Vulnerabilities > Linux > Linux Kernel > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2023-0468 Use After Free vulnerability in Linux Kernel
A use-after-free flaw was found in io_uring/poll.c in io_poll_check_events in the io_uring subcomponent in the Linux Kernel due to a race condition of poll_refs.
local
high complexity
linux CWE-416
4.7
2023-01-26 CVE-2023-0469 Use After Free vulnerability in Linux Kernel
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup.
local
low complexity
linux CWE-416
5.5
2023-01-17 CVE-2022-47929 NULL Pointer Dereference vulnerability in multiple products
In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands.
local
low complexity
linux debian CWE-476
5.5
2023-01-12 CVE-2022-3628 Classic Buffer Overflow vulnerability in Linux Kernel 6.1
A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver.
low complexity
linux CWE-120
6.6
2023-01-12 CVE-2022-4842 Unspecified vulnerability in Linux Kernel 6.2
A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found.
local
low complexity
linux
5.5
2023-01-12 CVE-2023-23454 Type Confusion vulnerability in multiple products
cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).
local
low complexity
linux debian CWE-843
5.5
2023-01-12 CVE-2023-23455 Type Confusion vulnerability in multiple products
atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).
local
low complexity
linux debian CWE-843
5.5
2023-01-11 CVE-2022-4543 Information Exposure Through Discrepancy vulnerability in Linux Kernel
A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI).
local
low complexity
linux CWE-203
5.5
2023-01-10 CVE-2022-4382 Unspecified vulnerability in Linux Kernel
A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found.
high complexity
linux
6.4
2022-12-23 CVE-2022-47946 Use After Free vulnerability in Linux Kernel
An issue was discovered in the Linux kernel 5.10.x before 5.10.155.
local
low complexity
linux CWE-416
5.5