PatchSiren

Linux CVE debriefs · Page 121

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Linux CVE published 2022-09-15

CVE-2013-6282

CVE-2013-6282 is a Linux Kernel improper input validation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. In the supplied timeline, CISA added it on 2022-09-15 and set a remediation due date of 2022-10-06. Because it is KEV-listed, organizations should treat remediation as urgent and follow vendor update guidance promptly.

Known exploited Linux CVE published 2022-09-15

CVE-2013-2596

CVE-2013-2596 is a Linux kernel integer overflow vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is not the missing CVSS score in the supplied record, but the fact that CISA flagged this issue for remediation and set a due date of 2022-10-06 in the provided KEV metadata. The source notes point to a Linux kernel git commit as the vendor fix [truncated]

Known exploited Linux CVE published 2022-09-15

CVE-2013-2094

CVE-2013-2094 is a Linux Kernel privilege escalation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is on KEV, defenders should treat it as a high-priority patching item and follow vendor update guidance without delay. The supplied source record points to the upstream Linux kernel commit and the NVD entry, but does not provide affected version ranges or exploit de [truncated]

Known exploited Linux CVE published 2022-05-25

CVE-2014-3153

CVE-2014-3153 is identified by CISA as a Known Exploited Vulnerability affecting the Linux Kernel. The source corpus only confirms that it is a privilege escalation issue and that CISA added it to the KEV catalog on 2022-05-25 with a remediation due date of 2022-06-15. Because it is KEV-listed, defenders should treat it as a high-priority patching item and follow vendor update guidance.

Known exploited Linux CVE published 2022-04-25

CVE-2022-0847

CVE-2022-0847 is a Linux kernel privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-04-25. Because it is listed in KEV, defenders should treat it as an active-risk issue and prioritize remediation on affected Linux systems, especially hosts that are widely deployed or externally reachable. CISA’s catalog entry specifies a mitigation deadline of 2022-05 [truncated]

Known exploited Linux CVE published 2022-04-11

CVE-2021-22600

CVE-2021-22600 is a Linux kernel privilege escalation vulnerability that CISA has placed in its Known Exploited Vulnerabilities catalog. Because it is listed as known exploited, it should be treated as an urgent patching item for any environment running affected Linux kernel versions. The supplied records direct defenders to apply updates per vendor instructions.

Known exploited Linux CVE published 2022-03-03

CVE-2016-5195

CVE-2016-5195 is a Linux Kernel race condition vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog, which means it is known to have been exploited in the wild. Because CISA assigned a remediation due date and directed organizations to apply vendor updates, this issue should be treated as a high-priority patching item for any Linux systems that may be affected.

Known exploited Linux CVE published 2021-12-10

CVE-2019-13272

CVE-2019-13272 is a Linux kernel improper privilege management vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. Because it is flagged as known exploited, defenders should treat remediation as urgent and follow vendor update guidance without delay. The supplied corpus does not include version ranges or exploit details, so the safest response is broad inventory, rapid patching, [truncated]

MEDIUM Linux CVE published 2017-03-01

CVE-2017-6353

CVE-2017-6353 is a local denial-of-service issue in the Linux kernel's SCTP socket handling. A multithreaded application could trigger association peel-off operations during certain wait states, leading to an invalid unlock and double free. The issue is notable because the CVE description says it exists due to an incorrect fix for CVE-2017-5986.

MEDIUM Linux CVE published 2017-03-01

CVE-2017-6348

CVE-2017-6348 affects the Linux kernel’s IrDA queue handling and can let a local user trigger a denial of service by causing a deadlock on IrDA devices. NVD records the issue as affecting Linux kernel versions through 4.9.12, with a fix available in 4.9.13. The vulnerability is rated medium severity (CVSS 5.5) and is not listed as a Known Exploited Vulnerability in the supplied data.

