CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102367  CVE-2017-5547  Candidate  drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.  Assigned (20170120)  None (candidate not yet proposed)    View
102368  CVE-2017-5548  Candidate  drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.  Assigned (20170120)  None (candidate not yet proposed)    View
102369  CVE-2017-5549  Candidate  The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents into a log entry upon a failure to read the line status, which allows local users to obtain sensitive information by reading the log.  Assigned (20170120)  None (candidate not yet proposed)    View
102370  CVE-2017-5550  Candidate  Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances by reading from a pipe after an incorrect buffer-release decision.  Assigned (20170120)  None (candidate not yet proposed)    View
102371  CVE-2017-5551  Candidate  The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 preserves the setgid bit during a setxattr call involving a tmpfs filesystem, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7097.  Assigned (20170120)  None (candidate not yet proposed)    View

Page 1105 of 20943, showing 5 records out of 104715 total, starting on record 5521, ending on 5525

Actions