Linux Vulnerabilities

Timeline

The analysis of the timeline helps to identify the required approach and handling of single vulnerabilities and vulnerability collections. This overview makes it possible to see less important slices and more severe hotspots at a glance. Initiating immediate vulnerability response and prioritizing of issues is possible.

Type

The moderation team is working with the threat intelligence team to categorize software that is affected by security vulnerabilities. This helps to illustrate the assignment of these categories to determine the most affected software types.

Product

Linux Kernel4377
Linux Foundation Xen122
Linux Foundation ONOS8
Linux Foundation cups-filters5
Linux Foundation xen5

Grouping vulnerabilities by products helps to get an overview. This makes it possible to determine an homogeneous landscape or the most important hotspots in heterogeneous landscapes.

Remediation

Official Fix4066
Temporary Fix0
Workaround15
Unavailable13
Not Defined463

Vendors and researchers are eager to find countermeasures to mitigate security vulnerabilities. These can be distinguished between multiple forms and levels of remediation which influence risks differently.

Exploitability

High28
Functional3
Proof-of-Concept539
Unproven229
Not Defined3758

Researcher and attacker which are looking for security vulnerabilities try to exploit them for academic purposes or personal gain. The level and quality of exploitability can be distinguished to determine simplicity and strength of attacks.

Access Vector

Not Defined0
Physical61
Local1966
Adjacent1585
Network945

The approach a vulnerability it becomes important to use the expected access vector. This is typically via the network, local, or physically even.

Authentication

Not Defined0
High58
Low2655
None1844

To exploit a vulnerability a certail level of authentication might be required. Vulnerabilities without such a requirement are much more popular.

User Interaction

Not Defined0
Required77
None4480

Some attack scenarios require some user interaction by a victim. This is typical for phishing, social engineering and cross site scripting attacks.

C3BM Index

Our unique C3BM Index (CVSSv3 Base Meta Index) cumulates the CVSSv3 Meta Base Scores of all entries over time. Comparing this index to the amount of disclosed vulnerabilities helps to pinpoint the most important events.

CVSSv3 Base

≤10
≤20
≤383
≤4550
≤5704
≤61374
≤7943
≤8549
≤9230
≤10124

The Common Vulnerability Scoring System (CVSS) is an industry standard to define the characteristics and impacts of security vulnerabilities. The base score represents the intrinsic aspects that are constant over time and across user environments. Our unique meta score merges all available scores from different sources to aggregate to the most reliable result.

CVSSv3 Temp

≤10
≤20
≤3100
≤4563
≤5805
≤61616
≤7746
≤8466
≤9203
≤1058

The Common Vulnerability Scoring System (CVSS) uses temp scores to reflect the characteristics of a vulnerability that may change over time but not across user environments. This includes reporting confidence, exploitability and remediation levels. We do also provide our unique meta score for temp scores, even though other sources rarely publish them.

VulDB

≤10
≤21
≤3119
≤4807
≤5516
≤61567
≤7631
≤8560
≤9200
≤10156

The moderation team is always defining the base vector and base score for an entry. These and all other available scores are used to generate the meta score.

NVD

≤10
≤20
≤39
≤427
≤5149
≤6499
≤7193
≤8538
≤934
≤1060

The National Vulnerability Database (NVD) is also defining CVSS vectors and scores. These are usually not complete and might differ from VulDB scores.

CNA

≤10
≤20
≤35
≤413
≤534
≤661
≤750
≤879
≤92
≤102

A CVE Numbering Authority (CNA) is responsible for assigning new CVE entries. They might also include a CVSS score. These are usually not complete and might differ from VulDB scores.

Vendor

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

Some vendors are willing to publish their own CVSS vectors and scores for vulnerabilities in their products. The coverage varies from vendor to vendor.

Research

≤10
≤20
≤30
≤40
≤50
≤61
≤70
≤80
≤90
≤100

There are sometimes also security researcher which provide their own CVSS vectors and scores for vulnerabilities they have found and published.

Exploit 0-day

<1k33
<2k82
<5k1016
<10k2258
<25k974
<50k186
<100k7
≥100k1

The moderation team is working with the threat intelligence team to determine prices for exploits. Our unique algorithm is used to identify the 0-day prices for an exploit, before it got distributed or became public. Calculated prices are aligned to prices disclosed by vulnerability broker and compared to prices we see on exploit markets.

Exploit Today

<1k3158
<2k635
<5k529
<10k175
<25k60
<50k0
<100k0
≥100k0

The 0-day prices do not consider time-relevant factors. The today price does reflect price impacts like disclosure of vulnerability details, alternative exploits, availability of countermeasures. These dynamic aspects might decrease the exploit prices over time. Under certain circumstances this happens very fast.