HIGH Linux CVE published 2017-03-01

CVE-2017-6347

CVE-2017-6347 is a Linux kernel vulnerability in ip_cmsg_recv_checksum that stems from incorrect expectations about skb data layout. On affected kernels, a local user can trigger a buffer over-read through crafted system calls; the described impact includes denial of service and possibly other unspecified effects. The issue was publicly disclosed on 2017-03-01, and Linux 4.10.1 is referenced as the fixed release.

HIGH Linux CVE published 2017-03-01

CVE-2017-6346

CVE-2017-6346 is a Linux kernel race condition in net/packet/af_packet.c tied to PACKET_FANOUT setsockopt calls. According to NVD and the linked kernel references, the flaw can lead to a use-after-free and denial of service, with possible additional unspecified impact. The issue affects multiple Linux kernel branches and is fixed in the 4.9.13 release line referenced by the kernel changelog and patch commit.

HIGH Linux CVE published 2017-03-01

CVE-2017-6345

CVE-2017-6345 is a Linux kernel flaw in the LLC subsystem that was publicly disclosed on 2017-03-01. The issue affects kernel versions up to 4.9.12 and was fixed in 4.9.13. A local user can trigger a BUG_ON denial of service through crafted system calls, with the advisory also noting possible unspecified additional impact.

HIGH Linux CVE published 2017-02-23

CVE-2017-6214

CVE-2017-6214 is a Linux kernel availability issue in tcp_splice_read that can trigger an infinite loop and soft lockup when processing a TCP packet with the URG flag. The public NVD record classifies the issue as network-reachable, unauthenticated, and availability-only, with affected Linux kernel versions through 4.9.10 and a fix available in 4.9.11. For defenders, this is primarily a patch-management i [truncated]

HIGH Linux CVE published 2017-02-22

CVE-2016-8636

CVE-2016-8636 affects the Linux kernel’s Soft RoCE (rxe) RDMA path. An integer overflow in mem_check_range() can let a local user trigger unsafe read or write handling, resulting in memory corruption, possible kernel-memory disclosure, or other undefined impact on kernels before 4.9.10.

HIGH Linux CVE published 2017-02-18

CVE-2017-6074

CVE-2017-6074 is a Linux kernel vulnerability in DCCP receive-state processing that mishandles DCCP_PKT_REQUEST data in the LISTEN state. The flaw can trigger a double free, which the NVD describes as enabling local privilege escalation to root or a denial of service. Because exploitation requires local access and kernel interaction, the risk is highest on shared, multi-user Linux systems that permit untr [truncated]

HIGH Linux CVE published 2017-02-18

CVE-2017-6001

CVE-2017-6001 is a Linux kernel race condition in kernel/events/core.c affecting certain kernel series before 4.9.7. NVD describes it as a local privilege escalation issue triggered by a crafted application that makes concurrent perf_event_open system calls while moving a software group into a hardware context. The CVE record also states this issue exists because of an incomplete fix for CVE-2016-6786.

MEDIUM Linux CVE published 2017-02-18

CVE-2017-5986

CVE-2017-5986 affects the Linux kernel SCTP socket code and can let a local user trigger a denial of service through an assertion failure and kernel panic. The issue was published by CVE on 2017-02-18, and NVD later marked the record modified on 2026-05-13. NVD lists affected Linux kernel versions through 4.9.11 and references the upstream fix, release notes, and downstream vendor advisories.

HIGH Linux CVE published 2017-02-14

CVE-2017-5972

CVE-2017-5972 is a Linux kernel 3.x denial-of-service issue in TCP SYN cookie handling. According to the NVD record, an attacker can send many TCP SYN packets to cause high CPU consumption on affected systems, including a demonstrated impact against CentOS Linux 7's kernel-3.10.0 package. The vulnerable range in the NVD metadata spans Linux kernel versions 3.0.0 through 3.19.8.

HIGH Linux CVE published 2017-02-14

CVE-2017-5970

CVE-2017-5970 is a Linux kernel issue in the IPv4 packet info path that can crash affected systems. NVD rates it High because the flaw is remotely reachable, requires no privileges, and can result in a denial of service on Linux kernels through 4.9.9.

