PatchSiren

Linux CVE debriefs · Page 120

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Linux CVE published 2024-04-09

CVE-2024-24858

CVE-2024-24858 is a race condition in the Linux kernel Bluetooth stack that can disrupt I2CAP connection or broadcast behavior and may lead to denial of service. NVD rates it Medium severity (CVSS 4.6) and identifies affected Linux kernel ranges across multiple release lines.

MEDIUM Linux CVE published 2024-04-09

CVE-2024-24857

CVE-2024-24857 is a Linux kernel Bluetooth issue involving a race condition in conn_info_{min,max}_age_set(). According to the CVE record, the flaw can lead to an integrity overflow and may cause Bluetooth connection abnormality or denial of service. The issue is rated medium severity, but it still matters for systems that rely on Bluetooth connectivity or run affected kernel builds.

HIGH Linux CVE published 2024-04-09

CVE-2024-23848

CVE-2024-23848 is a Linux kernel use-after-free in the CEC message handling path, specifically cec_queue_msg_fh in the drivers/media/cec/core code. NVD lists the issue as affecting Linux kernel versions through 6.7.1 and scores it 5.5 (MEDIUM) with local, low-privilege access and high availability impact. For defenders, this is primarily a kernel-stability and availability concern, with the usual urgency [truncated]

MEDIUM Linux CVE published 2024-04-09

CVE-2024-23307

CVE-2024-23307 is a Linux kernel vulnerability classified by NVD as a CWE-190 integer overflow/wraparound issue. The CVSS 3.1 score is 4.4 (AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H), so the main concern is availability rather than data compromise. NVD’s affected-version criteria show multiple vulnerable release bands, making kernel update hygiene the key mitigation.

MEDIUM Linux CVE published 2024-04-09

CVE-2024-22099

CVE-2024-22099 describes a NULL pointer dereference in the Linux kernel Bluetooth RFCOMM path, specifically in net/bluetooth/rfcomm/core.C. The supplied record assigns CVSS 3.1 6.3 (MEDIUM) with network attack vector, low privileges required, no user interaction, and high availability impact. The source record was published on 2024-01-25 and later modified on 2026-05-12; the modification date should not b [truncated]

MEDIUM Linux CVE published 2024-04-09

CVE-2023-52458

CVE-2023-52458 is a Linux kernel block-layer bug in partition handling. When a partition is added or resized without checking alignment to the disk’s logical block size, reads of the final sector can be truncated into an I/O error on systems with logical block sizes larger than 512 bytes. If integrity data is enabled, the same condition can also lead to a NULL pointer dereference. NVD rates the issue CVSS [truncated]

MEDIUM Linux CVE published 2024-04-09

CVE-2023-47233

CVE-2023-47233 affects the Linux kernel’s brcm80211/brcmfmac code path handling device unplugging. NVD rates it 4.3 (medium) and describes it as a use-after-free that may be exploitable by a physically proximate attacker with local access. The issue was published on 2023-11-03 and later modified on 2026-05-12; no KEV entry is present in the supplied data.

MEDIUM Linux CVE published 2024-04-09

CVE-2023-1652

CVE-2023-1652 is a use-after-free flaw in Linux kernel NFS server code that can let a local attacker crash the system or potentially expose kernel information. NVD lists it as high severity, with low attack complexity but requiring local privileges. The issue affects specific Linux kernel version ranges and is tracked by vendor and third-party advisories.

MEDIUM Linux CVE published 2024-04-09

CVE-2022-38096

CVE-2022-38096 is a Linux kernel vmwgfx NULL pointer dereference issue. The NVD record identifies affected Linux kernel versions starting at 4.20 and rates the issue CVSS 3.1 6.3 MEDIUM (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H). In practical terms, a local attacker with an account and user interaction could trigger a kernel fault that may lead to denial of service, with the record also noting low integrity impact.

MEDIUM Linux CVE published 2024-04-09

CVE-2021-47002

CVE-2021-47002 is a Linux kernel SUNRPC issue that can trigger a null pointer dereference in svc_rqst_free(). According to the CVE description, if alloc_pages_node() returns null in svc_rqst_alloc(), the resulting rq_scratch_page can later be passed to put_page() without a null check. The result is a crash condition rather than a confidentiality or integrity compromise.

