VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,255)

  • CVE-2024-56685MedDec 28, 2024
    affected >= 6.8.0, < 6.11.11fixed 6.11.11

    In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: Check num_codecs is not zero to avoid panic during probe Following commit 13f58267cda3 ("ASoC: soc.h: don't create dummy Component via COMP_DUMMY()"), COMP_DUMMY() became an array with zero leng

  • CVE-2024-56684HigDec 28, 2024
    affected >= 6.11.0, < 6.11.11fixed 6.11.11

    In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: fix wrong use of sizeof in cmdq_get_clocks() It should be size of the struct clk_bulk_data, not data pointer pass to devm_kcalloc().

  • CVE-2024-56683MedDec 28, 2024
    affected >= 6.0.0, < 6.1.120fixed 6.1.120

    In the Linux kernel, the following vulnerability has been resolved: drm/vc4: hdmi: Avoid hang with debug registers when suspended Trying to read /sys/kernel/debug/dri/1/hdmi1_regs when the hdmi is disconnected results in a fatal system hang. This is due to the pm suspend code

  • CVE-2024-56682MedDec 28, 2024
    affected >= 6.10.0, < 6.12.2fixed 6.12.2

    In the Linux kernel, the following vulnerability has been resolved: irqchip/riscv-aplic: Prevent crash when MSI domain is missing If the APLIC driver is probed before the IMSIC driver, the parent MSI domain will be missing, which causes a NULL pointer dereference in msi_create_

  • CVE-2024-56681HigDec 28, 2024
    affected >= 4.11.0, < 4.19.325fixed 4.19.325

    In the Linux kernel, the following vulnerability has been resolved: crypto: bcm - add error check in the ahash_hmac_init function The ahash_init functions may return fails. The ahash_hmac_init should not return ok when ahash_init returns error. For an example, ahash_init will r

  • CVE-2024-56680MedDec 28, 2024
    affected >= 6.10.0, < 6.11.11fixed 6.11.11

    In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: do not handle interrupts when device is disabled Some IPU6 devices have shared interrupts. We need to handle properly case when interrupt is triggered from other device on shared irq line and

  • CVE-2024-56679MedDec 28, 2024
    affected >= 5.12.0, < 5.15.174fixed 5.15.174

    In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_common.c Add error pointer check after calling otx2_mbox_get_rsp().

  • CVE-2024-56678HigDec 28, 2024
    affected >= 5.13.0, < 5.15.174fixed 5.15.174

    In the Linux kernel, the following vulnerability has been resolved: powerpc/mm/fault: Fix kfence page fault reporting copy_from_kernel_nofault() can be called when doing read of /proc/kcore. /proc/kcore can have some unmapped kfence objects which when read via copy_from_kernel_

  • CVE-2024-56677HigDec 28, 2024
    affected >= 5.19.0, < 6.1.120fixed 6.1.120

    In the Linux kernel, the following vulnerability has been resolved: powerpc/fadump: Move fadump_cma_init to setup_arch() after initmem_init() During early init CMA_MIN_ALIGNMENT_BYTES can be PAGE_SIZE, since pageblock_order is still zero and it gets initialized later during ini

  • CVE-2024-56676MedDec 28, 2024
    affected >= 6.12.0, < 6.12.2fixed 6.12.2

    In the Linux kernel, the following vulnerability has been resolved: thermal: testing: Initialize some variables annoteded with _free() Variables annotated with __free() need to be initialized if the function can return before they get updated for the first time or the attempt t

  • CVE-2024-56675HigDec 27, 2024
    affected >= 6.0.0, < 6.1.121fixed 6.1.121

    In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors Uprobes always use bpf_prog_run_array_uprobe() under tasks-trace-RCU protection. But it is possible to attach a non-sleepable BPF program to a uprobe

  • CVE-2024-56674MedDec 27, 2024
    affected >= 6.11.0, < 6.12.6fixed 6.12.6

    In the Linux kernel, the following vulnerability has been resolved: virtio_net: correct netdev_tx_reset_queue() invocation point When virtnet_close is followed by virtnet_open, some TX completions can possibly remain unconsumed, until they are finally processed during the first

  • CVE-2024-56673MedDec 27, 2024
    affected >= 6.11.0, < 6.12.6fixed 6.12.6

    In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Do not call pmd dtor on vmemmap page table teardown The vmemmap's, which is used for RV64 with SPARSEMEM_VMEMMAP, page tables are populated using pmd (page middle directory) hugetables. However, the

  • CVE-2024-56672HigDec 27, 2024
    affected >= 5.7.0, < 5.10.234fixed 5.10.234

    In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Fix UAF in blkcg_unpin_online() blkcg_unpin_online() walks up the blkcg hierarchy putting the online pin. To walk up, it uses blkcg_parent(blkcg) but it was calling that after blkcg_destroy_blkgs(bl

  • CVE-2024-56671MedDec 27, 2024
    affected >= 6.10.0, < 6.12.6fixed 6.12.6

    In the Linux kernel, the following vulnerability has been resolved: gpio: graniterapids: Fix vGPIO driver crash Move setting irq_chip.name from probe() function to the initialization of "irq_chip" struct in order to fix vGPIO driver crash during bootup. Crash was caused by una

  • CVE-2024-56670MedDec 27, 2024
    affected >= 2.6.27, < 5.4.288fixed 5.4.288

    In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer Considering that in some extreme cases, when u_serial driver is accessed by multiple threads, Thread A is executing th

  • CVE-2024-56669HigDec 27, 2024
    affected >= 6.10.0, < 6.12.6fixed 6.12.6

    In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Remove cache tags before disabling ATS The current implementation removes cache tags after disabling ATS, leading to potential memory leaks and kernel crashes. Specifically, CACHE_TAG_DEVTLB type ca

  • CVE-2024-56668MedDec 27, 2024
    affected >= 6.12.0, < 6.12.6fixed 6.12.6

    In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix qi_batch NULL pointer with nested parent domain The qi_batch is allocated when assigning cache tag for a domain. While for nested parent domain, it is missed. Hence, when trying to map pages to

  • CVE-2024-56667MedDec 27, 2024
    affected >= 6.3.0, < 6.6.67fixed 6.6.67

    In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix NULL pointer dereference in capture_engine When the intel_context structure contains NULL, it raises a NULL pointer dereference error in drm_info(). (cherry picked from commit 754302a5bc1bd8fd3b7

  • CVE-2024-56666MedDec 27, 2024
    affected >= 6.12.0, < 6.12.6fixed 6.12.6

    In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Dereference null return value In the function pqm_uninit there is a call-assignment of "pdd = kfd_get_process_device_data" which could be null, and this value was later dereferenced without checking

Page 538 of 713