VendorsLinuxlinux_kernel2.6.34
Vulnerabilities

Linux Kernel 2.6.34

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2010-2521
Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary code via a crafted NFSv4 compound WRITE request, related to the read_buf and nfsd4_decode_compound functions.
Published 2010-09-07 · Modified
10.0EPSS 0.090
CVE-2022-49770
ceph: avoid putting the realm twice when decoding snaps fails
Published 2025-05-01 · Modified
9.8EPSS 0.006
CVE-2023-52732
ceph: blocklist the kclient when receiving corrupted snap trace
Published 2024-05-21 · Modified
9.8EPSS 0.005
CVE-2026-52955
libceph: Fix potential out-of-bounds access in crush_decode()
Published 2026-06-24 · Analyzed
9.8EPSS 0.005
CVE-2026-43407
libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
Published 2026-05-08 · Analyzed
9.1EPSS 0.007
CVE-2026-46119
libceph: Fix slab-out-of-bounds access in auth message processing
Published 2026-05-28 · Undergoing Analysis
9.1EPSS 0.007
CVE-2010-2248
fs/cifs/cifssmb.c in the CIFS implementation in the Linux kernel before 2.6.34-rc4 allows remote attackers to cause a denial of service (panic) via an SMB response packet with an invalid CountHigh value, as demonstrated by a response from an OS/2 server, related to the CIFSSMBWrite and CIFSSMBWrite2 functions.
Published 2010-09-07 · Modified
7.8EPSS 0.040
CVE-2025-39927
ceph: fix race condition validating r_parent before applying state
Published 2025-10-01 · Modified
7.8EPSS 0.001
CVE-2026-46052
ceph: only d_add() negative dentries when they are unhashed
Published 2026-05-27 · Modified
7.5EPSS 0.007
CVE-2026-46024
libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()
Published 2026-05-27 · Analyzed
7.5EPSS 0.007
CVE-2024-56644
net/ipv6: release expired exception dst cached in socket
Published 2024-12-27 · Modified
7.5EPSS 0.007
CVE-2026-22990
libceph: replace overzealous BUG_ON in osdmap_apply_incremental()
Published 2026-01-23 · Modified
7.5EPSS 0.004
CVE-2010-1162
The release_one_tty function in drivers/char/tty_io.c in the Linux kernel before 2.6.34-rc4 omits certain required calls to the put_pid function, which has unspecified impact and local attack vectors.
Published 2010-04-20 · Modified
7.2EPSS 0.004
CVE-2010-1437
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.
Published 2010-05-07 · Modified
7.01 PoCEPSS 0.007
CVE-2022-49109
ceph: fix inode reference leakage in ceph_get_snapdir()
Published 2025-02-26 · Analyzed
5.5EPSS 0.003
CVE-2024-53685
ceph: give up on paths longer than PATH_MAX
Published 2025-01-11 · Modified
5.5EPSS 0.002
CVE-2023-53125
net: usb: smsc75xx: Limit packet length to skb->len
Published 2025-05-02 · Analyzed
5.5EPSS 0.002
CVE-2025-38474
usb: net: sierra: check for no status endpoint
Published 2025-07-28 · Analyzed
5.5EPSS 0.002
CVE-2026-23367
wifi: radiotap: reject radiotap with unknown bits
Published 2026-03-25 · Analyzed
5.5EPSS 0.001
CVE-2026-23357
can: mcp251x: fix deadlock in error path of mcp251x_open
Published 2026-03-25 · Analyzed
5.5EPSS 0.001
CVE-2010-1088
fs/namei.c in Linux kernel 2.6.18 through 2.6.34 does not always follow NFS automount "symlinks," which allows attackers to have an unknown impact, related to LOOKUP_FOLLOW.
Published 2010-04-06 · Modified
5.4EPSS 0.028
CVE-2012-4444
The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.
Published 2012-12-21 · Modified
5.0EPSS 0.036
CVE-2024-24855
Race condition vulnerability in Linux kernel scsi device driver lpfc_unregister_fcf_rescan()
Published 2024-02-05 · Modified
5.0EPSS 0.002
CVE-2026-46159
btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak
Published 2026-05-28 · Modified
4.7EPSS 0.001
CVE-2010-1641
The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.
Published 2010-06-01 · Modified
4.6EPSS 0.004
CVE-2010-1488
The proc_oom_score function in fs/proc/base.c in the Linux kernel before 2.6.34-rc4 uses inappropriate data structures during selection of a candidate for the OOM killer, which might allow local users to cause a denial of service via unspecified patterns of task creation.
Published 2010-04-20 · Modified
2.1EPSS 0.003
CVE-2010-4525
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.
Published 2011-01-11 · Modified
1.9EPSS 0.003