Vulnerabilities > Linux > Linux Kernel > 4.1.38

DATE CVE VULNERABILITY TITLE RISK
2015-11-16 CVE-2015-2925 7PK - Security Features vulnerability in Linux Kernel
The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack."
local
linux CWE-254
6.9
2015-10-19 CVE-2015-7799 Local Denial of Service vulnerability in Google Android 'PPP Character Device Driver'
The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.
local
low complexity
linux
4.9
2015-10-19 CVE-2015-7613 Race Condition vulnerability in Linux Kernel
Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.
local
linux CWE-362
6.9
2015-10-19 CVE-2015-6937 Null Pointer Deference Denial of Service vulnerability in Linux Kernel
The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.
local
low complexity
linux canonical debian
4.9