Oracle / Linux
230 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-35233 | An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches t… | MEDIUM | 4.4 | May 1, 2026 |
| CVE-2026-21996 | An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab() | MEDIUM | 5.5 | May 1, 2026 |
| CVE-2026-21991 | A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names. | MEDIUM | 5.5 | Mar 16, 2026 |
| CVE-2025-4598 | Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump | MEDIUM | 4.7 | May 30, 2025 |
| CVE-2022-21505 | kernel: lockdown bypass using IMA | MEDIUM | 6.7 | Dec 24, 2024 |
| CVE-2023-22024 | In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A… | MEDIUM | 5.5 | Sep 20, 2023 |
| CVE-2022-21385 | A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Base Score 6.2 (Availability impacts). CVS… | MEDIUM | 6.2 | Aug 29, 2022 |
| CVE-2022-21504 | The code in UEK6 U3 was missing an appropiate file descriptor count to be missing. This resulted in a use count error that allowed a file descriptor to a socke… | MEDIUM | 5.5 | Jun 14, 2022 |
| CVE-2022-21499 | kernel: possible to use the debugger to write zero into a location of choice | MEDIUM | 6.7 | Jun 9, 2022 |
| CVE-2021-3551 | pki-server: Dogtag installer "pkispawn" logs admin credentials into a world-readable log file | HIGH | 7.8 | Feb 16, 2022 |
| CVE-2021-2464 | Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitable vulnerability allows low privileged… | HIGH | 7.8 | Sep 24, 2021 |
| CVE-2018-17962 | QEMU: pcnet: integer overflow leads to buffer overflow | HIGH | 7.5 | Oct 9, 2018 |
| CVE-2015-7852 | ntp: ntpq atoascii memory corruption vulnerability | MEDIUM | 5.9 | Aug 7, 2017 |
| CVE-2015-7702 | ntp: incomplete checks in ntp_crypto.c | MEDIUM | 6.5 | Aug 7, 2017 |
| CVE-2015-7701 | ntp: slow memory leak in CRYPTO_ASSOC | HIGH | 7.5 | Aug 7, 2017 |
| CVE-2015-7692 | ntp: incomplete checks in ntp_crypto.c | HIGH | 7.5 | Aug 7, 2017 |
| CVE-2015-7691 | ntp: incomplete checks in ntp_crypto.c | HIGH | 7.5 | Aug 7, 2017 |
| CVE-2015-7703 | ntp: config command can be used to set the pidfile and drift file paths | HIGH | 7.5 | Jul 24, 2017 |
| CVE-2015-5219 | ntp: infinite loop in sntp processing crafted packet | HIGH | 7.5 | Jul 21, 2017 |
| CVE-2016-1908 | openssh: possible fallback from untrusted to trusted X11 forwarding | CRITICAL | 9.8 | Apr 11, 2017 |
| CVE-2015-8896 | ImageMagick: Integer truncation vulnerability in coders/pict.c | MEDIUM | 6.5 | Mar 15, 2017 |
| CVE-2016-2518 | ntp: out-of-bounds references on crafted packet | MEDIUM | 5.3 | Jan 30, 2017 |
| CVE-2015-7977 | ntp: restriction list NULL pointer dereference | MEDIUM | 5.9 | Jan 30, 2017 |
| CVE-2016-7039 | kernel: remotely triggerable unbounded recursion in the vlan gro code leading to a kernel crash | HIGH | 7.5 | Oct 16, 2016 |
| CVE-2016-0617 | kernel: hugetlbfs: fix bugs in hugetlb_vmtruncate_list() | MEDIUM | 5.5 | Sep 30, 2016 |
Showing 1 to 25 of 230 CVEs