Skip to main content

Vendor/product archive

oracle / linux CVEs

Beta · best-effort

230 CVEs tagged to oracle / linux24 Critical, 85 High, 101 Medium, 20 Low, 0 Unrated.

CVE-2026-35233

Published May 1, 2026

An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21996

Published May 1, 2026

An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21991

Published Mar 16, 2026

A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-21505

Published Dec 24, 2024

In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailabl…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22024

Published Sep 20, 2023

In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local us…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21385

Published Aug 29, 2022

A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector (CVSS:3.1/A…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21504

Published Jun 14, 2022

The code in UEK6 U3 was missing an appropiate file descriptor count to be missing. This resulted in a use count error that allowed a file descriptor to a socket to be closed and f…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21499

Published Jun 9, 2022

KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-2464

Published Sep 24, 2021

Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitable vulnerability allows low privileged attacker with logon…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1908

Published Apr 11, 2017

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows rem…

CVSS 9.8 · Critical

CVE-2015-8896

Published Mar 15, 2017

Integer truncation issue in coders/pict.c in ImageMagick before 7.0.5-0 allows remote attackers to cause a denial of service (application crash) via a crafted .pict file.

CVSS 6.5 · Medium

CVE-2015-7977

Published Jan 30, 2017

ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.

CVSS 5.9 · Medium

CVE-2016-5425

Published Oct 13, 2016

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Showing 1-25 of 230 CVEsPage 1 of 10