DE EN FR
hlukh.ch Stand: 2026-02-25T21:01:10.471Z · week: 2022-W10

Sicherheitswarnungen

Kuratiert aus öffentlich verfügbaren Advisories. Fokus: Sichtbarkeit, Einordnung und schneller Export – ohne Clickbait.

Neueste Warnungen
CVE-2021-3609
.A flaw was found in the CAN BCM networking protocol in the Linux kernel where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
2026‑02‑21 · CVE-2021-3609
MSRC 2026‑02‑21 Hoch
CVE-2022-24464
.NET and Visual Studio Denial of Service Vulnerability
2026‑02‑21 · CVE-2022-24464
MSRC 2026‑02‑21 Hoch
CVE-2022-24512
.NET and Visual Studio Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-24512
MSRC 2026‑02‑21 Mittel
CVE-2021-20321
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-20321
MSRC 2026‑02‑21 Mittel
CVE-2021-20320
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-20320
MSRC 2026‑02‑21 Mittel
CVE-2021-3607
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-3607
MSRC 2026‑02‑21 Mittel
CVE-2021-3608
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-3608
MSRC 2026‑02‑21 Mittel
CVE-2021-4190
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-4190
MSRC 2026‑02‑21 Hoch
CVE-2021-3700
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-3700
MSRC 2026‑02‑21 Mittel
CVE-2021-44531
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-44531
MSRC 2026‑02‑21 Hoch
CVE-2022-0563
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2022-0563
MSRC 2026‑02‑21 Mittel
CVE-2022-0696
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2022-0696
MSRC 2026‑02‑21 Mittel
CVE-2022-0617
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2022-0617
MSRC 2026‑02‑21 Mittel
CVE-2021-44533
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-44533
MSRC 2026‑02‑21 Mittel
CVE-2021-44532
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-44532
MSRC 2026‑02‑21 Mittel
CVE-2022-21824
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2022-21824
MSRC 2026‑02‑21 Hoch
CVE-2022-0729
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2022-0729
MSRC 2026‑02‑21 Hoch
CVE-2022-0714
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2022-0714
MSRC 2026‑02‑21 Mittel
CVE-2022-24407
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2022-24407
MSRC 2026‑02‑21 Hoch
CVE-2022-23308
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2022-23308
MSRC 2026‑02‑21 Hoch
CVE-2021-43666
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
2026‑02‑21 · CVE-2021-43666
MSRC 2026‑02‑21 Hoch
CVE-2021-3981
A flaw in grub2 was found where its configuration file known as grub.cfg is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.
2026‑02‑21 · CVE-2021-3981
MSRC 2026‑02‑21 Niedrig
CVE-2021-3640
A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.
2026‑02‑21 · CVE-2021-3640
MSRC 2026‑02‑21 Hoch
CVE-2021-3620
A flaw was found in Ansible Engine's ansible-connection module where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
2026‑02‑21 · CVE-2021-3620
MSRC 2026‑02‑21 Mittel
CVE-2021-3698
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
2026‑02‑21 · CVE-2021-3698
MSRC 2026‑02‑21 Hoch
CVE-2022-0811
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
2026‑02‑21 · CVE-2022-0811
MSRC 2026‑02‑21 Hoch
CVE-2021-3631
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
2026‑02‑21 · CVE-2021-3631
MSRC 2026‑02‑21 Mittel
CVE-2021-3716
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.
2026‑02‑21 · CVE-2021-3716
MSRC 2026‑02‑21 Niedrig
CVE-2021-3677
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 the known versions of this attack are infeasible. However undiscovered variants of the attack may be independent of that setting.
2026‑02‑21 · CVE-2021-3677
MSRC 2026‑02‑21 Mittel
CVE-2021-3737
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker who controls the HTTP server to make the client script enter an infinite loop consuming CPU time. The highest threat from this vulnerability is to system availability.
2026‑02‑21 · CVE-2021-3737
MSRC 2026‑02‑21 Hoch
CVE-2021-4023
A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allows a local user with permissions to execute io-uring requests to possibly crash the system.
2026‑02‑21 · CVE-2021-4023
MSRC 2026‑02‑21 Mittel
CVE-2021-3656
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result the L2 guest would be allowed to read/write physical pages of the host resulting in a crash of the entire system leak of sensitive data or potential guest-to-host escape.
2026‑02‑21 · CVE-2021-3656
MSRC 2026‑02‑21 Hoch
CVE-2021-3732
A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.
2026‑02‑21 · CVE-2021-3732
MSRC 2026‑02‑21 Mittel
CVE-2020-35501
A flaw was found in the Linux kernels implementation of audit rules where a syscall can unexpectedly not be correctly not be logged by the audit subsystem
2026‑02‑21 · CVE-2020-35501
MSRC 2026‑02‑21 Niedrig
CVE-2021-3772
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.
2026‑02‑21 · CVE-2021-3772
MSRC 2026‑02‑21 Mittel
CVE-2022-1050
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated potentially leading to a use-after-free condition.
2026‑02‑21 · CVE-2022-1050
MSRC 2026‑02‑21 Hoch
CVE-2022-0322
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw an attempt to use more buffer than is allocated triggers a BUG_ON issue leading to a denial of service (DOS).
2026‑02‑21 · CVE-2022-0322
MSRC 2026‑02‑21 Mittel
CVE-2022-0711
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
2026‑02‑21 · CVE-2022-0711
MSRC 2026‑02‑21 Hoch
CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
2026‑02‑21 · CVE-2022-0847
MSRC 2026‑02‑21 Hoch
CVE-2022-0500
A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.
2026‑02‑21 · CVE-2022-0500
MSRC 2026‑02‑21 Hoch
CVE-2022-27666
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
2026‑02‑21 · CVE-2022-27666
MSRC 2026‑02‑21 Hoch
CVE-2022-0891
A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash potential information disclosure or any other context-dependent impact
2026‑02‑21 · CVE-2022-0891
MSRC 2026‑02‑21 Hoch
CVE-2022-0494
A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO) to create issues with confidentiality.
2026‑02‑21 · CVE-2022-0494
MSRC 2026‑02‑21 Mittel
CVE-2021-23222
A man-in-the-middle attacker can inject false responses to the client's first few queries despite the use of SSL certificate verification and encryption.
2026‑02‑21 · CVE-2021-23222
MSRC 2026‑02‑21 Mittel
CVE-2021-4002
A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.
2026‑02‑21 · CVE-2021-4002
MSRC 2026‑02‑21 Mittel
CVE-2021-3744
A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.
2026‑02‑21 · CVE-2021-3744
MSRC 2026‑02‑21 Mittel
CVE-2022-0854
A memory leak flaw was found in the Linux kernel’s DMA subsystem in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.
2026‑02‑21 · CVE-2022-0854
MSRC 2026‑02‑21 Mittel
CVE-2021-3739
A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest threat from this vulnerability is to system availability.
2026‑02‑21 · CVE-2021-3739
MSRC 2026‑02‑21 Hoch
CVE-2022-0433
A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prior to 5.17-rc1.
2026‑02‑21 · CVE-2022-0433
MSRC 2026‑02‑21 Mittel
CVE-2021-4095
A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a denial of service by issuing a KVM_XEN_HVM_SET_ATTR ioctl. This flaw affects Linux kernel versions prior to 5.17-rc1.
2026‑02‑21 · CVE-2021-4095
MSRC 2026‑02‑21 Mittel
Seite 1