VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,255)

  • CVE-2024-56564MedDec 27, 2024
    affected >= 6.10.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: ceph: pass cred pointer to ceph_mds_auth_match() This eliminates a redundant get_current_cred() call, because ceph_mds_check_access() has already obtained this pointer. As a side effect, this also fixes a refe

  • CVE-2024-56563HigDec 27, 2024
    affected >= 6.10.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: ceph: fix cred leak in ceph_mds_check_access() get_current_cred() increments the reference counter, but the put_cred() call was missing.

  • CVE-2024-56562MedDec 27, 2024
    affected >= 5.0.0, < 5.4.287fixed 5.4.287

    In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs() if (dev->boardinfo && dev->boardinfo->init_dyn_addr) ^^^ here check "init_dyn_addr" i3c_bus_set_addr

  • CVE-2024-56561HigDec 27, 2024
    affected >= 6.12.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Fix PCI domain ID release in pci_epc_destroy() pci_epc_destroy() invokes pci_bus_release_domain_nr() to release the PCI domain ID, but there are two issues: - 'epc->dev' is passed to pci_bus_r

  • CVE-2024-56560MedDec 27, 2024
    affected >= 6.12.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: slab: Fix too strict alignment check in create_cache() On m68k, where the minimum alignment of unsigned long is 2 bytes: Kernel panic - not syncing: __kmem_cache_create_args: Failed to create slab 'io_kioc

  • CVE-2024-56559MedDec 27, 2024
    affected >= 6.9.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: combine all TLB flush operations of KASAN shadow virtual address into one operation When compiling kernel source 'make -j $(nproc)' with the up-and-running KASAN-enabled kernel on a 256-core machine

  • CVE-2024-56558HigDec 27, 2024
    affected >= 3.17.0, < 5.4.287fixed 5.4.287

    In the Linux kernel, the following vulnerability has been resolved: nfsd: make sure exp active before svc_export_show The function `e_show` was called with protection from RCU. This only ensures that `exp` will not be freed. Therefore, the reference count for `exp` can drop to

  • CVE-2024-56557HigDec 27, 2024
    affected >= 5.6.0, < 5.15.203fixed 5.15.203

    In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer The AD7923 was updated to support devices with 8 channels, but the size of tx_buf and ring_xfer was not increased accordingly, leading to a potenti

  • CVE-2024-56556HigDec 27, 2024
    affected >= 6.12.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: binder: fix node UAF in binder_add_freeze_work() In binder_add_freeze_work() we iterate over the proc->nodes with the proc->inner_lock held. However, this lock is temporarily dropped in order to acquire the nod

  • CVE-2024-56555HigDec 27, 2024
    affected >= 6.12.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: binder: fix OOB in binder_add_freeze_work() In binder_add_freeze_work() we iterate over the proc->nodes with the proc->inner_lock held. However, this lock is temporarily dropped to acquire the node->lock first

  • CVE-2024-56554HigDec 27, 2024
    affected >= 6.12.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: binder: fix freeze UAF in binder_release_work() When a binder reference is cleaned up, any freeze work queued in the associated process should also be removed. Otherwise, the reference is freed while its ref->f

  • CVE-2024-56553MedDec 27, 2024
    affected >= 6.12.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: binder: fix memleak of proc->delivered_freeze If a freeze notification is cleared with BC_CLEAR_FREEZE_NOTIFICATION before calling binder_freeze_notification_done(), then it is detached from its reference (e.g.

  • CVE-2024-56552HigDec 27, 2024
    affected >= 6.8.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc_submit: fix race around suspend_pending Currently in some testcases we can trigger: xe 0000:03:00.0: [drm] Assertion `exec_queue_destroyed(q)` failed! .... WARNING: CPU: 18 PID: 2640 at drivers/gpu/

  • CVE-2024-56551HigDec 27, 2024
    affected >= 4.2.0, < 5.15.181fixed 5.15.181

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix usage slab after free [ +0.000021] BUG: KASAN: slab-use-after-free in drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched] [ +0.000027] Read of size 8 at addr ffff8881b8605f88 by task amd_pci_unplug

  • CVE-2024-56550MedDec 27, 2024
    affected >= 6.10.0, < 6.12.4fixed 6.12.4

    In the Linux kernel, the following vulnerability has been resolved: s390/stacktrace: Use break instead of return statement arch_stack_walk_user_common() contains a return statement instead of a break statement in case store_ip() fails while trying to store a callchain entry of

  • CVE-2024-56549HigDec 27, 2024
    affected >= 5.19.0, < 6.1.129fixed 6.1.129

    In the Linux kernel, the following vulnerability has been resolved: cachefiles: Fix NULL pointer dereference in object->file At present, the object->file has the NULL pointer dereference problem in ondemand-mode. The root cause is that the allocated fd and object->file lifetime

  • CVE-2024-56548HigDec 27, 2024
    affected >= 3.1.0, < 4.19.325fixed 4.19.325

    In the Linux kernel, the following vulnerability has been resolved: hfsplus: don't query the device logical block size multiple times Devices block sizes may change. One of these cases is a loop device by using ioctl LOOP_SET_BLOCK_SIZE. While this may cause other issues like

  • CVE-2024-56547MedDec 27, 2024
    affected >= 6.12.0, < 6.12.2fixed 6.12.2

    In the Linux kernel, the following vulnerability has been resolved: rcu/nocb: Fix missed RCU barrier on deoffloading Currently, running rcutorture test with torture_type=rcu fwd_progress=8 n_barrier_cbs=8 nocbs_nthreads=8 nocbs_toggle=100 onoff_interval=60 test_boost=2, will tr

  • CVE-2024-56546MedDec 27, 2024
    affected >= 5.19.0, < 6.1.120fixed 6.1.120

    In the Linux kernel, the following vulnerability has been resolved: drivers: soc: xilinx: add the missing kfree in xlnx_add_cb_for_suspend() If we fail to allocate memory for cb_data by kmalloc, the memory allocation for eve_data is never freed, add the missing kfree() in the e

  • CVE-2024-56545MedDec 27, 2024
    affected >= 6.5.0, < 6.6.64fixed 6.6.64

    In the Linux kernel, the following vulnerability has been resolved: HID: hyperv: streamline driver probe to avoid devres issues It was found that unloading 'hid_hyperv' module results in a devres complaint: ... hv_vmbus: unregistering driver hid_hyperv ------------[ cut her

Page 544 of 713