VendorsLinuxlinux_kernel2.6.39
Vulnerabilities

Linux Kernel 2.6.39

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2011-2211
The osf_wait4 function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform uses an incorrect pointer, which allows local users to gain privileges by writing a certain integer value to kernel memory.
Published 2012-06-13 · Modified
7.2EPSS 0.005
CVE-2011-2182
The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain sensitive information, via a crafted LDM partition table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1017.
Published 2012-06-13 · Modified
7.2EPSS 0.004
CVE-2026-45917
ipvs: do not keep dest_dst if dev is going down
Published 2026-05-27 · Undergoing Analysis
5.5EPSS 0.002
CVE-2025-71184
btrfs: fix NULL dereference on root when tracing inode eviction
Published 2026-01-31 · Analyzed
5.5EPSS 0.001
CVE-2011-1598
The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
Published 2011-05-09 · Modified
4.9EPSS 0.004
CVE-2011-1748
The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.
Published 2011-05-09 · Modified
4.9EPSS 0.004
CVE-2011-2183
Race condition in the scan_get_next_rmap_item function in mm/ksm.c in the Linux kernel before 2.6.39.3, when Kernel SamePage Merging (KSM) is enabled, allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted application.
Published 2012-06-13 · Modified
4.01 PoCEPSS 0.005
CVE-2011-2210
The osf_getsysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform does not properly restrict the data size for GSI_GET_HWRPB operations, which allows local users to obtain sensitive information from kernel memory via a crafted call.
Published 2012-06-13 · Modified
2.1EPSS 0.005
CVE-2011-2495
fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password.
Published 2012-06-13 · Modified
2.1EPSS 0.005
CVE-2011-2208
Integer signedness error in the osf_getdomainname function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call.
Published 2012-06-13 · Modified
2.1EPSS 0.005
CVE-2011-2209
Integer signedness error in the osf_sysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call.
Published 2012-06-13 · Modified
2.1EPSS 0.005