VendorsLinuxlinux_kernel2.6.12
Vulnerabilities

Linux Kernel 2.6.12

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

357CVEs
CVE-2010-2521
Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary code via a crafted NFSv4 compound WRITE request, related to the read_buf and nfsd4_decode_compound functions.
Published 2010-09-07 · Modified
10.0EPSS 0.090
CVE-2008-1673
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; or (3) an indefinite length for a primitive encoding.
Published 2008-06-10 · Modified
10.0EPSS 0.071
CVE-2008-5134
Buffer overflow in the lbs_process_bss function in drivers/net/wireless/libertas/scan.c in the libertas subsystem in the Linux kernel before 2.6.27.5 allows remote attackers to have an unknown impact via an "invalid beacon/probe response."
Published 2008-11-18 · Modified
10.0EPSS 0.054
CVE-2026-43011
net/x25: Fix potential double free of skb
Published 2026-05-01 · Modified
9.8EPSS 0.009
CVE-2026-31405
media: dvb-net: fix OOB access in ULE extension header tables
Published 2026-04-06 · Analyzed
9.8EPSS 0.008
CVE-2026-52982
net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
Published 2026-06-24 · Analyzed
9.8EPSS 0.007
CVE-2026-53246
sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
Published 2026-06-25 · Analyzed
9.8EPSS 0.006
CVE-2026-31402
nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
Published 2026-04-03 · Modified
9.8EPSS 0.006
CVE-2026-43198
tcp: fix potential race in tcp_v6_syn_recv_sock()
Published 2026-05-06 · Modified
9.8EPSS 0.004
CVE-2026-31685
netfilter: ip6t_eui64: reject invalid MAC header for all packets
Published 2026-04-25 · Modified
9.4EPSS 0.006
CVE-2026-53131
netfilter: require Ethernet MAC header before using eth_hdr()
Published 2026-06-25 · Analyzed
9.4EPSS 0.006
CVE-2026-53224
sctp: validate embedded INIT chunk and address list lengths in cookie
Published 2026-06-25 · Analyzed
9.1EPSS 0.007
CVE-2026-46266
inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
Published 2026-06-03 · Modified
9.1EPSS 0.007
CVE-2006-1857
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.
Published 2006-05-22 · Modified
9.0EPSS 0.069
CVE-2026-43158
xfs: fix freemap adjustments when adding xattrs to leaf blocks
Published 2026-05-06 · Analyzed
8.8EPSS 0.007
CVE-2026-43187
xfs: delete attr leaf freemap entries when empty
Published 2026-05-06 · Analyzed
8.8EPSS 0.007
CVE-2026-64178
Bluetooth: bnep: Fix UAF read of dev->name
Published 2026-07-19 · Analyzed
8.8EPSS 0.004
CVE-2026-31408
Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold
Published 2026-04-06 · Modified
8.8EPSS 0.004
CVE-2026-52918
Bluetooth: serialize accept_q access
Published 2026-06-24 · Analyzed
8.8EPSS 0.003
CVE-2024-27415
netfilter: bridge: confirm multicast packets before passing them up the stack
Published 2024-05-17 · Modified
8.8EPSS 0.003
CVE-2025-38377
rose: fix dangling neighbour pointers in rose_rt_device_down()
Published 2025-07-25 · Modified
8.8EPSS 0.002
CVE-2025-39848
ax25: properly unshare skbs in ax25_kiss_rcv()
Published 2025-09-19 · Modified
8.8EPSS 0.002
CVE-2025-39827
net: rose: include node references in rose_neigh refcount
Published 2025-09-16 · Modified
8.8EPSS 0.002
CVE-2025-39826
net: rose: convert 'use' field to refcount_t
Published 2025-09-16 · Modified
8.8EPSS 0.002
CVE-2026-23098
netrom: fix double-free in nr_route_frame()
Published 2026-02-04 · Modified
8.8EPSS 0.002
CVE-2025-38574
pptp: ensure minimal skb length in pptp_xmit()
Published 2025-08-19 · Modified
8.6EPSS 0.004
CVE-2026-53369
udf: reject descriptors with oversized CRC length
Published 2026-07-19 · Analyzed
8.4EPSS 0.002
CVE-2026-43190
netfilter: xt_tcpmss: check remaining length before reading optlen
Published 2026-05-06 · Analyzed
8.2EPSS 0.006
CVE-2026-45843
slip: bound decode() reads against the compressed packet length
Published 2026-05-27 · Analyzed
8.2EPSS 0.005
CVE-2025-37749
net: ppp: Add bound checking for skb data on ppp_sync_txmung
Published 2025-05-01 · Modified
8.2EPSS 0.004
CVE-2026-53254
Bluetooth: RFCOMM: validate skb length in MCC handlers
Published 2026-06-25 · Analyzed
8.1EPSS 0.003
CVE-2026-53256
Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
Published 2026-06-25 · Analyzed
8.0EPSS 0.002
CVE-2006-2444
The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling function, as demonstrated via certain test cases of the PROTOS SNMP test suite.
Published 2006-05-25 · Modified
7.81 PoCEPSS 0.221
CVE-2006-3468
Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and causes an exported directory to be remounted read-only.
Published 2006-07-18 · Modified
7.81 PoCEPSS 0.160
CVE-2009-3613
The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of service (IOMMU space exhaustion and system crash) by using jumbo frames for a large amount of network traffic, as demonstrated by a flood ping.
Published 2009-10-19 · Modified
7.81 PoCEPSS 0.125
CVE-2010-0437
The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.
Published 2010-03-24 · Modified
7.81 PoCEPSS 0.124
CVE-2009-3726
The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.
Published 2009-11-09 · Modified
7.81 PoCEPSS 0.120
CVE-2009-2846
The eisa_eeprom_read function in the parisc isa-eeprom component (drivers/parisc/eisa_eeprom.c) in the Linux kernel before 2.6.31-rc6 allows local users to access restricted memory via a negative ppos argument, which bypasses a check that assumes that ppos is positive and causes an out-of-bounds read in the readb function.
Published 2009-08-18 · Modified
7.8EPSS 0.082
CVE-2006-1858
SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.
Published 2006-05-22 · Modified
7.8EPSS 0.063
CVE-2009-1389
Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.
Published 2009-06-16 · Modified
7.8EPSS 0.055
1 / 9Next →