VendorsLinuxlinux_kernel2.6.12
Vulnerabilities

Linux Kernel 2.6.12

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

357CVEs
CVE-2026-31400
sunrpc: fix cache_request leak in cache_release
Published 2026-04-03 · Analyzed
5.5EPSS 0.002
CVE-2026-64252
MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
Published 2026-07-24 · Analyzed
5.5EPSS 0.002
CVE-2026-43156
net: usb: pegasus: enable basic endpoint checking
Published 2026-05-06 · Analyzed
5.5EPSS 0.002
CVE-2026-46151
usb: usblp: fix heap leak in IEEE 1284 device ID via short response
Published 2026-05-28 · Analyzed
5.5EPSS 0.002
CVE-2026-46002
ext2: reject inodes with zero i_nlink and valid mode in ext2_iget()
Published 2026-05-27 · Analyzed
5.5EPSS 0.002
CVE-2023-53457
FS: JFS: Fix null-ptr-deref Read in txBegin
Published 2025-10-01 · Analyzed
5.5EPSS 0.002
CVE-2025-38215
fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var
Published 2025-07-04 · Modified
5.5EPSS 0.002
CVE-2023-53620
md: fix soft lockup in status_resync
Published 2025-10-07 · Analyzed
5.5EPSS 0.002
CVE-2025-39716
parisc: Revise __get_user() to probe user read access
Published 2025-09-05 · Modified
5.5EPSS 0.001
CVE-2025-71118
ACPICA: Avoid walking the Namespace if start_node is NULL
Published 2026-01-14 · Analyzed
5.5EPSS 0.001
CVE-2026-46153
8021q: delete cleared egress QoS mappings
Published 2026-05-28 · Analyzed
5.5EPSS 0.001
CVE-2026-23474
mtd: Avoid boot crash in RedBoot partition table parser
Published 2026-04-03 · Modified
5.5EPSS 0.001
CVE-2026-53403
fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
Published 2026-07-19 · Analyzed
5.5EPSS 0.001
CVE-2026-23290
net: usb: pegasus: validate USB endpoints
Published 2026-03-25 · Modified
5.5EPSS 0.001
CVE-2026-64370
posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
Published 2026-07-25 · Analyzed
5.5EPSS 0.001
CVE-2026-23286
atm: lec: fix null-ptr-deref in lec_arp_clear_vccs
Published 2026-03-25 · Analyzed
5.5EPSS 0.001
CVE-2026-53249
ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
Published 2026-06-25 · Modified
5.5EPSS 0.001
CVE-2026-23460
net/rose: fix NULL pointer dereference in rose_transmit_link on reconnect
Published 2026-04-03 · Analyzed
5.5EPSS 0.001
CVE-2026-23312
net: usb: kaweth: validate USB endpoints
Published 2026-03-25 · Analyzed
5.5EPSS 0.001
CVE-2026-64335
USB: serial: digi_acceleport: fix broken rx after throttle
Published 2026-07-25 · Analyzed
5.5EPSS 0.001
CVE-2026-53236
tcp: restrict SO_ATTACH_FILTER to priv users
Published 2026-06-25 · Modified
5.5EPSS 0.001
CVE-2026-53208
Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
Published 2026-06-25 · Analyzed
5.5EPSS 0.001
CVE-2026-23472
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
Published 2026-04-03 · Analyzed
5.5EPSS 0.001
CVE-2026-23266
fbdev: rivafb: fix divide error in nv3_arb()
Published 2026-03-18 · Analyzed
5.5EPSS 0.001
CVE-2026-23255
net: add proper RCU protection to /proc/net/ptype
Published 2026-03-18 · Modified
5.5EPSS 0.001
CVE-2026-64334
USB: serial: digi_acceleport: fix hard lockup on disconnect
Published 2026-07-25 · Analyzed
5.5EPSS 0.001
CVE-2024-24864
Race condition vulnerability in Linux kernel media/dvb-core in dvbdmx_write()
Published 2024-02-05 · Modified
5.3EPSS 0.002
CVE-2005-2459
The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer dereference, a different vulnerability than CVE-2005-2458.
Published 2005-08-22 · Modified
5.0EPSS 0.046
CVE-2005-2458
inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with "improper tables".
Published 2005-08-22 · Modified
5.0EPSS 0.040
CVE-2006-0454
Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value.
Published 2006-02-07 · Modified
5.0EPSS 0.039
CVE-2005-2457
The driver for compressed ISO file systems (zisofs) in the Linux kernel before 2.6.12.5 allows local users and remote attackers to cause a denial of service (kernel crash) via a crafted compressed ISO file system.
Published 2005-08-22 · Modified
5.0EPSS 0.037
CVE-2012-1583
Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.
Published 2012-06-16 · Modified
5.0EPSS 0.036
CVE-2006-1242
The ip_push_pending_frames function in Linux 2.4.x and 2.6.x before 2.6.16 increments the IP ID field when sending a RST after receiving unsolicited TCP SYN-ACK packets, which allows remote attackers to conduct an Idle Scan (nmap -sI) attack, which bypasses intended protections against such attacks.
Published 2006-03-15 · Modified
5.0EPSS 0.035
CVE-2005-2099
The Linux kernel before 2.6.12.5 does not properly destroy a keyring that is not instantiated properly, which allows local users or remote attackers to cause a denial of service (kernel oops) via a keyring with a payload that is not empty, which causes the creation to fail, leading to a null dereference in the keyring destructor.
Published 2005-08-22 · Modified
5.0EPSS 0.033
CVE-2005-2098
The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via a new session keyring (1) with an empty name string, (2) with a long name string, (3) with the key quota reached, or (4) ENOMEM.
Published 2005-08-22 · Modified
5.0EPSS 0.032
CVE-2005-4635
The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink messages.
Published 2006-01-09 · Modified
5.0EPSS 0.029
CVE-2007-2451
Unspecified vulnerability in drivers/crypto/geode-aes.c in GEODE-AES in the Linux kernel before 2.6.21.3 allows attackers to obtain sensitive information via unspecified vectors.
Published 2007-05-29 · Modified
5.0EPSS 0.021
CVE-2007-1861
The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow.
Published 2007-05-07 · Modified
4.91 PoCEPSS 0.010
CVE-2005-3358
Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bitmask, which causes a panic when a page fault occurs.
Published 2005-12-14 · Modified
4.91 PoCEPSS 0.010
CVE-2009-2847
The do_sigaltstack function in kernel/signal.c in Linux kernel 2.4 through 2.4.37 and 2.6 before 2.6.31-rc5, when running on 64-bit systems, does not clear certain padding bytes from a structure, which allows local users to obtain sensitive information from the kernel stack via the sigaltstack function.
Published 2009-08-18 · Modified
4.91 PoCEPSS 0.009
← Prev6 / 9Next →