Vulnerabilities > Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-02-23 CVE-2023-0597 Memory Leak vulnerability in Linux Kernel 6.2
A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data.
local
low complexity
linux CWE-401
5.5
2023-02-22 CVE-2023-23039 Race Condition vulnerability in Linux Kernel
An issue was discovered in the Linux kernel through 6.2.0-rc2.
high complexity
linux CWE-362
5.7
2023-02-17 CVE-2023-23586 Use After Free vulnerability in Linux Kernel
Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process. timens_install calls current_is_single_threaded to determine if the current process is single-threaded, but this call does not consider io_uring's io_worker threads, thus it is possible to insert a time namespace's vvar page to process's memory space via a page fault.
local
low complexity
linux CWE-416
5.5
2023-02-06 CVE-2023-0615 Memory Leak vulnerability in Linux Kernel
A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality.
local
low complexity
linux CWE-401
5.5
2023-02-02 CVE-2023-25012 Use After Free vulnerability in Linux Kernel
The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long.
low complexity
linux CWE-416
4.6
2023-01-26 CVE-2023-0394 Unspecified vulnerability in Linux Kernel
A NULL pointer dereference flaw was found in rawv6_push_pending_frames in net/ipv6/raw.c in the network subcomponent in the Linux kernel.
local
low complexity
linux
5.5
2023-01-26 CVE-2023-0468 Use After Free vulnerability in Linux Kernel
A use-after-free flaw was found in io_uring/poll.c in io_poll_check_events in the io_uring subcomponent in the Linux Kernel due to a race condition of poll_refs.
local
high complexity
linux CWE-416
4.7
2023-01-26 CVE-2023-0469 Use After Free vulnerability in Linux Kernel
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup.
local
low complexity
linux CWE-416
5.5
2023-01-17 CVE-2022-47929 NULL Pointer Dereference vulnerability in multiple products
In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands.
local
low complexity
linux debian CWE-476
5.5
2023-01-12 CVE-2022-3628 Classic Buffer Overflow vulnerability in Linux Kernel 6.1
A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver.
low complexity
linux CWE-120
6.6