Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

829 CVEs tagged with CWE-90891 Critical, 255 High, 450 Medium, 33 Low, 0 Unrated.

CVE-2024-29780

Published Jun 13, 2024

In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data disclosure due to uninitialized data. This could lead to local i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36454

Published Jun 12, 2024

Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability is ex…

CVSS 5.3 · Medium

CVE-2024-36933

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). syzbot triggered various…

CVSS 7.8 · High
evidence mentions
11
Buzz score
36.4
Vendor/product tagsBeta · best-effort

CVE-2024-36927

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1].…

CVSS 4.7 · Medium
evidence mentions
9
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2024-36903

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix…

CVSS 5.5 · Medium
evidence mentions
9
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2024-36900

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when devlink reload during initialization The devlink reload process will access…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36898

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix uninitialised kfifo If a line is requested with debounce, and that results in debouncing i…

CVSS 7.1 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2024-36021

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when devlink reload during pf initialization The devlink reload process will acce…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36020

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: i40e: fix vf may be used uninitialized in this function warning To fix the regression introduced by commit 52…

CVSS 7.8 · High
evidence mentions
11
Buzz score
36.4
Vendor/product tagsBeta · best-effort

CVE-2021-47554

Published May 24, 2024

In the Linux kernel, the following vulnerability has been resolved: vdpa_sim: avoid putting an uninitialized iova_domain The system will crash if we put an uninitialized iova_do…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47553

Published May 24, 2024

In the Linux kernel, the following vulnerability has been resolved: sched/scs: Reset task stack state in bringup_cpu() To hot unplug a CPU, the idle task on that CPU calls a few…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47462

Published May 22, 2024

In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: do not allow illegal MPOL_F_NUMA_BALANCING | MPOL_LOCAL in mbind() syzbot reported access to un…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47451

Published May 22, 2024

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: fix panic that occurs when timer_type has garbage value Currently, when the rule rel…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2021-47446

Published May 22, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/msm/a4xx: fix error handling in a4xx_gpu_init() This code returns 1 on error instead of a negative error.…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-52845

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: tipc: Change nla_policy for bearer-related names to NLA_NUL_STRING syzbot reported the following uninit-value…

CVSS 7.1 · High
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort

CVE-2023-52843

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: llc: verify mac len before reading mac header LLC reads the mac header with eth_hdr without verifying that th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52842

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: virtio/vsock: Fix uninit-value in virtio_transport_recv_pkt() KMSAN reported the following uninit-value acces…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52792

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: cxl/region: Do not try to cleanup after cxl_region_setup_targets() fails Commit 5e42bcbc3fef ("cxl/region: de…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52703

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: net/usb: kalmia: Don't pass act_len in usb_bulk_msg error path syzbot reported that act_len in kalmia_send_in…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47424

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: i40e: Fix freeing of uninitialized misc IRQ vector When VSI set up failed in i40e_probe() as part of PF switc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47339

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-core: explicitly clear ioctl input data As seen from a recent syzbot bug report, mistakes in the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47297

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: net: fix uninit-value in caif_seqpkt_sendmsg When nr_segs equal to zero in iovec_from_user, the object msg->m…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35973

Published May 20, 2024

In the Linux kernel, the following vulnerability has been resolved: geneve: fix header validation in geneve[6]_xmit_skb syzbot is able to trigger an uninit-value in geneve_xmit(…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35915

Published May 19, 2024

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet syzbot reported the following uninit-value access…

CVSS 8.8 · High
evidence mentions
11
Buzz score
36.4
Vendor/product tagsBeta · best-effort

CVE-2024-35893

Published May 19, 2024

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_skbmod: prevent kernel-infoleak syzbot found that tcf_skbmod_dump() was copying four bytes fro…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 829 CVEsPage 17 of 34