Search CVE reports
281 – 290 of 1263 results
The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlattr array, which allows local users to cause a denial of service (uninitialized...
31 affected packages
linux, linux-armadaxp, linux-aws, linux-azure, linux-euclid...
| Package | 20.04 LTS |
|---|---|
| linux | — |
| linux-armadaxp | — |
| linux-aws | — |
| linux-azure | — |
| linux-euclid | — |
| linux-flo | — |
| linux-gcp | — |
| linux-gke | — |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | — |
| linux-hwe-edge | — |
| linux-kvm | — |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | — |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-qcm-msm | — |
| linux-raspi2 | — |
| linux-snapdragon | — |
| linux-ti-omap4 | — |
The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c,...
104 affected packages
linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux, linux-armadaxp...
| Package | 20.04 LTS |
|---|---|
| linux-aws-fips | Not affected |
| linux-azure-fips | Not affected |
| linux-gcp-fips | Not affected |
| linux | Not affected |
| linux-armadaxp | — |
| linux-aws | Not affected |
| linux-aws-5.15 | Not affected |
| linux-aws-5.4 | Not in release |
| linux-aws-6.14 | Not in release |
| linux-aws-6.8 | Not in release |
| linux-aws-hwe | Not in release |
| linux-azure | Not affected |
| linux-azure-4.15 | Not in release |
| linux-azure-5.15 | Not affected |
| linux-azure-5.4 | Not in release |
| linux-azure-6.11 | Not in release |
| linux-azure-6.8 | Not in release |
| linux-azure-edge | Not in release |
| linux-azure-fde | Ignored |
| linux-azure-fde-5.15 | Ignored |
| linux-azure-nvidia | Not in release |
| linux-bluefield | Not affected |
| linux-euclid | — |
| linux-fips | Not affected |
| linux-flo | — |
| linux-gcp | Not affected |
| linux-gcp-4.15 | Not in release |
| linux-gcp-5.15 | Not affected |
| linux-gcp-5.4 | Not in release |
| linux-gcp-6.11 | Not in release |
| linux-gcp-6.14 | Not in release |
| linux-gcp-6.8 | Not in release |
| linux-gke | Ignored |
| linux-gkeop | Not affected |
| linux-gkeop-5.15 | Not affected |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | Not in release |
| linux-hwe-5.15 | Not affected |
| linux-hwe-5.4 | Not in release |
| linux-hwe-6.11 | Not in release |
| linux-hwe-6.14 | Not in release |
| linux-hwe-6.8 | Not in release |
| linux-hwe-edge | Not in release |
| linux-ibm | Not affected |
| linux-ibm-5.15 | Not affected |
| linux-ibm-5.4 | Not in release |
| linux-ibm-6.8 | Not in release |
| linux-intel | Not in release |
| linux-intel-iot-realtime | Not in release |
| linux-intel-iotg | Not in release |
| linux-intel-iotg-5.15 | Not affected |
| linux-iot | Not affected |
| linux-kvm | Not affected |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lowlatency | Not in release |
| linux-lowlatency-hwe-5.15 | Not affected |
| linux-lowlatency-hwe-6.11 | Not in release |
| linux-lowlatency-hwe-6.8 | Not in release |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | Not in release |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-nvidia | Not in release |
| linux-nvidia-6.11 | Not in release |
| linux-nvidia-6.5 | Not in release |
| linux-nvidia-6.8 | Not in release |
| linux-nvidia-lowlatency | Not in release |
| linux-nvidia-tegra | Not in release |
| linux-nvidia-tegra-5.15 | Not affected |
| linux-nvidia-tegra-igx | Not in release |
| linux-oem | Not in release |
| linux-oem-6.11 | Not in release |
| linux-oem-6.14 | Not in release |
| linux-oem-6.8 | Not in release |
| linux-oracle | Not affected |
| linux-oracle-5.15 | Not affected |
| linux-oracle-5.4 | Not in release |
| linux-oracle-6.14 | Not in release |
| linux-oracle-6.8 | Not in release |
| linux-qcm-msm | — |
| linux-raspi | Not affected |
| linux-raspi-5.4 | Not in release |
| linux-raspi-realtime | Not in release |
| linux-raspi2 | Ignored |
| linux-realtime | Not in release |
| linux-realtime-6.14 | Not in release |
| linux-realtime-6.8 | Not in release |
| linux-riscv | Ignored |
| linux-riscv-5.15 | Not affected |
| linux-riscv-6.14 | Not in release |
| linux-riscv-6.8 | Not in release |
| linux-snapdragon | Not in release |
| linux-ti-omap4 | — |
| linux-xilinx-zynqmp | Not affected |
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and...
103 affected packages
linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux, linux-armadaxp...
| Package | 20.04 LTS |
|---|---|
| linux-aws-fips | Not affected |
| linux-azure-fips | Not affected |
| linux-gcp-fips | Not affected |
| linux | Not affected |
| linux-armadaxp | — |
| linux-aws | Not affected |
| linux-aws-5.15 | Not affected |
| linux-aws-5.4 | Not in release |
| linux-aws-6.14 | Not in release |
| linux-aws-6.8 | Not in release |
| linux-aws-hwe | Not in release |
| linux-azure | Not affected |
| linux-azure-4.15 | Not in release |
| linux-azure-5.15 | Not affected |
| linux-azure-5.4 | Not in release |
| linux-azure-6.11 | Not in release |
| linux-azure-6.8 | Not in release |
| linux-azure-fde | Ignored |
| linux-azure-fde-5.15 | Ignored |
| linux-azure-nvidia | Not in release |
| linux-bluefield | Not affected |
| linux-euclid | — |
| linux-fips | Not affected |
| linux-flo | — |
| linux-gcp | Not affected |
| linux-gcp-4.15 | Not in release |
| linux-gcp-5.15 | Not affected |
| linux-gcp-5.4 | Not in release |
| linux-gcp-6.11 | Not in release |
| linux-gcp-6.14 | Not in release |
| linux-gcp-6.8 | Not in release |
| linux-gke | Ignored |
| linux-gkeop | Not affected |
| linux-gkeop-5.15 | Not affected |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | Not in release |
| linux-hwe-5.15 | Not affected |
| linux-hwe-5.4 | Not in release |
| linux-hwe-6.11 | Not in release |
| linux-hwe-6.14 | Not in release |
| linux-hwe-6.8 | Not in release |
| linux-hwe-edge | Not in release |
| linux-ibm | Not affected |
| linux-ibm-5.15 | Not affected |
| linux-ibm-5.4 | Not in release |
| linux-ibm-6.8 | Not in release |
| linux-intel | Not in release |
| linux-intel-iot-realtime | Not in release |
| linux-intel-iotg | Not in release |
| linux-intel-iotg-5.15 | Not affected |
| linux-iot | Not affected |
| linux-kvm | Not affected |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lowlatency | Not in release |
| linux-lowlatency-hwe-5.15 | Not affected |
| linux-lowlatency-hwe-6.11 | Not in release |
| linux-lowlatency-hwe-6.8 | Not in release |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | Not in release |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-nvidia | Not in release |
| linux-nvidia-6.11 | Not in release |
| linux-nvidia-6.5 | Not in release |
| linux-nvidia-6.8 | Not in release |
| linux-nvidia-lowlatency | Not in release |
| linux-nvidia-tegra | Not in release |
| linux-nvidia-tegra-5.15 | Not affected |
| linux-nvidia-tegra-igx | Not in release |
| linux-oem | Not in release |
| linux-oem-6.11 | Not in release |
| linux-oem-6.14 | Not in release |
| linux-oem-6.8 | Not in release |
| linux-oracle | Not affected |
| linux-oracle-5.15 | Not affected |
| linux-oracle-5.4 | Not in release |
| linux-oracle-6.14 | Not in release |
| linux-oracle-6.8 | Not in release |
| linux-qcm-msm | — |
| linux-raspi | Not affected |
| linux-raspi-5.4 | Not in release |
| linux-raspi-realtime | Not in release |
| linux-raspi2 | Ignored |
| linux-realtime | Not in release |
| linux-realtime-6.14 | Not in release |
| linux-realtime-6.8 | Not in release |
| linux-riscv | Ignored |
| linux-riscv-5.15 | Not affected |
| linux-riscv-6.14 | Not in release |
| linux-riscv-6.8 | Not in release |
| linux-snapdragon | Not in release |
| linux-ti-omap4 | — |
| linux-xilinx-zynqmp | Not affected |
Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857.
27 affected packages
linux, linux-armadaxp, linux-aws, linux-flo, linux-gke...
| Package | 20.04 LTS |
|---|---|
| linux | — |
| linux-armadaxp | — |
| linux-aws | — |
| linux-flo | — |
| linux-gke | — |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | — |
| linux-hwe-edge | — |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | — |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-qcm-msm | — |
| linux-raspi2 | — |
| linux-snapdragon | — |
| linux-ti-omap4 | — |
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
27 affected packages
linux, linux-armadaxp, linux-aws, linux-flo, linux-gke...
| Package | 20.04 LTS |
|---|---|
| linux | — |
| linux-armadaxp | — |
| linux-aws | — |
| linux-flo | — |
| linux-gke | — |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | — |
| linux-hwe-edge | — |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | — |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-qcm-msm | — |
| linux-raspi2 | — |
| linux-snapdragon | — |
| linux-ti-omap4 | — |
crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.
