VendorsLinuxlinux_kernel2.6.12
Vulnerabilities

Linux Kernel 2.6.12

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

357CVEs
CVE-2005-3848
Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in icmp_push_reply."
Published 2005-11-27 · Modified
7.8EPSS 0.054
CVE-2010-0008
The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.
Published 2010-03-19 · Modified
7.8EPSS 0.045
CVE-2009-1439
Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB mount request.
Published 2009-04-27 · Modified
7.8EPSS 0.043
CVE-2010-2248
fs/cifs/cifssmb.c in the CIFS implementation in the Linux kernel before 2.6.34-rc4 allows remote attackers to cause a denial of service (panic) via an SMB response packet with an invalid CountHigh value, as demonstrated by a response from an OS/2 server, related to the CIFSSMBWrite and CIFSSMBWrite2 functions.
Published 2010-09-07 · Modified
7.8EPSS 0.040
CVE-2019-12615
An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).
Published 2019-06-03 · Modified
7.8EPSS 0.039
CVE-2007-3642
The decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the Linux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.22 allows remote attackers to cause a denial of service (crash) via an encoded, out-of-range index value for a choice field, which triggers a NULL pointer dereference.
Published 2007-07-10 · Modified
7.8EPSS 0.039
CVE-2008-2750
The pppol2tp_recvmsg function in drivers/net/pppol2tp.c in the Linux kernel 2.6 before 2.6.26-rc6 allows remote attackers to cause a denial of service (kernel heap memory corruption and system crash) and possibly have unspecified other impact via a crafted PPPOL2TP packet that results in a large value for a certain length variable.
Published 2008-06-18 · Modified
7.8EPSS 0.038
CVE-2010-0741
The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause a denial of service (guest OS crash, and an associated qemu-kvm process exit) by sending a large amount of network traffic to a TCP port on the guest OS, related to a virtio-net whitelist that includes an improper implementation of TCP Segment Offloading (TSO).
Published 2010-04-12 · Modified
7.8EPSS 0.035
CVE-2009-3623
The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an NFSv4 mount request.
Published 2009-10-30 · Modified
7.8EPSS 0.035
CVE-2009-2844
cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies function. NOTE: a potential weakness in the is_mesh function was also addressed, but the relevant condition did not exist in the code, so it is not a vulnerability.
Published 2009-08-18 · Modified
7.8EPSS 0.034
CVE-2005-3858
Memory leak in the ip6_input_finish function in ip6_input.c in Linux kernel 2.6.12 and earlier might allow attackers to cause a denial of service via malformed IPv6 packets with unspecified parameter problems, which prevents the SKB from being freed.
Published 2005-11-27 · Modified
7.8EPSS 0.033
CVE-2006-3085
xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers to cause a denial of service (infinite loop) via an SCTP chunk with a 0 length.
Published 2006-06-23 · Modified
7.8EPSS 0.031
CVE-2009-4026
The mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (panic) via a crafted Delete Block ACK (aka DELBA) packet, related to an erroneous "code shuffling patch."
Published 2009-12-02 · Modified
7.8EPSS 0.031
CVE-2006-2936
The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up to 2.6.17, and possibly later versions, allows local users to cause a denial of service (memory consumption) by writing more data to the serial port than the hardware can handle, which causes the data to be queued.
Published 2006-07-10 · Modified
7.8EPSS 0.030
CVE-2005-4886
The selinux_parse_skb_ipv6 function in security/selinux/hooks.c in the Linux kernel before 2.6.12-rc4 allows remote attackers to cause a denial of service (OOPS) via vectors associated with an incorrect call to the ipv6_skip_exthdr function.
Published 2010-02-26 · Modified
7.8EPSS 0.027
CVE-2007-6694
The chrp_show_cpuinfo function (chrp/setup.c) in Linux kernel 2.4.21 through 2.6.18-53, when running on PowerPC, might allow local users to cause a denial of service (crash) via unknown vectors that cause the of_get_property function to fail, which triggers a NULL pointer dereference.
Published 2008-01-29 · Modified
7.8EPSS 0.026
CVE-2024-21803
Possible UAF in bt_accept_poll in Linux kernel
Published 2024-01-30 · Analyzed
7.8EPSS 0.005
CVE-2025-21704
usb: cdc-acm: Check control transfer buffer size before access
Published 2025-02-22 · Modified
7.8EPSS 0.004
CVE-2025-38617
net/packet: fix a race in packet_set_ring() and packet_notifier()
Published 2025-08-22 · Modified
7.8EPSS 0.003
CVE-2024-35886
ipv6: Fix infinite recursion in fib6_dump_done().
Published 2024-05-19 · Modified
7.8EPSS 0.003
CVE-2024-58094
jfs: add check read-only before truncation in jfs_truncate_nolock()
Published 2025-04-16 · Modified
7.8EPSS 0.002
CVE-2025-37823
net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
Published 2025-05-08 · Modified
7.8EPSS 0.002
CVE-2025-38323
net: atm: add lec_mutex
Published 2025-07-10 · Analyzed
7.8EPSS 0.002
CVE-2023-53485
fs: jfs: Fix UBSAN: array-index-out-of-bounds in dbAllocDmapLev
Published 2025-10-01 · Modified
7.8EPSS 0.002
CVE-2025-38702
fbdev: fix potential buffer overflow in do_register_framebuffer()
Published 2025-09-04 · Modified
7.8EPSS 0.002
CVE-2025-38180
net: atm: fix /proc/net/atm/lec handling
Published 2025-07-04 · Modified
7.8EPSS 0.002
CVE-2025-38697
jfs: upper bound check of tree index in dbAllocAG
Published 2025-09-04 · Modified
7.8EPSS 0.002
CVE-2025-38193
net_sched: sch_sfq: reject invalid perturb period
Published 2025-07-04 · Modified
7.8EPSS 0.002
CVE-2025-22109
ax25: Remove broken autobind
Published 2025-04-16 · Modified
7.8EPSS 0.002
CVE-2025-39691
fs/buffer: fix use-after-free when call bh_read() helper
Published 2025-09-05 · Modified
7.8EPSS 0.002
CVE-2025-38459
atm: clip: Fix infinite recursive call of clip_push().
Published 2025-07-25 · Analyzed
7.8EPSS 0.002
CVE-2025-38685
fbdev: Fix vmalloc out-of-bounds write in fast_imageblit
Published 2025-09-04 · Modified
7.8EPSS 0.002
CVE-2025-38542
net: appletalk: Fix device refcount leak in atrtr_create()
Published 2025-08-16 · Modified
7.8EPSS 0.002
CVE-2026-64333
USB: serial: digi_acceleport: fix write buffer corruption
Published 2026-07-25 · Analyzed
7.8EPSS 0.002
CVE-2026-64273
Input: iforce - bound the device-reported force-feedback effect index
Published 2026-07-25 · Analyzed
7.8EPSS 0.002
CVE-2025-39828
atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control().
Published 2025-09-16 · Modified
7.8EPSS 0.002
CVE-2025-38230
jfs: validate AG parameters in dbMount() to prevent crashes
Published 2025-07-04 · Modified
7.8EPSS 0.002
CVE-2025-38666
net: appletalk: Fix use-after-free in AARP proxy probe
Published 2025-08-22 · Analyzed
7.8EPSS 0.002
CVE-2025-38714
hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()
Published 2025-09-04 · Modified
7.8EPSS 0.002
CVE-2025-38715
hfs: fix slab-out-of-bounds in hfs_bnode_read()
Published 2025-09-04 · Modified
7.8EPSS 0.002
← Prev2 / 9Next →