855 Firmware 1.1.0
Deep Sea Electronics DSE855 Multipart Boundary Infinite Loop Denial-of-Service Vulnerability.
low complexity
deepseaelectronics CWE-835
6.5