HIGH Linux CVE published 2024-04-05

CVE-2024-26812

CVE-2024-26812 is a Linux kernel VFIO/PCI issue in INTx interrupt handling. The supplied NVD record describes a path where the INTx eventfd could be deconfigured, unregistering the IRQ handler while later irqfd or SET_IRQS paths could still signal an eventfd with a NULL context. The published fix changes how the INTx handler is managed and adds synchronization so the trigger can be updated safely while in [truncated]

HIGH Linux CVE published 2024-04-05

CVE-2024-26810

CVE-2024-26810 is a Linux kernel VFIO PCI race condition involving INTx masking and interrupt-configuration changes. The flaw occurs when mask operations through config-space changes to DisINTx can race ioctl-driven INTx configuration changes. The result is an unsafe interrupt state transition path that can affect availability.

HIGH Linux CVE published 2024-04-02

CVE-2024-26659

CVE-2024-26659 is a Linux kernel xHCI bug in isochronous transfer error handling. According to the public record, the driver could incorrectly assume ownership of a multi-TRB transfer descriptor after early error events, which could lead to freed or overwritten descriptors and incorrect completion handling. The issue is rated medium severity and primarily affects availability, with the NVD vector indicati [truncated]

HIGH Linux CVE published 2024-03-21

CVE-2024-26643

CVE-2024-26643 is a Linux kernel netfilter/nf_tables race condition affecting anonymous sets with timeouts. NVD rates it Medium (CVSS 5.5), and the issue is described as an asynchronous garbage-collection race that can interfere with set teardown and lead to denial of service on vulnerable kernels. The fix marks the set dead so async GC skips it during release and abort handling.

HIGH Linux CVE published 2024-03-21

CVE-2024-26642

CVE-2024-26642 is a Linux kernel nf_tables issue that was fixed by rejecting anonymous sets with the timeout flag, except where NFT_SET_EVAL is needed for legacy meter support. The CVE is rated medium severity and is primarily a defensive maintenance concern for systems running affected kernel branches.

HIGH Linux CVE published 2024-03-21

CVE-2023-52620

CVE-2023-52620 affects the Linux kernel’s netfilter nf_tables path. According to the CVE description, the fix disallows timeout parameters for anonymous sets because those parameters were never intended to be used from userspace. NVD rates the issue as LOW severity with local access, low privileges, high attack complexity, and availability-only impact. The record also links multiple stable-kernel patch re [truncated]

HIGH Linux CVE published 2024-03-18

CVE-2023-52614

CVE-2023-52614 is a Linux kernel memory-safety issue in PM/devfreq’s trans_stat_show() path. According to the CVE record and referenced kernel patches, the function could overrun its output buffer while building transition statistics. The fix replaces snprintf with scnprintf, stops when PAGE_SIZE would be exceeded, emits a warning that statistics are disabled, and returns -EFBIG when the full table cannot [truncated]

CRITICAL Linux CVE published 2024-03-04

CVE-2021-47107

CVE-2021-47107 is a Linux kernel NFSD memory-corruption issue in the READDIR path. According to NVD and the kernel fix notes, a too-small READDIR count can underflow the buffer-size calculation in the new init_dirlist helper, which can then allow XDR reserve/write logic to go past the intended buffer. NVD rates the issue 7.8 HIGH and lists affected Linux kernel builds in the 5.13 to 5.15.12 range, plus 5. [truncated]

HIGH Linux CVE published 2024-02-22

CVE-2023-52447

CVE-2023-52447 is a Linux kernel BPF use-after-free issue in the handling of inner maps. When an inner map is updated or deleted from an outer map, BPF programs may still access it. The kernel fix defers the final free until after the required RCU and tasks trace RCU grace periods, reducing the risk that a BPF program can touch freed memory.

