It was discovered that the Traffic-Control Index (TCINDEX) implementation
in the Linux kernel contained a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-1281)
It was discovered that the OverlayFS implementation in the Linux kernel did
not properly handle copy up operation in some conditions. A local attacker
could possibly use this to gain elevated privileges. (CVE-2023-0386)
Haowei Yan discovered that a race condition existed in the Layer 2
Tunneling Protocol (L2TP) implementation in the Linux kernel. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2022-4129)
It was discovered that the network queuing discipline implementation in the
Linux kernel contained a null pointer dereference in some situations. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2022-47929)
It was discovered that the NTFS file system implementation in the Linux
kernel contained a null pointer dereference in some situations. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2022-4842)
Kyle Zeng discovered that the IPv6 implementation in the Linux kernel
contained a NULL pointer dereference vulnerability in certain situations. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2023-0394)
It was discovered that the Human Interface Device (HID) support driver in
the Linux kernel contained a type confusion vulnerability in some
situations. A local attacker could use this to cause a denial of service
(system crash). (CVE-2023-1073)
It was discovered that a memory leak existed in the SCTP protocol
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (memory exhaustion). (CVE-2023-1074)
It was discovered that the NFS implementation in the Linux kernel did not
properly handle pending tasks in some situations. A local attacker could
use this to cause a denial of service (system crash) or expose sensitive
information (kernel memory). (CVE-2023-1652)
Lianhui Tang discovered that the MPLS implementation in the Linux kernel
did not properly handle certain sysctl allocation failure conditions,
leading to a double-free vulnerability. An attacker could use this to cause
a denial of service or possibly execute arbitrary code. (CVE-2023-26545)
More Stories
CrushFTP Authentication Bypass
What is the Vulnerability?FortiGuard Labs has observed in-the-wild attack attempts targeting CVE-2025-31161, an authentication bypass vulnerability in CrushFTP managed file...
Multiple Vulnerabilities in Fortinet Products Could Allow for Remote Code Execution
Multiple vulnerabilities have been discovered Fortinet Products, the most severe of which could allow for remote code execution. FortiAnalyzer...
rust-openssl-0.10.72-1.el9 rust-openssl-sys-0.9.107-1.el9
FEDORA-EPEL-2025-13a0cac2ac Packages in this update: rust-openssl-0.10.72-1.el9 rust-openssl-sys-0.9.107-1.el9 Update description: Update the openssl crate to version 0.10.72. Update the openssl-sys crate...
rust-openssl-0.10.72-1.el10_0 rust-openssl-sys-0.9.107-1.el10_0
FEDORA-EPEL-2025-2495fcffcc Packages in this update: rust-openssl-0.10.72-1.el10_0 rust-openssl-sys-0.9.107-1.el10_0 Update description: Update the openssl crate to version 0.10.72. Update the openssl-sys crate...
rust-openssl-0.10.72-1.el10_1 rust-openssl-sys-0.9.107-1.el10_1
FEDORA-EPEL-2025-15fa9fed48 Packages in this update: rust-openssl-0.10.72-1.el10_1 rust-openssl-sys-0.9.107-1.el10_1 Update description: Update the openssl crate to version 0.10.72. Update the openssl-sys crate...
rust-openssl-0.10.72-1.fc40 rust-openssl-sys-0.9.107-1.fc40
FEDORA-2025-472776e5dc Packages in this update: rust-openssl-0.10.72-1.fc40 rust-openssl-sys-0.9.107-1.fc40 Update description: Update the openssl crate to version 0.10.72. Update the openssl-sys crate...