[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht nähere beschriebene Effekte zu verursachen.
CSIRTS triage
- What
- Multiple vulnerabilities allow Denial of Service attacks.
- Who is affected
- Deployments of the Linux Kernel.
- Urgency
- Remediation is urgent due to the high severity of potential Denial of Service attacks.
- Action
- Apply the latest patches for the Linux Kernel.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Kernel
Get an email when a new Kernel advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2092
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2022-503750.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-503760.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-503780.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-503790.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-503800.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-503810.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-503820.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-503830.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2022-503840.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUbuntu Linux Kernel Multiple Vulnerabilitieshkcert
- unknownUSN-8725-1: Linux kernel vulnerabilitiesubuntu
- mediumCVE-2023-53376: scsi: mpi3mr: Use number of bits to manage bitmap sizesmsrc
- mediumCVE-2022-50407: crypto: hisilicon/qm - increase the memory of local variablesmsrc
- mediumCVE-2022-50393: drm/amdgpu: SDMA update use unlocked iteratormsrc
Recent advisories for Linux Kernel
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownUSN-8748-1: Linux kernel (NVIDIA) vulnerabilitiesubuntu · 2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Privilegieneskalationcert-bund · 2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriffcert-bund · 2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Servicecert-bund · 2026-09-10
- mediumexploited[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-10
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] vim: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] ffmpeg: Mehrere Schwachstellen ermöglichen Codeausführung und DoS2026-09-10
- high[UPDATE] [hoch] ffmpeg: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Unbound: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] Internet Systems Consortium BIND: Mehrere Schwachstellen2026-09-10