Vulnerability index

Browse CVEs

1,622 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Linux Kernel HIGH 7.8
CVE-2022-2978

A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following c…

Fix: 4.9.331 / 4.14.296+
Fix from $1,950 2022-08-24
Linux Kernel HIGH 7.8
CVE-2021-4028

A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to l…

Fix: 5.10.71 / 5.14.10+
Fix from $1,950 2022-08-24
Linux Kernel HIGH 7.8
CVE-2022-2938

A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an atta…

Fix: 5.4.177 / 5.10.97+
Fix from $1,950 2022-08-23
Linux Kernel HIGH 7.8
CVE-2022-1158

A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_…

Fix: 5.4.189 / 5.10.110+
Fix from $1,950 2022-08-05
Linux Kernel HIGH 7.1
CVE-2022-1973

A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash…

Fix: 5.15.46 / 5.17.14+
Fix from $1,950 2022-08-05
Linux Kernel HIGH 7.8
CVE-2022-2327

io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when…

Patch available
Fix from $1,950 2022-07-22
Linux Kernel MEDIUM 5.1
CVE-2020-36557

A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lead to a use-after-free.

Fix: 5.6.2+
Fix from $1,600 2022-07-21
Linux Kernel MEDIUM 5.5
CVE-2022-2318

There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without…

Fix: 5.19+
Fix from $1,600 2022-07-06
Linux Kernel HIGH 7.8
CVE-2022-1998

A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in …

Fix: 5.10.97 / 5.15.20+
Fix from $1,950 2022-06-09
Linux Kernel HIGH 7.8
CVE-2022-32250

net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to r…

Fix: 4.9.318 / 4.14.283+
Fix from $1,950 2022-06-02
Linux Kernel HIGH 7.8
CVE-2022-1786

A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one…

Fix: 5.12+
Fix from $1,950 2022-06-02
Linux Kernel HIGH 7.8
CVE-2022-1419

The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_gem_object *(created in *vgem_g…

Fix: 5.6+
Fix from $1,950 2022-06-02
Linux Kernel HIGH 7.8
CVE-2022-1652

Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr fu…

Fix: 4.9.316 / 4.14.281+
Fix from $1,950 2022-06-02
Linux Kernel HIGH 7.8
CVE-2022-1882

A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notification() …

Fix: 5.10.134 / 5.15.58+
Fix from $1,950 2022-05-26
Linux Kernel HIGH 7.0
CVE-2022-1734

A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non syn…

Fix: 5.18+
Fix from $1,950 2022-05-18
Linux Kernel HIGH 7.8
CVE-2022-1679

A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function…

Fix: 4.14.291 / 4.19.256+
Fix from $1,950 2022-05-16
Linux Kernel MEDIUM 5.5
CVE-2022-1516

A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality in the way a user terminates…

Patch available
Fix from $1,600 2022-05-05
Linux Kernel HIGH 7.0
CVE-2022-1048

A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctl…

Fix: 4.14.279 / 4.19.243+
Fix from $1,950 2022-04-29
Linux Kernel MEDIUM 5.5
CVE-2022-1195

A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to caus…

Fix: 5.16+
Fix from $1,600 2022-04-29
Linux Kernel MEDIUM 6.3
CVE-2022-1280

A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows…

Fix: after 5.17.4
Fix from $1,600 2022-04-13
Linux Kernel HIGH 7.8
CVE-2022-28893

The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.

Fix: 5.4.196 / 5.10.117+
Fix from $1,950 2022-04-11
Linux Kernel HIGH 7.8
CVE-2022-1055

A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires un…

Fix: 5.4.177 / 5.10.97+
Fix from $1,950 2022-03-29
Linux Kernel HIGH 7.0
CVE-2021-4202

A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a l…

Fix: 4.4.294 / 4.9.292+
Fix from $1,950 2022-03-25
Linux Kernel MEDIUM 6.8
CVE-2021-4203

A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) …

Fix: 5.15+
Fix from $1,600 2022-03-25
Linux Kernel MEDIUM 5.5
CVE-2021-4150

A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could caus…

Fix: 5.15+
Fix from $1,600 2022-03-23
Linux Kernel HIGH 7.8
CVE-2022-1011

A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unaut…

Fix: 5.17+
Fix from $1,950 2022-03-18
Linux Kernel MEDIUM 5.5
CVE-2021-45868

In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead …

Fix: 5.15.3+
Fix from $1,600 2022-03-18
Linux Kernel HIGH 7.0
CVE-2021-3640

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other …

Fix: 4.4.293 / 4.9.291+
Fix from $1,950 2022-03-03
Linux Kernel HIGH 7.8
CVE-2021-3715

A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of cl…

Fix: 4.4.218 / 4.9.218+
Fix from $1,950 2022-03-02
Linux Kernel HIGH 7.8
CVE-2022-0646

A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_syn…

Patch available
Fix from $1,950 2022-02-18