linux security advisories
47 threat alerts tracking vulnerabilities and security advisories that affect linux products.
Vulnios monitors linux CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent linux security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2019-14897 — linux, debian — linux_kernel, debian_linux
A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute ar
criticalCVE-2019-14897Critical Vulnerability: CVE-2019-14901 — linux, fedoraproject — linux_kernel, fedora
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulti
criticalCVE-2019-14901Critical Vulnerability: CVE-2019-14896 — linux, fedoraproject — linux_kernel, fedora
A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possi
criticalCVE-2019-14896Critical Vulnerability: CVE-2019-14895 — linux, debian — linux_kernel, debian_linux
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection ne
criticalCVE-2019-14895Critical Vulnerability: CVE-2019-18805 — linux, opensuse — linux_kernel, leap
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very la
criticalCVE-2019-18805Critical Vulnerability: CVE-2019-18814 — linux — linux_kernel
An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c.
criticalCVE-2019-18814Critical Vulnerability: CVE-2019-17133 — linux, debian — linux_kernel, debian_linux
In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
criticalCVE-2019-17133Critical Vulnerability: CVE-2019-16746 — linux, debian — linux_kernel, debian_linux
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
criticalCVE-2019-16746Critical Vulnerability: CVE-2019-15926 — linux, debian — linux_kernel, debian_linux
An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/
criticalCVE-2019-15926Critical Vulnerability: CVE-2019-15505 — linux, debian — linux_kernel, debian_linux
drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir).
criticalCVE-2019-15505Critical Vulnerability: CVE-2019-15504 — linux, canonical — linux_kernel, ubuntu_linux
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
criticalCVE-2019-15504Critical Vulnerability: CVE-2018-20961 — linux — linux_kernel
In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of serv
criticalCVE-2018-20961Critical Vulnerability: CVE-2017-18379 — linux — linux_kernel
In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c.
criticalCVE-2017-18379Critical Vulnerability: CVE-2016-10764 — linux — linux_kernel
In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MAX_CHIPSELECT elements in the ->f_pdata array so th
criticalCVE-2016-10764Critical Vulnerability: CVE-2019-10126 — linux, redhat — linux_kernel, virtualization
A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly othe
criticalCVE-2019-10126Critical Vulnerability: CVE-2019-11683 — linux, canonical — linux_kernel, ubuntu_linux
udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have uns
criticalCVE-2019-11683Critical Vulnerability: CVE-2019-10125 — linux, netapp — linux_kernel, active_iq_unified_manager
An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., by the close of a pa
criticalCVE-2019-10125Critical Vulnerability: CVE-2018-20784 — linux, canonical — linux_kernel, ubuntu_linux
In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspeci
criticalCVE-2018-20784Critical Vulnerability: CVE-2018-12714 — linux — linux_kernel
An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, which is an N=0 case when it expected at least one
criticalCVE-2018-12714Critical Vulnerability: CVE-2017-18174 — linux — linux_kernel
In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.
criticalCVE-2017-18174Critical Vulnerability: CVE-2018-5703 — linux — linux_kernel
The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.14.11 allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other
criticalCVE-2018-5703Critical Vulnerability: CVE-2017-18017 — linux, debian — linux_kernel, debian_linux
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory
criticalCVE-2017-18017Critical Vulnerability: CVE-2017-13715 — linux — linux_kernel
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a
criticalCVE-2017-13715Critical Vulnerability: CVE-2017-12762 — linux, canonical — linux_kernel, ubuntu_linux
In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux k
criticalCVE-2017-12762Critical Vulnerability: CVE-2017-7895 — linux, debian — linux_kernel, debian_linux
The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possib
criticalCVE-2017-7895Critical Vulnerability: CVE-2017-0561 — linux — linux_kernel
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due t
criticalCVE-2017-0561Critical Vulnerability: CVE-2016-10229 — linux, google — linux_kernel, android
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with t
criticalCVE-2016-10229Critical Vulnerability: CVE-2017-5897 — linux, canonical — linux_kernel, ubuntu_linux
The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds a
criticalCVE-2017-5897Critical Vulnerability: CVE-2016-10150 — linux — linux_kernel
Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or possi
criticalCVE-2016-10150Critical Vulnerability: CVE-2016-8459 — linux — linux_kernel
Possible buffer overflow in storage subsystem. Bad parameters as part of listener responses to RPMB commands could lead to buffer overflow. Product: Android. Versions: Kernel 3.18. Android ID: A-32577
criticalCVE-2016-8459Critical Vulnerability: CVE-2016-8437 — linux — linux_kernel
Improper input validation in Access Control APIs. Access control API may return memory range checking incorrectly. Product: Android. Versions: Kernel 3.18. Android ID: A-31623057. References: QC-CR#10
criticalCVE-2016-8437Critical Vulnerability: CVE-2016-8438 — linux — linux_kernel
Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android
criticalCVE-2016-8438Critical Vulnerability: CVE-2016-8440 — linux — linux_kernel
Possible buffer overflow in SMMU system call. Improper input validation in ADSP SID2CB system call may result in hypervisor memory overwrite. Product: Android. Versions: Kernel 3.18. Android ID: A-316
criticalCVE-2016-8440Critical Vulnerability: CVE-2016-8439 — linux — linux_kernel
Possible buffer overflow in trust zone access control API. Buffer overflow may occur due to lack of buffer size checking. Product: Android. Versions: Kernel 3.18. Android ID: A-31625204. References: Q
criticalCVE-2016-8439Critical Vulnerability: CVE-2016-8398 — linux — linux_kernel
Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. Referen
criticalCVE-2016-8398Critical Vulnerability: CVE-2016-9555 — linux — linux_kernel
The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-o
criticalCVE-2016-9555Critical Vulnerability: CVE-2016-5343 — linux — linux_kernel
drivers/soc/qcom/qdsp6v2/voice_svc.c in the QDSP6v2 Voice Service driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products
criticalCVE-2016-5343Critical Vulnerability: CVE-2015-0573 — linux — linux_kernel
drivers/media/platform/msm/broadcast/tsc.c in the TSC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows att
criticalCVE-2015-0573Critical Vulnerability: CVE-2014-9410 — linux — linux_kernel
The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM
criticalCVE-2014-9410Critical Vulnerability: CVE-2015-8787 — linux — linux_kernel
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or
criticalCVE-2015-8787Critical Vulnerability: CVE-2011-2717 — linux, redhat — dhcp6c, enterprise_linux
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message
criticalCVE-2011-2717Critical Vulnerability: CVE-2014-3180 — linux, google — linux_kernel, chrome_os
In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting comp
criticalCVE-2014-3180Critical Vulnerability: CVE-2012-6712 — linux — linux_kernel
In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.
criticalCVE-2012-6712Critical Vulnerability: CVE-2007-6762 — linux — linux_kernel
In the Linux kernel before 2.6.20, there is an off-by-one bug in net/netlabel/netlabel_cipso_v4.c where it is possible to overflow the doi_def->tags[] array.
criticalCVE-2007-6762Critical Vulnerability: CVE-2011-5327 — linux — linux_kernel
In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.
criticalCVE-2011-5327Critical Vulnerability: CVE-2011-1180 — linux — linux_kernel
Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow remote attackers to cause a denial of service (memory
criticalCVE-2011-1180Critical Vulnerability: CVE-2011-3188 — linux, redhat — linux_kernel, enterprise_linux
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote
criticalCVE-2011-3188
Track linux exposure across your environment
Vulnios automatically cross-references your asset inventory against new linux CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan