VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,255)

  • CVE-2022-49178HigFeb 26, 2025
    affected >= 2.6.25, < 5.16.19fixed 5.16.19

    In the Linux kernel, the following vulnerability has been resolved: memstick/mspro_block: fix handling of read-only devices Use set_disk_ro to propagate the read-only state to the block layer instead of checking for it in ->open and leaking a reference in case of a read-only de

  • CVE-2022-49177MedFeb 26, 2025
    affected >= 5.17.0, < 5.17.2fixed 5.17.2

    In the Linux kernel, the following vulnerability has been resolved: hwrng: cavium - fix NULL but dereferenced coccicheck error Fix following coccicheck warning: ./drivers/char/hw_random/cavium-rng-vf.c:182:17-20: ERROR: pdev is NULL but dereferenced.

  • CVE-2022-49176HigFeb 26, 2025
    affected >= 4.15.0, < 4.19.238fixed 4.19.238

    In the Linux kernel, the following vulnerability has been resolved: bfq: fix use-after-free in bfq_dispatch_request KASAN reports a use-after-free report when doing normal scsi-mq test [69832.239032] ================================================================== [69832.241

  • CVE-2022-49175MedFeb 26, 2025
    affected >= 4.5.0, < 4.9.311fixed 4.9.311

    In the Linux kernel, the following vulnerability has been resolved: PM: core: keep irq flags in device_pm_check_callbacks() The function device_pm_check_callbacks() can be called under the spin lock (in the reported case it happens from genpd_add_device() -> dev_pm_domain_set()

  • CVE-2022-49174HigFeb 26, 2025
    affected >= 5.10.0, < 5.10.110fixed 5.10.110

    In the Linux kernel, the following vulnerability has been resolved: ext4: fix ext4_mb_mark_bb() with flex_bg with fast_commit In case of flex_bg feature (which is by default enabled), extents for any given inode might span across blocks from two different block group. ext4_mb_m

  • CVE-2022-49173MedFeb 26, 2025
    affected >= 5.7.0, < 5.16.19fixed 5.16.19

    In the Linux kernel, the following vulnerability has been resolved: spi: fsi: Implement a timeout for polling status The data transfer routines must poll the status register to determine when more data can be shifted in or out. If the hardware gets into a bad state, these polli

  • CVE-2022-49172HigFeb 26, 2025
    affected >= 2.6.12, < 5.16.19fixed 5.16.19

    In the Linux kernel, the following vulnerability has been resolved: parisc: Fix non-access data TLB cache flush faults When a page is not present, we get non-access data TLB faults from the fdc and fic instructions in flush_user_dcache_range_asm and flush_user_icache_range_asm.

  • CVE-2022-49171MedFeb 26, 2025
    affected >= 2.6.37, < 4.9.311fixed 4.9.311

    In the Linux kernel, the following vulnerability has been resolved: ext4: don't BUG if someone dirty pages without asking ext4 first [un]pin_user_pages_remote is dirtying pages without properly warning the file system in advance. A related race was noted by Jan Kara in 2018[1]

  • CVE-2022-49170HigFeb 26, 2025
    affected >= 3.8.0, < 5.10.110fixed 5.10.110

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on curseg->alloc_type As Wenqing Liu reported in bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=215657 - Overview UBSAN: array-index-out-of-bounds in fs/f2fs/segment.c:3460

  • CVE-2022-49169MedFeb 26, 2025
    affected >= 3.8.0, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: f2fs: use spin_lock to avoid hang [14696.634553] task:cat state:D stack: 0 pid:1613738 ppid:1613735 flags:0x00000004 [14696.638285] Call Trace: [14696.639038] [14696.640032] __schedule+0

  • CVE-2022-49168HigFeb 26, 2025
    affected >= 3.18.0, < 5.10.248fixed 5.10.248

    In the Linux kernel, the following vulnerability has been resolved: btrfs: do not clean up repair bio if submit fails The submit helper will always run bio_endio() on the bio if it fails to submit, so cleaning up the bio just leads to a variety of use-after-free and NULL pointe

  • CVE-2022-49167HigFeb 26, 2025
    affected >= 5.16.0, < 5.16.19fixed 5.16.19

    In the Linux kernel, the following vulnerability has been resolved: btrfs: do not double complete bio on errors during compressed reads I hit some weird panics while fixing up the error handling from btrfs_lookup_bio_sums(). Turns out the compression path will complete the bio

  • CVE-2022-49166MedFeb 26, 2025
    affected >= 2.6.12, < 4.9.311fixed 4.9.311

    In the Linux kernel, the following vulnerability has been resolved: ntfs: add sanity check on allocation size ntfs_read_inode_mount invokes ntfs_malloc_nofs with zero allocation size. It triggers one BUG in the __ntfs_malloc function. Fix this by adding sanity check on ni->at

  • CVE-2022-49165MedFeb 26, 2025
    affected >= 5.13.0, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Prevent decoding NV12M jpegs into single-planar buffers If the application queues an NV12M jpeg as output buffer, but then queues a single planar capture buffer, the kernel will crash with "Una

  • CVE-2022-49164MedFeb 26, 2025
    affected >= 3.9.0, < 5.15.54fixed 5.15.54

    In the Linux kernel, the following vulnerability has been resolved: powerpc/tm: Fix more userspace r13 corruption Commit cf13435b730a ("powerpc/tm: Fix userspace r13 corruption") fixes a problem in treclaim where a SLB miss can occur on the thread_struct->ckpt_regs while SCRATC

  • CVE-2022-49163HigFeb 26, 2025
    affected >= 5.13.0, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: fix a bug of accessing array out of bounds When error occurs in parsing jpeg, the slot isn't acquired yet, it may be the default value MXC_MAX_SLOTS. If the driver access the slot using the inc

  • CVE-2022-49162HigFeb 26, 2025
    affected >= 2.6.33, < 4.9.311fixed 4.9.311

    In the Linux kernel, the following vulnerability has been resolved: video: fbdev: sm712fb: Fix crash in smtcfb_write() When the sm712fb driver writes three bytes to the framebuffer, the driver will crash: BUG: unable to handle page fault for address: ffffc90001ffffff R

  • CVE-2022-49161MedFeb 26, 2025
    affected >= 5.2.0, < 5.17.2fixed 5.17.2

    In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: Fix error handling in mt8183_da7219_max98357_dev_probe The device_node pointer is returned by of_parse_phandle() with refcount incremented. We should use of_node_put() on it when done. This fu

  • CVE-2022-49160HigFeb 26, 2025
    affected >= 5.9.0, < 5.15.54fixed 5.15.54

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash during module load unload test During purex packet handling the driver was incorrectly freeing a pre-allocated structure. Fix this by skipping that entry. System crashed with the follo

  • CVE-2022-49159HigFeb 26, 2025
    affected >= 2.6.32, < 5.15.33fixed 5.15.33

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Implement ref count for SRB The timeout handler and the done function are racing. When qla2x00_async_iocb_timeout() starts to run it can be preempted by the normal response path (via the firmware

Page 516 of 713