Vulnerabilities > Linux > Linux Kernel > 4.1.38
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2015-11-16 | CVE-2015-2925 | 7PK - Security Features vulnerability in Linux Kernel The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack." | 6.9 |
2015-10-19 | CVE-2015-7799 | Local Denial of Service vulnerability in Google Android 'PPP Character Device Driver' The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call. | 4.9 |
2015-10-19 | CVE-2015-7613 | Race Condition vulnerability in Linux Kernel Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c. | 6.9 |
2015-10-19 | CVE-2015-6937 | Null Pointer Deference Denial of Service vulnerability in Linux Kernel The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. | 4.9 |