Vulnerabilities > Linux > Linux Kernel > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-04 | CVE-2023-6240 | A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. | 6.5 |
2024-01-30 | CVE-2024-0564 | Information Exposure Through Discrepancy vulnerability in multiple products A flaw was found in the Linux kernel's memory deduplication mechanism. | 6.5 |
2024-01-25 | CVE-2024-22099 | NULL Pointer Dereference vulnerability in Linux Kernel 2.6.12 NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. | 5.5 |
2024-01-23 | CVE-2023-46343 | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c. | 5.5 |
2024-01-23 | CVE-2024-23848 | Use After Free vulnerability in Linux Kernel In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c. | 5.5 |
2024-01-23 | CVE-2024-23849 | Off-by-one Error vulnerability in Linux Kernel In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access. | 5.5 |
2024-01-23 | CVE-2024-23850 | Unspecified vulnerability in Linux Kernel In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation. | 5.5 |
2024-01-23 | CVE-2024-23851 | Unspecified vulnerability in Linux Kernel copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, and crash, because of a missing param_kernel->data_size check. | 5.5 |
2024-01-18 | CVE-2024-0607 | A flaw was found in the Netfilter subsystem in the Linux kernel. | 6.6 |
2024-01-17 | CVE-2024-0639 | Improper Locking vulnerability in multiple products A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. | 5.5 |