Exploit Market Volume

Our unique calculation of exploit prices makes it possible to forecast the expected exploit market volume. The calculated prices for all possible 0-day expoits are cumulated for this task. Comparing the volume to the amount of disclosed vulnerabilities helps to pinpoint the most important events.

🔴 CTI Activities

Our unique Cyber Threat Intelligence aims to determine the ongoing research of actors to anticipiate their acitivities. Observing exploit markets on the Darknet, discussions of vulnerabilities on mailinglists, and exchanges on social media makes it possible to identify planned attacks. Monitored actors and activities are classified whether they are offensive or defensive. They are also weighted as some actors are well-known for certain products and technologies. And some of their disclosures might contain more or less details about technical aspects and personal context. The world map highlights active actors in real-time.

Affected Products (32): Board-TNK (1), CPU (1), DeepOfix (1), Enterprise Server (1), Heartbeat (2), Jami (2), Kernel (4377), LibThai (1), MySQL (1), MySQLDatabase Admin Tool (1), News-TNK (1), Nslookup (1), OCF Resource Agents (1), ONOS (8), ONOS SDN Controller (1), Sblim-sfcb (2), Traceroute Script (1), UMIP (2), XEN (1), Xen (122), Xen Elf Parser (3), Xreader (2), cups-filters (5), foomatic (1), heartbeat (2), libvchan (1), nfs-utils (3), php Download Manager (1), php User Base (1), sblim-sfcb (4), xen (5), zephyr (1)

