More than six years after the Spectre security flaw impacting modern CPU processors came to light, new research has found that the latest AMD and Intel processors are still susceptible to speculative execution attacks.
The attack, disclosed by ETH Zürich researchers Johannes Wikner and Kaveh Razavi, aims to undermine the Indirect Branch Predictor Barrier (IBPB) on x86 chips, a crucial mitigation
A vulnerability was found in Linux Kernel up to 5.19.10. It has been declared as problematic. Affected by this vulnerability is the function unflatten_dt_nodes. The manipulation leads to off-by-one.
This vulnerability is known as CVE-2022-48672. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.9-rc1. This issue affects the function scsi_proc_hostdir_rm of the file /proc/scsi/${proc_name}. The manipulation leads to allocation of resources.
The identification of this vulnerability is CVE-2024-26935. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Linux Kernel up to 6.8.1. Affected by this vulnerability is an unknown functionality of the component nf_tables. The manipulation leads to incorrect comparison.
This vulnerability is known as CVE-2024-27065. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.6.2. This affects an unknown part. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2023-52836. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.13.3 and classified as problematic. This issue affects the function ibmasm_init_remote_input_dev. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2021-47334. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.12.12. It has been rated as critical. This issue affects the function mlx5e_rep_neigh_update. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2021-47247. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.8.9. It has been classified as problematic. Affected is the function bad_inode. The manipulation leads to uninitialized pointer.
This vulnerability is traded as CVE-2024-36923. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.6.30/6.8.9. Affected is the function __ip_make_skb of the component ipv4. The manipulation leads to uninitialized resource.
This vulnerability is traded as CVE-2024-36927. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 5.10.98/5.15.21/5.16.7. This vulnerability affects the function pt_buffer_region_size. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2022-48713. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 5.10.95/5.15.18/5.16.4. Affected by this vulnerability is the function test_bpf of the component powerpc64. The manipulation leads to denial of service.
This vulnerability is known as CVE-2022-48755. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.4.175/5.10.95/5.15.18/5.16.4. This issue affects the function kstrdup of the component histogram. The manipulation leads to memory leak.
The identification of this vulnerability is CVE-2022-48768. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.10.95/5.15.18/5.16.4. Affected is the function bpf_get_task_stack. The manipulation leads to unchecked return value.
This vulnerability is traded as CVE-2022-48770. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.32/6.9.3. This affects the function vfio_intx_enable. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2024-38632. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Sun One Application Server 7.0 on Windows. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure (Password).
This vulnerability is handled as CVE-2003-0414. Local access is required to approach this attack. There is no exploit available.