299,878
Total vulnerabilities in the database
The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 3.13 | 3.16.40 |
| linux / linux_kernel | 3.11 | 3.12.70 |
| linux / linux_kernel | 3.17 | 3.18.47 |
| linux / linux_kernel | 3.19 | 4.1.38 |
| linux / linux_kernel | - | 3.10.107 |
| linux / linux_kernel | 4.2 | 4.4.41 |
| linux / linux_kernel | 4.5 | 4.8.17 |
| linux / linux_kernel | 4.9 | 4.9.2 |