Link to Vendor Website: https://www.kernel.org/

PublishedBaseTempVulnerabilityProdExpRemEPSSCTICVE
05/14/20245.04.9Linux Kernel register_device null pointer dereferenceOperating SystemNot DefinedOfficial Fix0.000000.13-CVE-2024-4810
05/13/20245.55.3Linux Kernel io_uring Privilege EscalationOperating SystemNot DefinedOfficial Fix0.000000.25CVE-2023-52656
05/13/20244.64.4Linux Kernel Bluetooth sco_sock_timeout use after freeOperating SystemNot DefinedOfficial Fix0.000000.15CVE-2024-27398
05/13/20247.87.5Linux Kernel firewire packet_buffer_get buffer overflowOperating SystemNot DefinedOfficial Fix0.000000.09CVE-2024-27401
05/13/20245.55.3Linux Kernel amdgpu amdgpu_ttm_move heap-based overflowOperating SystemNot DefinedOfficial Fix0.000000.09CVE-2024-27400
05/13/20245.35.1Linux Kernel Bluetooth l2cap_chan_timeout null pointer dereferenceOperating SystemNot DefinedOfficial Fix0.000000.09CVE-2024-27399
05/13/20247.37.0Linux Kernel aqc111 skb_trim wrap-aroundOperating SystemNot DefinedOfficial Fix0.000000.10CVE-2023-52655
05/09/20245.35.1Linux Kernel nf_tables information disclosureOperating SystemNot DefinedOfficial Fix0.000430.00CVE-2024-27397
05/09/20247.16.8Linux Kernel net gtp_dellink use after freeOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2024-27396
05/09/20247.16.8Linux Kernel tcp_ao_connect_init use after freeOperating SystemNot DefinedOfficial Fix0.000430.04CVE-2024-27394
05/09/20244.64.4Linux Kernel af_unix unix_stream_read_generic Privilege EscalationOperating SystemNot DefinedOfficial Fix0.000440.05CVE-2023-52654
05/09/20247.16.8Linux Kernel openvswitch ovs_ct_exit use after freeOperating SystemNot DefinedOfficial Fix0.000440.04CVE-2024-27395
05/09/20245.75.5Linux Kernel page_pool skb_mark_for_recycle memory leakOperating SystemNot DefinedOfficial Fix0.000450.04CVE-2024-27393
05/08/20246.96.8Linux Kernel Bluetooth CMTP Module double freeOperating SystemNot DefinedOfficial Fix0.000650.04CVE-2021-34981
05/03/20245.55.3Linux Kernel mpt3sas refcount.c use after freeOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2022-48695
05/03/20245.75.5Linux Kernel XDP_SETUP_XSK_POOL ice_vsi_cfg_rxq memory leakOperating SystemNot DefinedOfficial Fix0.000430.04CVE-2022-48690
05/03/20244.84.6Linux Kernel mt7921e napi_diable denial of serviceOperating SystemNot DefinedOfficial Fix0.000430.03CVE-2022-48705
05/03/20242.62.5Linux Kernel radeon_suspend_kms denial of serviceOperating SystemNot DefinedOfficial Fix0.000440.05CVE-2022-48704
05/03/20245.75.5Linux Kernel soc brcmstb_pm_probe memory leakOperating SystemNot DefinedOfficial Fix0.000440.04CVE-2022-48693
05/03/20244.84.6Linux Kernel null pointer dereferenceOperating SystemNot DefinedOfficial Fix0.000450.04CVE-2022-48692
05/03/20242.62.5Linux Kernel irdma ib_drain_sq state issueOperating SystemNot DefinedOfficial Fix0.000450.00CVE-2022-48694
05/03/20244.84.6Linux Kernel slab.h nft_chain_release_hook memory leakOperating SystemNot DefinedOfficial Fix0.000450.00CVE-2022-48691
05/03/20245.75.5Linux Kernel kmemdup null pointer dereferenceOperating SystemNot DefinedOfficial Fix0.000430.00CVE-2022-48703
05/03/20243.53.4Linux Kernel Audio Device __snd_usb_parse_audio_interface out-of-boundsOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2022-48701
05/03/20245.75.5Linux Kernel debugfs_lookup memory leakOperating SystemNot DefinedOfficial Fix0.000450.00CVE-2022-48699
05/03/20245.75.5Linux Kernel AMD Display debugfs_lookup memory leakOperating SystemNot DefinedOfficial Fix0.000450.00CVE-2022-48698
05/03/20244.64.4Linux Kernel ALSA snd_emu10k1_pcm_channel_alloc array indexOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2022-48702
05/03/20245.75.5Linux Kernel pin_user_pages_remote infinite loopOperating SystemNot DefinedOfficial Fix0.000450.00CVE-2022-48700
05/03/20247.16.8Linux Kernel nvmet use after freeOperating SystemNot DefinedOfficial Fix0.000440.07CVE-2022-48697
05/03/20245.55.3Linux Kernel regmap_get_spi_bus memory corruptionOperating SystemNot DefinedOfficial Fix0.000430.00CVE-2022-48696
05/03/20245.55.3Linux Kernel mmput_async memory corruptionOperating SystemNot DefinedOfficial Fix0.000450.00CVE-2022-48675
05/03/20245.35.1Linux Kernel i40e_client_subtask null pointer dereferenceOperating SystemNot DefinedOfficial Fix0.000440.04CVE-2022-48688
05/03/20248.07.6Linux Kernel nvme-tcp use after freeOperating SystemNot DefinedOfficial Fix0.000450.00CVE-2022-48686
05/03/20248.07.6Linux Kernel smc use after freeOperating SystemNot DefinedOfficial Fix0.000430.08CVE-2022-48673
05/03/20245.55.3Linux Kernel unflatten_dt_nodes off-by-oneOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2022-48672
05/03/20245.75.5Linux Kernel cgroup cgroup_attach_task_all deadlockOperating SystemNot DefinedOfficial Fix0.000440.04CVE-2022-48671
05/03/20245.35.1Linux Kernel HMAC Data seg6.c out-of-boundsOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2022-48687
05/03/20247.16.8Linux Kernel erofs erofs_workgroup_unfreeze use after freeOperating SystemNot DefinedOfficial Fix0.000450.04CVE-2022-48674
05/03/20245.55.3Linux Kernel tcp page_is_pfmemalloc buffer overflowOperating SystemNot DefinedOfficial Fix0.000450.04CVE-2022-48689
05/03/20247.67.3Linux Kernel peci refcount.c adev_release use after freeOperating SystemNot DefinedOfficial Fix0.000430.03CVE-2022-48670
05/01/20244.34.1Linux Kernel wifi allocation of resourcesOperating SystemNot DefinedOfficial Fix0.000430.04CVE-2024-27056
05/01/20245.75.5Linux Kernel ASoC sof_ipc4_pcm_hw_free denial of serviceOperating SystemNot DefinedOfficial Fix0.000450.03CVE-2024-27057
05/01/20244.84.6Linux Kernel cpumask_test_cpu denial of serviceOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2024-27055
05/01/20245.55.3Linux Kernel s390 Privilege EscalationOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2024-27054
05/01/20245.75.5Linux Kernel brcmstb-avs-cpufreq cpufreq_cpu_get's null pointer dereferenceOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2024-27051
05/01/20245.75.5Linux Kernel brcm80211 kzalloc null pointer dereferenceOperating SystemNot DefinedOfficial Fix0.000450.00CVE-2024-27048
05/01/20245.75.5Linux Kernel flower kmalloc_array null pointer dereferenceOperating SystemNot DefinedOfficial Fix0.000440.06CVE-2024-27046
05/01/20248.07.6Linux Kernel rtl8xxxu c2hcmd_work use after freeOperating SystemNot DefinedOfficial Fix0.000440.05CVE-2024-27052
05/01/20243.53.4Linux Kernel libbpf OPTS_SET out-of-boundsOperating SystemNot DefinedOfficial Fix0.000450.00CVE-2024-27050
05/01/20245.75.5Linux Kernel phy phy_get_internal_delay null pointer dereferenceOperating SystemNot DefinedOfficial Fix0.000440.00CVE-2024-27047

4507 more entries are not shown

Do you need the next level of professionalism?

Upgrade your account now!