298,930
Total vulnerabilities in the database
The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 3.5.2 | 3.5.2.x |
| linux / linux_kernel | - | 3.5.6.x |
| linux / linux_kernel | 3.5.5 | 3.5.5.x |
| linux / linux_kernel | 3.5.3 | 3.5.3.x |
| linux / linux_kernel | 3.5.4 | 3.5.4.x |
| linux / linux_kernel | 3.5.1 | 3.5.1.x |