296,854
Total vulnerabilities in the database
In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev name containing a / character. This is similar to CVE-2013-4343.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 4.13.14 |