Linux Enterprise Real Time Extension

Vendor:

First CVE: Dec 4, 2007 · Active for 18 years

58
Total CVEs
More Total CVEs than 99% of tracked products
8.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
4.7
Avg CVSS
Higher Avg CVSS than 7% of tracked products
3.4%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Linux Enterprise Real Time Extension over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 4, 2007
18 years ago
Most Recent CVE
Jan 3, 2018
3,128 days ago

CVE Severity & Scoring

Linux Enterprise Real Time Extension58 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local8 (13.8%)
Network4 (6.9%)
Unknown45 (77.6%)
Physical1 (1.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (22.4%)
High0 (0.0%)
Unknown45 (77.6%)
User Interaction
None13 (22.4%)
Unknown45 (77.6%)
Required0 (0.0%)
Privileges Required
Low6 (10.3%)
High1 (1.7%)
None6 (10.3%)
Unknown45 (77.6%)

Top CVEs

Signals from CVEs in this product scope (58 CVEs).

58 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain priv
Jun 7, 20147.890YESYES
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addres
Dec 6, 20107.884YESYES
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-a
Jan 3, 20189.860NONO
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register a
Sep 22, 20107.236NOYES
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACP
Dec 22, 20106.934NOYES
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information
Oct 4, 20106.634NOYES
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok r
Dec 30, 20106.233NOYES
Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users t
Dec 30, 20106.933NOYES
The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a d
Nov 22, 20104.929NOYES
Multiple integer underflows in the x25_parse_facilities function in net/x25/x25_facilities.c in the Linux kernel before 2.6.36.2 allow remote attackers to cause a denial of service
Jan 3, 20117.827NONO

Exploit Exposure

Signals from CVEs in this product scope (58 CVEs).

CISA KEV
2 CVEs
3.4% of CVEs· 98th percentile
Metasploit
2 CVEs
3.4% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
22.4% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (58 CVEs).

Media Mentions

Signals from CVEs in this product scope (58 CVEs).

Top CNAs Publishing CVEs For Linux Enterprise Real Time Extension

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1267.416.3%01
11.014.31.2%00
11544.73.5%213
1012.10.4%00