VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,119)

  • CVE-2024-42090MedJul 29, 2024
    affected >= 3.10.0, < 4.19.317fixed 4.19.317

    In the Linux kernel, the following vulnerability has been resolved: pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER In create_pinctrl(), pinctrl_maps_mutex is acquired before calling add_setting(). If add_setting() returns -EPROBE_DEFER, create_pinctrl() c

  • CVE-2024-42089MedJul 29, 2024
    affected >= 3.18.0, < 4.19.317fixed 4.19.317

    In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl-asoc-card: set priv->pdev before using it priv->pdev pointer was set after being used in fsl_asoc_card_audmux_init(). Move this assignment at the start of the probe function, so sub-functions can corr

  • CVE-2024-42088HigJul 29, 2024
    affected >= 6.8.0, < 6.9.8fixed 6.9.8

    In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") removed the codec entry for the ETDM1_OUT_BE d

  • CVE-2024-42087MedJul 29, 2024
    affected >= 4.19.0, < 4.19.317fixed 4.19.317

    In the Linux kernel, the following vulnerability has been resolved: drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep The ilitek-ili9881c controls the reset GPIO using the non-sleeping gpiod_set_value() function. This complains loudly when the GPIO contro

  • CVE-2024-42086HigJul 29, 2024
    affected >= 4.19.0, < 4.19.317fixed 4.19.317

    In the Linux kernel, the following vulnerability has been resolved: iio: chemical: bme680: Fix overflows in compensate() functions There are cases in the compensate functions of the driver that there could be overflows of variables due to bit shifting ops. These implications we

  • CVE-2024-42085MedJul 29, 2024
    affected < 5.15.162fixed 5.15.162

    In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: remove lock of otg mode during gadget suspend/resume to avoid deadlock When config CONFIG_USB_DWC3_DUAL_ROLE is selected, and trigger system to enter suspend status with below command: echo mem

  • CVE-2024-42084MedJul 29, 2024
    affected >= 3.9.0, < 4.19.317fixed 4.19.317

    In the Linux kernel, the following vulnerability has been resolved: ftruncate: pass a signed offset The old ftruncate() syscall, using the 32-bit off_t misses a sign extension when called in compat mode on 64-bit architectures. As a result, passing a negative length accidental

  • CVE-2024-42083HigJul 29, 2024
    affected >= 6.9.0, < 6.9.8fixed 6.9.8

    In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic due to multi-buffer handling Currently, the ionic_run_xdp() doesn't handle multi-buffer packets properly for XDP_TX and XDP_REDIRECT. When a jumbo frame is received, the ionic_run_xdp()

  • CVE-2024-42082MedJul 29, 2024
    affected >= 4.18.0, < 5.10.221fixed 5.10.221

    In the Linux kernel, the following vulnerability has been resolved: xdp: Remove WARN() from __xdp_reg_mem_model() syzkaller reports a warning in __xdp_reg_mem_model(). The warning occurs only if __mem_id_init_hash_table() returns an error. It returns the error in two cases:

  • CVE-2024-42081MedJul 29, 2024
    affected >= 6.8.0, < 6.9.8fixed 6.9.8

    In the Linux kernel, the following vulnerability has been resolved: drm/xe/xe_devcoredump: Check NULL before assignments Assign 'xe_devcoredump_snapshot *' and 'xe_device *' only if 'coredump' is not NULL. v2 - Fix commit messages. v3 - Define variables before code.(Ashutosh/

  • CVE-2024-42080MedJul 29, 2024
    affected >= 4.17.0, < 5.15.162fixed 5.15.162

    In the Linux kernel, the following vulnerability has been resolved: RDMA/restrack: Fix potential invalid address access struct rdma_restrack_entry's kern_name was set to KBUILD_MODNAME in ib_create_cq(), while if the module exited but forgot del this rdma_restrack_entry, it wou

  • CVE-2024-42079MedJul 29, 2024
    affected >= 5.12.0, < 5.15.200fixed 5.15.200

    In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix NULL pointer dereference in gfs2_log_flush In gfs2_jindex_free(), set sdp->sd_jdesc to NULL under the log flush lock to provide exclusion against gfs2_log_flush(). In gfs2_log_flush(), check if sdp->

  • CVE-2024-42078MedJul 29, 2024
    affected >= 6.8.0, < 6.9.8fixed 6.9.8

    In the Linux kernel, the following vulnerability has been resolved: nfsd: initialise nfsd_info.mutex early. nfsd_info.mutex can be dereferenced by svc_pool_stats_start() immediately after the new netns is created. Currently this can trigger an oops. Move the initialisation ea

  • CVE-2024-42077MedJul 29, 2024
    affected >= 4.6.0, < 5.10.221fixed 5.10.221

    In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix DIO failure due to insufficient transaction credits The code in ocfs2_dio_end_io_write() estimates number of necessary transaction credits using ocfs2_calc_extend_credits(). This however does not ta

  • CVE-2024-42076MedJul 29, 2024
    affected >= 5.4.0, < 5.4.279fixed 5.4.279

    In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: Initialize unused data in j1939_send_one() syzbot reported kernel-infoleak in raw_recvmsg() [1]. j1939_send_one() creates full frame including unused data, but it doesn't initialize it. This ca

  • CVE-2024-42075HigJul 29, 2024
    affected >= 6.9.0, < 6.9.8fixed 6.9.8

    In the Linux kernel, the following vulnerability has been resolved: bpf: Fix remap of arena. The bpf arena logic didn't account for mremap operation. Add a refcnt for multiple mmap events to prevent use-after-free in arena_vm_close.

  • CVE-2024-42074MedJul 29, 2024
    affected >= 6.6.0, < 6.6.37fixed 6.6.37

    In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: add a null check for chip_pdev structure When acp platform device creation is skipped, chip->chip_pdev value will remain NULL. Add NULL check for chip->chip_pdev structure in snd_acp_resume() fu

  • CVE-2024-42073MedJul 29, 2024
    affected >= 5.17.0, < 6.1.97fixed 6.1.97

    In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_buffers: Fix memory corruptions on Spectrum-4 systems The following two shared buffer operations make use of the Shared Buffer Status Register (SBSR): # devlink sb occupancy snapshot pci/0000:

  • CVE-2024-42072HigJul 29, 2024
    affected >= 6.9.0, < 6.9.8fixed 6.9.8

    In the Linux kernel, the following vulnerability has been resolved: bpf: Fix may_goto with negative offset. Zac's syzbot crafted a bpf prog that exposed two bugs in may_goto. The 1st bug is the way may_goto is patched. When offset is negative it should be patched differently. T

  • CVE-2024-42071HigJul 29, 2024
    affected >= 6.9.0, < 6.9.8fixed 6.9.8

    In the Linux kernel, the following vulnerability has been resolved: ionic: use dev_consume_skb_any outside of napi If we're not in a NAPI softirq context, we need to be careful about how we call napi_consume_skb(), specifically we need to call it with budget==0 to signal to it

Page 613 of 706