VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,255)

  • CVE-2022-49259MedFeb 26, 2025
    affected >= 4.16.0, < 4.19.238fixed 4.19.238

    In the Linux kernel, the following vulnerability has been resolved: block: don't delete queue kobject before its children kobjects aren't supposed to be deleted before their child kobjects are deleted. Apparently this is usually benign; however, a WARN will be triggered if one

  • CVE-2022-49258HigFeb 26, 2025
    affected >= 4.17.0, < 5.10.110fixed 5.10.110

    In the Linux kernel, the following vulnerability has been resolved: crypto: ccree - Fix use after free in cc_cipher_exit() kfree_sensitive(ctx_p->user.key) will free the ctx_p->user.key. But ctx_p->user.key is still used in the next line, which will lead to a use after free. W

  • CVE-2022-49257MedFeb 26, 2025
    affected >= 5.8.0, < 5.10.110fixed 5.10.110

    In the Linux kernel, the following vulnerability has been resolved: watch_queue: Fix NULL dereference in error cleanup In watch_queue_set_size(), the error cleanup code doesn't take account of the fact that __free_page() can't handle a NULL pointer when trying to free up buffer

  • CVE-2022-49256MedFeb 26, 2025
    affected >= 5.8.0, < 5.10.110fixed 5.10.110

    In the Linux kernel, the following vulnerability has been resolved: watch_queue: Actually free the watch free_watch() does everything barring actually freeing the watch object. Fix this by adding the missing kfree. kmemleak produces a report something like the following. Not

  • CVE-2022-49255MedFeb 26, 2025
    affected >= 4.19.0, < 5.4.189fixed 5.4.189

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix missing free nid in f2fs_handle_failed_inode This patch fixes xfstests/generic/475 failure. [ 293.680694] F2FS-fs (dm-1): May loss orphan inode, run fsck to fix. [ 293.685358] Buffer I/O error on d

  • CVE-2022-49254MedFeb 26, 2025
    affected >= 5.12.0, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: media: ti-vpe: cal: Fix a NULL pointer dereference in cal_ctx_v4l2_init_formats() In cal_ctx_v4l2_init_formats(), devm_kzalloc() is assigned to ctx->active_fmt and there is a dereference of it after that, which

  • CVE-2022-49253MedFeb 26, 2025
    affected >= 3.10.0, < 4.9.311fixed 4.9.311

    In the Linux kernel, the following vulnerability has been resolved: media: usb: go7007: s2250-board: fix leak in probe() Call i2c_unregister_device(audio) on this error path.

  • CVE-2022-49252HigFeb 26, 2025
    affected >= 5.12.0, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type Accessing enums using integer would result in array out of bounds access on platforms like aarch64 where sizeof(long) is 8 compared to enu

  • CVE-2022-49251HigFeb 26, 2025
    affected >= 5.11.0, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: va-macro: fix accessing array out of bounds for enum type Accessing enums using integer would result in array out of bounds access on platforms like aarch64 where sizeof(long) is 8 compared to enu

  • CVE-2022-49250HigFeb 26, 2025
    affected >= 5.12.0, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: rx-macro: fix accessing compander for aux AUX interpolator does not have compander, so check before accessing compander data for this. Without this checkan array of out bounds access will be made

  • CVE-2022-49249HigFeb 26, 2025
    affected >= 5.14.0, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wc938x: fix accessing array out of bounds for enum type Accessing enums using integer would result in array out of bounds access on platforms like aarch64 where sizeof(long) is 8 compared to enum

  • CVE-2022-49248MedFeb 26, 2025
    affected >= 3.16.0, < 4.9.311fixed 4.9.311

    In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-lib: fix uninitialized flag for AV/C deferred transaction AV/C deferred transaction was supported at a commit 00a7bb81c20f ("ALSA: firewire-lib: Add support for deferred transaction") while 'defe

  • CVE-2022-49247MedFeb 26, 2025
    affected >= 3.7.0, < 4.14.276fixed 4.14.276

    In the Linux kernel, the following vulnerability has been resolved: media: stk1160: If start stream fails, return buffers with VB2_BUF_STATE_QUEUED If the callback 'start_streaming' fails, then all queued buffers in the driver should be returned with state 'VB2_BUF_STATE_QUEUED

  • CVE-2022-49246MedFeb 26, 2025
    affected >= 4.20.0, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: ASoC: atmel: Fix error handling in snd_proto_probe The device_node pointer is returned by of_parse_phandle() with refcount incremented. We should use of_node_put() on it when done. This function only calls of

  • CVE-2022-49245MedFeb 26, 2025
    affected >= 5.16.0, < 5.16.19fixed 5.16.19

    In the Linux kernel, the following vulnerability has been resolved: ASoC: rockchip: Fix PM usage reference of rockchip_i2s_tdm_resume pm_runtime_get_sync will increment pm usage counter even it failed. Forgetting to putting operation will result in reference leak here. We fix i

  • CVE-2022-49244MedFeb 26, 2025
    affected < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8192-mt6359: Fix error handling in mt8192_mt6359_dev_probe The device_node pointer is returned by of_parse_phandle() with refcount incremented. We should use of_node_put() on it when done. T

  • CVE-2022-49243MedFeb 26, 2025
    affected >= 3.8.0, < 4.9.311fixed 4.9.311

    In the Linux kernel, the following vulnerability has been resolved: ASoC: atmel: Add missing of_node_put() in at91sam9g20ek_audio_probe This node pointer is returned by of_parse_phandle() with refcount incremented in this function. Calling of_node_put() to avoid the refcount le

  • CVE-2022-49242MedFeb 26, 2025
    affected >= 3.5.0, < 4.9.311fixed 4.9.311

    In the Linux kernel, the following vulnerability has been resolved: ASoC: mxs: Fix error handling in mxs_sgtl5000_probe This function only calls of_node_put() in the regular path. And it will cause refcount leak in error paths. For example, when codec_np is NULL, saif_np[0] and

  • CVE-2022-49241MedFeb 26, 2025
    affected >= 3.12.0, < 5.10.110fixed 5.10.110

    In the Linux kernel, the following vulnerability has been resolved: ASoC: atmel: Fix error handling in sam9x5_wm8731_driver_probe The device_node pointer is returned by of_parse_phandle() with refcount incremented. We should use of_node_put() on it when done. This function on

  • CVE-2022-49240MedFeb 26, 2025
    affected >= 5.17.0, < 5.17.2fixed 5.17.2

    In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Fix error handling in mt8195_mt6359_rt1019_rt5682_dev_probe The device_node pointer is returned by of_parse_phandle() with refcount incremented. We should use of_node_put() on it when d

Page 512 of 713