Vulnerabilities > Linux
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-09 | CVE-2023-50431 | Unspecified vulnerability in Linux Kernel sec_attest_info in drivers/accel/habanalabs/common/habanalabs_ioctl.c in the Linux kernel through 6.6.5 allows an information leak to user space because info->pad0 is not initialized. | 5.5 |
2023-12-09 | CVE-2023-6560 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Linux Kernel An out-of-bounds memory access flaw was found in the io_uring SQ/CQ rings functionality in the Linux kernel. | 5.5 |
2023-12-08 | CVE-2023-6622 | NULL Pointer Dereference vulnerability in multiple products A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. | 5.5 |
2023-12-08 | CVE-2023-6606 | Out-of-bounds Read vulnerability in multiple products An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. | 7.1 |
2023-12-08 | CVE-2023-6610 | Out-of-bounds Read vulnerability in multiple products An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. | 7.1 |
2023-11-23 | CVE-2023-5972 | NULL Pointer Dereference vulnerability in multiple products A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. | 7.8 |
2023-11-21 | CVE-2023-6238 | Classic Buffer Overflow vulnerability in multiple products A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. | 6.7 |
2023-11-16 | CVE-2023-6176 | NULL Pointer Dereference vulnerability in multiple products A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. | 4.7 |
2023-11-14 | CVE-2023-6111 | Use After Free vulnerability in Linux Kernel A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times. We recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630. | 7.8 |
2023-11-09 | CVE-2023-39198 | Use After Free vulnerability in multiple products A race condition was found in the QXL driver in the Linux kernel. | 6.4 |