Grsecurity Kernel Patch

Vendor:

First CVE: Dec 31, 2002 · Active for 23 years

5
Total CVEs
More Total CVEs than 77% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Grsecurity Kernel Patch over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Apr 25, 2008
6,664 days ago

CVE Severity & Scoring

Grsecurity Kernel Patch5 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local1 (20.0%)
Network0 (0.0%)
Unknown4 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (20.0%)
High0 (0.0%)
Unknown4 (80.0%)
User Interaction
None1 (20.0%)
Unknown4 (80.0%)
Required0 (0.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None0 (0.0%)
Unknown4 (80.0%)

Top CVEs

Signals from CVEs in this product scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed
Jan 16, 20077.828NOYES
grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory.
Dec 31, 20024.621NOYES
The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the
Jan 17, 20067.220NONO
Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital A
Jan 16, 20077.218NONO
The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (
Apr 25, 20084.614NONO

Exploit Exposure

Signals from CVEs in this product scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
40.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (5 CVEs).

Media Mentions

Signals from CVEs in this product scope (5 CVEs).

Top CNAs Publishing CVEs For Grsecurity Kernel Patch

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.6.24.414.60.3%00
2.6.1814.60.3%00
2.4.3414.60.3%00
2.4.33.414.60.3%00
2.4.33.314.60.3%00
2.4.33.214.60.3%00
2.4.3314.60.3%00
2.1.817.81.0%01
2.1.727.50.7%01
2.1.627.50.7%01
2.1.527.50.7%01
2.1.427.50.7%01
2.1.327.50.7%01
2.1.227.50.7%01
2.1.127.50.7%01
2.1.027.50.7%01
2.0.227.50.7%01
2.0.127.50.7%01
1.9.426.21.0%02