Skip to content
Noroxi

kernel records

22 published records for vendor kernel.

All records

22 records
  • The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly o

    CriticalCVSS 9.8No exploitEPSS 5%

    kernel · util-linuxAug 23, 2017

  • pam_access does not handle netmask matches correctly

    HighCVSS 8.1No exploitEPSS 1%

    opensuse · leapNov 27, 2018

  • CVE-2014-9114
    31Monitor

    Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.

    HighCVSS 7.8No exploitEPSS 1%

    opensuse · opensuseMar 31, 2017

  • CVE-2018-7738
    31Monitor

    In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name

    HighCVSS 7.8No exploitEPSS 0%

    kernel · util-linuxMar 6, 2018

  • CVE-2016-2779
    31Monitor

    runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the te

    HighCVSS 7.8No exploitEPSS 0%

    kernel · util-linuxFeb 7, 2017

  • CVE-2007-5191
    28Monitor

    mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values

    HighCVSS 7.2No exploitEPSS 0%

    kernel · util-linuxOct 4, 2007

  • An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path paramet

    MediumCVSS 6.7No exploitEPSS 1%

    kernel · util-linuxAug 22, 2023

  • A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would onl

    MediumCVSS 6.1No exploitEPSS 0%

    kernel · selinuxMay 26, 2020

  • An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in

    MediumCVSS 5.5No exploitEPSS 1%

    kernel · util-linuxJul 30, 2021

  • CVE-2021-3996
    22Monitor

    A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem.

    MediumCVSS 5.5No exploitEPSS 1%

    kernel · util-linuxAug 23, 2022

  • CVE-2021-3995
    22Monitor

    A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem.

    MediumCVSS 5.5No exploitEPSS 1%

    kernel · util-linuxAug 23, 2022

  • CVE-2001-1494
    22Monitor

    script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescr

    MediumCVSS 5.5No exploitEPSS 0%

    kernel · util-linuxDec 31, 2001

  • CVE-2022-0563
    22Monitor

    A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support.

    MediumCVSS 5.5No exploitEPSS 0%

    kernel · util-linuxFeb 21, 2022

  • CVE-2026-3184
    21Monitor

    Util-linux: util-linux: access control bypass due to improper hostname canonicalization

    MediumCVSS 5.3No exploitEPSS 1%

    kernel · util-linuxApr 3, 2026

  • Util-linux: util-linux: heap use-after-free in libblkid nested partition probing

    MediumCVSS 5.3No exploitEPSS 0%

    redhat · hardened imagesJun 29, 2026

  • CVE-2009-3288
    19Monitor

    The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing

    MediumCVSS 4.9No exploitEPSS 0%

    kernel · linux kernelSep 22, 2009

  • CVE-2007-6712
    19Monitor

    Integer overflow in the hrtimer_forward function (hrtimer.c) in Linux kernel 2.6.21-rc4, when running on 64-bit systems, allows local users

    MediumCVSS 4.9No exploitEPSS 0%

    kernel · linux kernelApr 12, 2008

  • CVE-2016-5011
    18Monitor

    The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a d

    MediumCVSS 4.6No exploitEPSS 0%

    kernel · util-linuxApr 11, 2017

  • util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup

    MediumCVSS 4.7No exploitEPSS 0%

    kernel · util-linuxApr 3, 2026

  • wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals t

    LowCVSS 3.3Proof of conceptEPSS 2%

    kernel · util-linuxMar 27, 2024

  • Buffer overflow in text-utils/colcrt.c in colcrt in util-linux before 2.27 allows local users to cause a denial of service (crash) via a cra

    LowCVSS 2.1No exploitEPSS 1%

    kernel · util-linuxNov 9, 2015

  • (a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricte

    LowCVSS 2.1No exploitEPSS 0%

    kernel · util-linuxJan 21, 2014