85 affected packages
linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux, linux-armadaxp...
| Package | 20.04 LTS |
|---|---|
| linux-aws-fips | Not affected |
| linux-azure-fips | Not affected |
| linux-gcp-fips | Not affected |
| linux | Not affected |
| linux-armadaxp | — |
| linux-aws | Not affected |
| linux-aws-5.15 | Not affected |
| linux-aws-5.4 | Not in release |
| linux-aws-6.8 | Not in release |
| linux-aws-hwe | Not in release |
| linux-azure | Not affected |
| linux-azure-4.15 | Not in release |
| linux-azure-5.15 | Not affected |
| linux-azure-5.4 | Not in release |
| linux-azure-6.8 | Not in release |
| linux-azure-fde | Ignored |
| linux-azure-fde-5.15 | Not affected |
| linux-bluefield | Not affected |
| linux-euclid | — |
| linux-fips | Not affected |
| linux-flo | — |
| linux-gcp | Not affected |
| linux-gcp-4.15 | Not in release |
| linux-gcp-5.15 | Not affected |
| linux-gcp-5.4 | Not in release |
| linux-gcp-6.8 | Not in release |
| linux-gke | Ignored |
| linux-gkeop | Not affected |
| linux-gkeop-5.15 | Not affected |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | Not in release |
| linux-hwe-5.15 | Not affected |
| linux-hwe-5.4 | Not in release |
| linux-hwe-6.8 | Not in release |
| linux-hwe-edge | Not in release |
| linux-ibm | Not affected |
| linux-ibm-5.15 | Not affected |
| linux-ibm-5.4 | Not in release |
| linux-intel | Not in release |
| linux-intel-iot-realtime | Not in release |
| linux-intel-iotg | Not in release |
| linux-intel-iotg-5.15 | Not affected |
| linux-iot | Not affected |
| linux-kvm | Not affected |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lowlatency | Not in release |
| linux-lowlatency-hwe-5.15 | Not affected |
| linux-lowlatency-hwe-6.8 | Not in release |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | Not in release |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-nvidia | Not in release |
| linux-nvidia-6.5 | Not in release |
| linux-nvidia-6.8 | Not in release |
| linux-nvidia-lowlatency | Not in release |
| linux-oem | Not in release |
| linux-oem-6.11 | Not in release |
| linux-oem-6.8 | Not in release |
| linux-oracle | Not affected |
| linux-oracle-5.15 | Not affected |
| linux-oracle-5.4 | Not in release |
| linux-oracle-6.8 | Not in release |
| linux-qcm-msm | — |
| linux-raspi | Not affected |
| linux-raspi-5.4 | Not in release |
| linux-raspi-realtime | Not in release |
| linux-raspi2 | Ignored |
| linux-realtime | Not in release |
| linux-riscv | Ignored |
| linux-riscv-5.15 | Not affected |
| linux-riscv-6.8 | Not in release |
| linux-snapdragon | Not in release |
| linux-ti-omap4 | — |
| linux-xilinx-zynqmp | Not affected |
Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of...
103 affected packages
linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux, linux-armadaxp...