MEDIUM Linux CVE published 2017-02-14

CVE-2017-5967

CVE-2017-5967 is a local information disclosure flaw in the Linux kernel time subsystem. On affected systems with CONFIG_TIMER_STATS enabled, a user can read /proc/timer_list and learn real PID values, including values that are distinguishable from PID namespace values. NVD lists affected Linux kernel versions through 4.9.9 and rates the issue as medium severity with low confidentiality impact and no inte [truncated]

MEDIUM Linux CVE published 2017-02-08

CVE-2017-0451

CVE-2017-0451 is an information disclosure issue in the Qualcomm sound driver affecting Android kernels 3.10 and 3.18. The vendor bulletin characterizes it as Moderate because exploitation first requires compromising a privileged process. NVD records the issue as a local attack with high complexity and user interaction, with confidentiality impact but no integrity or availability impact.

HIGH Linux CVE published 2017-02-08

CVE-2017-0443

CVE-2017-0443 is a High-severity elevation of privilege issue in the Qualcomm Wi‑Fi driver affecting Android and listed kernel branches 3.10 and 3.18. According to the CVE description, a local malicious application could execute arbitrary code in kernel context, but only after first compromising a privileged process. Because the impact reaches the kernel, the issue deserves prompt patching on affected And [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2017-0442

CVE-2017-0442 is a high-severity elevation-of-privilege issue in the Qualcomm Wi‑Fi driver used by affected Android/kernel builds. NVD says a local attacker could reach arbitrary code execution in kernel context, while the Android-linked advisory notes the issue first requires compromising a privileged process. In practical terms, this is a local-to-kernel escalation problem with high impact, but it is no [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2017-0441

CVE-2017-0441 is a high-severity elevation-of-privilege vulnerability in the Qualcomm Wi‑Fi driver used by Android. According to the CVE description, a local malicious application could execute arbitrary code in the context of the kernel, but the issue first requires compromising a privileged process. NVD records the issue as affecting Android builds up to 7.1.1 as well as Linux kernel 3.10 and 3.18 CPEs, [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2017-0440

CVE-2017-0440 is a high-severity elevation-of-privilege issue affecting Android and Linux kernel 3.10/3.18. According to the NVD record and Android security bulletin reference, a local malicious application could leverage a flaw in the Qualcomm Wi‑Fi driver to execute arbitrary code in kernel context. The reported risk is elevated by the need to first compromise a privileged process, but the potential imp [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2017-0439

CVE-2017-0439 is a high-severity Android kernel issue in the Qualcomm Wi‑Fi driver. According to the CVE record, a local malicious app could reach arbitrary code execution in kernel context, and the description notes the attack first requires compromising a privileged process. The supplied record ties impact to Android builds through 7.1.1 and to Linux kernel 3.10 and 3.18.

HIGH Linux CVE published 2017-02-08

CVE-2017-0438

CVE-2017-0438 is a high-severity Android kernel vulnerability affecting Qualcomm Wi‑Fi driver code in Android kernel 3.10 and 3.18 builds. The advisory says a local malicious application could execute arbitrary code in kernel context, with the issue rated High because it first requires compromising a privileged process. NVD also classifies the issue as local, high-complexity, and high-impact. Administrato [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2017-0437

CVE-2017-0437 describes a Qualcomm Wi‑Fi driver elevation-of-privilege vulnerability that could let a local malicious application execute arbitrary code in kernel context. The CVE text says the issue is rated High because it first requires compromising a privileged process. In the supplied corpus, NVD also maps the issue to affected Android builds and Linux kernel CPEs, so remediation should be validated [truncated]

HIGH Linux CVE published 2017-02-08

CVE-2017-0436

CVE-2017-0436 is a high-severity elevation-of-privilege issue in the Qualcomm sound driver used on Android. According to the CVE record, a local malicious application could reach arbitrary code execution in kernel context, but only after first compromising a privileged process.