VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,254)

  • CVE-2024-46808MedSep 27, 2024
    affected >= 4.15.0, < 6.10.9fixed 6.10.9

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range [Why & How] ASSERT if return NULL from kcalloc.

  • CVE-2024-46807MedSep 27, 2024
    affected >= 4.20.0, < 5.15.167fixed 5.15.167

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdgpu: Check tbo resource pointer Validate tbo resource pointer, skip if NULL

  • CVE-2024-46806MedSep 27, 2024
    affected >= 5.1.0, < 6.6.50fixed 6.6.50

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix the warning division or modulo by zero Checks the partition mode and returns an error for an invalid mode.

  • CVE-2024-46805MedSep 27, 2024
    affected >= 5.15.0, < 5.15.167fixed 5.15.167

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix the waring dereferencing hive Check the amdgpu_hive_info *hive that maybe is NULL.

  • CVE-2024-46804HigSep 27, 2024
    affected >= 5.5.0, < 5.10.226fixed 5.10.226

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add array index check for hdcp ddc access [Why] Coverity reports OVERRUN warning. Do not check if array index valid. [How] Check msg_id valid and valid array index.

  • CVE-2024-46803HigSep 27, 2024
    affected >= 6.5.0, < 6.6.50fixed 6.6.50

    In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check debug trap enable before write dbg_ev_file In interrupt context, write dbg_ev_file will be run by work queue. It will cause write dbg_ev_file execution after debug_trap_disable, which will cau

  • CVE-2024-46802MedSep 27, 2024
    affected >= 4.15.0, < 6.1.109fixed 6.1.109

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: added NULL check at start of dc_validate_stream [Why] prevent invalid memory access [How] check if dc and stream are NULL

  • CVE-2022-48945HigSep 23, 2024
    affected >= 3.18.0, < 4.9.337fixed 4.9.337

    In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix compose size exceed boundary syzkaller found a bug: BUG: unable to handle page fault for address: ffffc9000a3b1000 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not

  • CVE-2024-46801HigSep 18, 2024
    affected >= 6.9.0, < 6.10.10fixed 6.10.10

    In the Linux kernel, the following vulnerability has been resolved: libfs: fix get_stashed_dentry() get_stashed_dentry() tries to optimistically retrieve a stashed dentry from a provided location. It needs to ensure to hold rcu lock before it dereference the stashed location t

  • CVE-2024-46800HigSep 18, 2024
    affected >= 3.3.0, < 4.19.322fixed 4.19.322

    In the Linux kernel, the following vulnerability has been resolved: sch/netem: fix use after free in netem_dequeue If netem_dequeue() enqueues packet to inner qdisc and that qdisc returns __NET_XMIT_STOLEN. The packet is dropped but qdisc_tree_reduce_backlog() is not called to

  • CVE-2024-46799HigSep 18, 2024
    affected >= 6.10.0, < 6.10.10fixed 6.10.10

    In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: Fix NULL dereference on XDP_TX If number of TX queues are set to 1 we get a NULL pointer dereference during XDP_TX. ~# ethtool -L eth0 tx 1 ~# ./xdp-trafficgen udp -A -

  • CVE-2024-46798HigSep 18, 2024
    affected >= 5.4.0, < 5.4.284fixed 5.4.284

    In the Linux kernel, the following vulnerability has been resolved: ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object When using kernel with the following extra config, - CONFIG_KASAN=y - CONFIG_KASAN_GENERIC=y - CONFIG_KASAN_INLINE=y - CONFIG_KASAN_VMALLOC=y - CONF

  • CVE-2024-46797MedSep 18, 2024
    affected >= 6.2.0, < 6.6.51fixed 6.6.51

    In the Linux kernel, the following vulnerability has been resolved: powerpc/qspinlock: Fix deadlock in MCS queue If an interrupt occurs in queued_spin_lock_slowpath() after we increment qnodesp->count and before node->lock is initialized, another CPU might see stale lock values

  • CVE-2024-46796CriSep 18, 2024
    affected < 6.6.51fixed 6.6.51

    In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_set_path_size() If smb2_compound_op() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() before retrying it as the referen

  • CVE-2024-46795MedSep 18, 2024
    affected >= 5.15.0, < 5.15.167fixed 5.15.167

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset the binding mark of a reused connection Steve French reported null pointer dereference error from sha256 lib. cifs.ko can send session setup requests on reused connection. If reused connection is u

  • CVE-2024-46794LowSep 18, 2024
    affected >= 5.19.0, < 6.1.110fixed 6.1.110

    In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix data leak in mmio_read() The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an address from the VMM. Sean noticed that mmio_read() unintentionally exposes the value of an initiali

  • CVE-2024-46793MedSep 18, 2024
    affected >= 6.8.0, < 6.10.10fixed 6.10.10

    In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: Boards: Fix NULL pointer deref in BYT/CHT boards harder Since commit 13f58267cda3 ("ASoC: soc.h: don't create dummy Component via COMP_DUMMY()") dummy codecs declared like this: SND_SOC_DAILINK_DE

  • CVE-2024-46792HigSep 18, 2024
    affected >= 6.7.0, < 6.10.10fixed 6.10.10

    In the Linux kernel, the following vulnerability has been resolved: riscv: misaligned: Restrict user access to kernel memory raw_copy_{to,from}_user() do not call access_ok(), so this code allowed userspace to access any virtual memory address.

  • CVE-2024-46791MedSep 18, 2024
    affected >= 5.5.0, < 5.10.226fixed 5.10.226

    In the Linux kernel, the following vulnerability has been resolved: can: mcp251x: fix deadlock if an interrupt occurs during mcp251x_open The mcp251x_hw_wake() function is called with the mpc_lock mutex held and disables the interrupt handler so that no interrupts can be proces

  • CVE-2024-46790MedSep 18, 2024
    affected >= 6.10.0, < 6.10.10fixed 6.10.10

    In the Linux kernel, the following vulnerability has been resolved: codetag: debug: mark codetags for poisoned page as empty When PG_hwpoison pages are freed they are treated differently in free_pages_prepare() and instead of being released they are isolated. Page allocation t

Page 590 of 713