| Package | 20.04 LTS |
|---|---|
| linux-aws-fips | Not affected |
| linux-azure-fips | Not affected |
| linux-gcp-fips | Not affected |
| linux | Not affected |
| linux-armadaxp | — |
| linux-aws | Not affected |
| linux-aws-5.15 | Not affected |
| linux-aws-5.4 | Not in release |
| linux-aws-6.14 | Not in release |
| linux-aws-6.8 | Not in release |
| linux-aws-hwe | Not in release |
| linux-azure | Not affected |
| linux-azure-4.15 | Not in release |
| linux-azure-5.15 | Not affected |
| linux-azure-5.4 | Not in release |
| linux-azure-6.11 | Not in release |
| linux-azure-6.8 | Not in release |
| linux-azure-fde | Ignored |
| linux-azure-fde-5.15 | Ignored |
| linux-azure-nvidia | Not in release |
| linux-bluefield | Not affected |
| linux-euclid | — |
| linux-fips | Not affected |
| linux-flo | — |
| linux-gcp | Not affected |
| linux-gcp-4.15 | Not in release |
| linux-gcp-5.15 | Not affected |
| linux-gcp-5.4 | Not in release |
| linux-gcp-6.11 | Not in release |
| linux-gcp-6.14 | Not in release |
| linux-gcp-6.8 | Not in release |
| linux-gke | Ignored |
| linux-gkeop | Not affected |
| linux-gkeop-5.15 | Not affected |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | Not in release |
| linux-hwe-5.15 | Not affected |
| linux-hwe-5.4 | Not in release |
| linux-hwe-6.11 | Not in release |
| linux-hwe-6.14 | Not in release |
| linux-hwe-6.8 | Not in release |
| linux-hwe-edge | Not in release |
| linux-ibm | Not affected |
| linux-ibm-5.15 | Not affected |
| linux-ibm-5.4 | Not in release |
| linux-ibm-6.8 | Not in release |
| linux-intel | Not in release |
| linux-intel-iot-realtime | Not in release |
| linux-intel-iotg | Not in release |
| linux-intel-iotg-5.15 | Not affected |
| linux-iot | Not affected |
| linux-kvm | Not affected |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lowlatency | Not in release |
| linux-lowlatency-hwe-5.15 | Not affected |
| linux-lowlatency-hwe-6.11 | Not in release |
| linux-lowlatency-hwe-6.8 | Not in release |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | Not in release |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-nvidia | Not in release |
| linux-nvidia-6.11 | Not in release |
| linux-nvidia-6.5 | Not in release |
| linux-nvidia-6.8 | Not in release |
| linux-nvidia-lowlatency | Not in release |
| linux-nvidia-tegra | Not in release |
| linux-nvidia-tegra-5.15 | Not affected |
| linux-nvidia-tegra-igx | Not in release |
| linux-oem | Not in release |
| linux-oem-6.11 | Not in release |
| linux-oem-6.14 | Not in release |
| linux-oem-6.8 | Not in release |
| linux-oracle | Not affected |
| linux-oracle-5.15 | Not affected |
| linux-oracle-5.4 | Not in release |
| linux-oracle-6.14 | Not in release |
| linux-oracle-6.8 | Not in release |
| linux-qcm-msm | — |
| linux-raspi | Not affected |
| linux-raspi-5.4 | Not in release |
| linux-raspi-realtime | Not in release |
| linux-raspi2 | Ignored |
| linux-realtime | Not in release |
| linux-realtime-6.14 | Not in release |
| linux-realtime-6.8 | Not in release |
| linux-riscv | Ignored |
| linux-riscv-5.15 | Not affected |
| linux-riscv-6.14 | Not in release |
| linux-riscv-6.8 | Not in release |
| linux-snapdragon | Not in release |
| linux-ti-omap4 | — |
| linux-xilinx-zynqmp | Not affected |
An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires...
27 affected packages
linux, linux-armadaxp, linux-aws, linux-flo, linux-gke...
| Package | 20.04 LTS |
|---|---|
| linux | — |
| linux-armadaxp | — |
| linux-aws | — |
| linux-flo | — |
| linux-gke | — |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | — |
| linux-hwe-edge | — |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | — |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-qcm-msm | — |
| linux-raspi2 | — |
| linux-snapdragon | — |
| linux-ti-omap4 | — |
An information disclosure vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires...
27 affected packages
linux, linux-armadaxp, linux-aws, linux-flo, linux-gke...
| Package | 20.04 LTS |
|---|---|
| linux | — |
| linux-armadaxp | — |
| linux-aws | — |
| linux-flo | — |
| linux-gke | — |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | — |
| linux-hwe-edge | — |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | — |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-qcm-msm | — |
| linux-raspi2 | — |
| linux-snapdragon | — |
| linux-ti-omap4 | — |
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires...
27 affected packages
linux, linux-armadaxp, linux-aws, linux-flo, linux-gke...
| Package | 20.04 LTS |
|---|---|
| linux | — |
| linux-armadaxp | — |
| linux-aws | — |
| linux-flo | — |
| linux-gke | — |
| linux-goldfish | — |
| linux-grouper | — |
| linux-hwe | — |
| linux-hwe-edge | — |
| linux-linaro-omap | — |
| linux-linaro-shared | — |
| linux-linaro-vexpress | — |
| linux-lts-quantal | — |
| linux-lts-raring | — |
| linux-lts-saucy | — |
| linux-lts-trusty | — |
| linux-lts-utopic | — |
| linux-lts-vivid | — |
| linux-lts-wily | — |
| linux-lts-xenial | — |
| linux-maguro | — |
| linux-mako | — |
| linux-manta | — |
| linux-qcm-msm | — |
| linux-raspi2 | — |
| linux-snapdragon | — |
| linux-ti-omap4 | — |