Vulnerabilities > Linux > Linux Kernel > 5.17.14

DATE CVE VULNERABILITY TITLE RISK
2022-12-23 CVE-2022-47939 Use After Free vulnerability in Linux Kernel
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2.
network
low complexity
linux CWE-416
critical
9.8
2022-12-23 CVE-2022-47941 Memory Leak vulnerability in Linux Kernel
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2.
network
low complexity
linux CWE-401
7.5
2022-12-23 CVE-2022-47942 Out-of-bounds Write vulnerability in Linux Kernel
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2.
network
low complexity
linux CWE-787
8.8
2022-12-18 CVE-2022-47518 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in the Linux kernel before 6.0.11.
local
low complexity
linux debian netapp CWE-787
7.8
2022-12-18 CVE-2022-47519 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in the Linux kernel before 6.0.11.
local
low complexity
linux debian netapp CWE-787
7.8
2022-12-18 CVE-2022-47520 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in the Linux kernel before 6.0.11.
local
low complexity
linux debian netapp CWE-125
7.1
2022-12-18 CVE-2022-47521 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in the Linux kernel before 6.0.11.
local
low complexity
linux debian netapp CWE-787
7.8
2022-12-07 CVE-2022-3643 Injection vulnerability in multiple products
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets.
local
low complexity
linux debian CWE-74
6.5
2022-12-07 CVE-2022-42328 Improper Locking vulnerability in multiple products
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free the SKB of a packet dropped due to the XSA-392 handling (CVE-2022-42328).
local
low complexity
linux debian CWE-667
5.5
2022-12-07 CVE-2022-42329 Improper Locking vulnerability in multiple products
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free the SKB of a packet dropped due to the XSA-392 handling (CVE-2022-42328).
local
low complexity
linux debian CWE-667
5.5