MEDIUM Linux CVE published 2023-12-12

CVE-2024-42096

CVE-2024-42096 is a medium-severity vulnerability (CVSS 5.1) in the Linux kernel affecting Siemens SIMATIC S7-1500 TM MFP industrial control systems with GNU/Linux subsystem. The vulnerability, published April 9, 2024, involves unsafe stack manipulation in the x86 `profile_pc()` function that could lead to out-of-bounds read conditions. The issue was resolved in the upstream Linux kernel by eliminating st [truncated]

MEDIUM Linux CVE published 2023-12-12

CVE-2024-26878

CVE-2024-26878 is a Linux kernel vulnerability in quota handling that can lead to a NULL pointer dereference during a race between inode quota teardown and quota-off processing. NVD lists impacted Linux kernel release ranges across multiple stable branches, and the kernel fix replaces the direct pointer use with a temporary reference to avoid the race window. The primary impact is availability, consistent [truncated]

MEDIUM Linux CVE published 2023-12-12

CVE-2024-26863

CVE-2024-26863 is a Linux kernel vulnerability in the HSR code path, published on 2024-04-17. A packet with ETH_P_PRP or ETH_P_HSR that is not followed by an HSR tag can cause hsr_get_node() to use an invalid uninitialized sequence number, leading to an availability impact rated CVSS 5.5/MEDIUM.

HIGH Linux CVE published 2023-12-12

CVE-2023-6817

CVE-2023-6817 is a Linux kernel netfilter:nf_tables use-after-free issue that can be used for local privilege escalation. The flaw is tied to nft_pipapo_walk failing to skip inactive elements during set walking, which can lead to double deactivation of PIPAPO elements and then use-after-free. NVD lists affected Linux kernel version ranges across multiple release lines, and the upstream fix is identified b [truncated]

HIGH Linux CVE published 2023-12-12

CVE-2023-45898

CVE-2023-45898 is a high-severity Linux kernel flaw in ext4’s extents status handling. NVD describes it as an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent. The vulnerable range is Linux kernel 6.5 up to, but not including, 6.5.4. From a defensive standpoint, the key action is to move affected systems to 6.5.4 or a later kernel that includes the fix and to prioritize hos [truncated]

HIGH Linux CVE published 2023-07-21

CVE-2023-3609

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. The vulnerability is caused by a reference counter issue in the tcf_change_indev() and u32_set_parms() functions. If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.

Known exploited Linux CVE published 2023-05-12

CVE-2014-0196

CVE-2014-0196 is a Linux kernel race condition vulnerability that CISA has listed in the Known Exploited Vulnerabilities (KEV) catalog. In the supplied corpus, CISA’s guidance is explicit: if the impacted product is end-of-life and still in use, it should be disconnected. No CVSS score, affected-version range, or patch details are provided in the supplied sources.

Known exploited Linux CVE published 2023-05-12

CVE-2010-3904

CVE-2010-3904 is a Linux Kernel improper input validation issue that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied CISA guidance treats impacted systems as legacy risk: the affected product is end-of-life and should be disconnected if still in use. That makes asset discovery and isolation the main defensive priority where this kernel lineage is still present.

Known exploited Linux CVE published 2023-03-30

CVE-2023-0266

CVE-2023-0266 is a Linux kernel use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-03-30, with remediation due by 2023-04-20. The official guidance is to apply vendor updates, and the kernel stable-queue patch referenced in the source notes indicates a fix in the ALSA PCM area aimed at preventing the UAF.

Known exploited Linux CVE published 2022-10-20

CVE-2021-3493

CVE-2021-3493 is a Linux kernel privilege escalation vulnerability that CISA has placed in the Known Exploited Vulnerabilities catalog. That KEV listing indicates the issue has been observed in active exploitation, so defenders should treat Linux kernel patching and verification as a priority. The supplied official sources do not provide affected versions or deeper technical root-cause details, so remedia [truncated]

Known exploited Linux CVE published 2022-09-15

CVE-2013-6282

CVE-2013-6282 is a Linux Kernel improper input validation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. In the supplied timeline, CISA added it on 2022-09-15 and set a remediation due date of 2022-10-06. Because it is KEV-listed, organizations should treat remediation as urgent and follow vendor update guidance promptly.