VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,119)

  • CVE-2024-41044MedJul 29, 2024
    affected >= 2.6.12, < 4.19.318fixed 4.19.318

    In the Linux kernel, the following vulnerability has been resolved: ppp: reject claimed-as-LCP but actually malformed packets Since 'ppp_async_encode()' assumes valid LCP packets (with code from 1 to 7 inclusive), add 'ppp_check_packet()' to ensure that LCP packet has an actual

  • CVE-2024-41043MedJul 29, 2024
    affected >= 6.9.0, < 6.9.10fixed 6.9.10

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: drop bogus WARN_ON Happens when rules get flushed/deleted while packet is out, so remove this WARN_ON. This WARN exists in one form or another since v4.14, no need to backport this

  • CVE-2024-41042HigJul 29, 2024
    affected >= 3.13.0, < 4.19.320fixed 4.19.320

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: prefer nft_chain_validate nft_chain_validate already performs loop detection because a cycle will result in a call stack overflow (ctx->level >= NFT_JUMP_STACK_SIZE). It also follows maps

  • CVE-2024-41041HigJul 29, 2024
    affected >= 4.20.0, < 5.4.280fixed 5.4.280

    In the Linux kernel, the following vulnerability has been resolved: udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port(). syzkaller triggered the warning [0] in udp_v4_early_demux(). In udp_v[46]_early_demux() and sk_lookup(), we do not touch the refcount of the looked-up sk a

  • CVE-2024-41040CriJul 29, 2024
    affected < 5.10.222fixed 5.10.222

    In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix UAF when resolving a clash KASAN reports the following UAF: BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct] Read of size 1 at addr ffff888c07603600 by ta

  • CVE-2024-41039HigJul 29, 2024
    affected >= 5.16.0, < 6.1.100fixed 6.1.100

    In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix overflow checking of wmfw header Fix the checking that firmware file buffer is large enough for the wmfw header, to prevent overrunning the buffer. The original code tested that the firmw

  • CVE-2024-41038HigJul 29, 2024
    affected >= 5.16.0, < 6.1.100fixed 6.1.100

    In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers Check that all fields of a V2 algorithm header fit into the available firmware data buffer. The wmfw V2 format introduced variable-length

  • CVE-2024-41037MedJul 29, 2024
    affected >= 6.4.0, < 6.6.41fixed 6.6.41

    In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: fix null deref on system suspend entry When system enters suspend with an active stream, SOF core calls hw_params_upon_resume(). On Intel platforms with HDA DMA used to manage the link DM

  • CVE-2024-41036HigJul 29, 2024
    affected < 6.1.100fixed 6.1.100

    In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Fix deadlock with the SPI chip variant When SMP is enabled and spinlocks are actually functional then there is a deadlock with the 'statelock' spinlock between ks8851_start_xmit_spi and ks8851_irq:

  • CVE-2024-41035MedJul 29, 2024
    affected >= 4.10.0, < 4.19.318fixed 4.19.318

    In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor Syzbot has identified a bug in usbcore (see the Closes: tag below) caused by our assumption that the reserved bits in an endpoin

  • CVE-2024-41034HigJul 29, 2024
    affected >= 2.6.30, < 4.19.318fixed 4.19.318

    In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel bug on rename operation of broken directory Syzbot reported that in rename directory operation on broken directory on nilfs2, __block_write_begin_int() called to prepare block write may fail

  • CVE-2024-41033MedJul 29, 2024
    affected >= 6.8.0, < 6.9.10fixed 6.9.10

    In the Linux kernel, the following vulnerability has been resolved: cachestat: do not flush stats in recency check syzbot detects that cachestat() is flushing stats, which can sleep, in its RCU read section (see [1]). This is done in the workingset_test_recent() step (which ch

  • CVE-2024-41032HigJul 29, 2024
    affected >= 6.4.0, < 6.6.41fixed 6.6.41

    In the Linux kernel, the following vulnerability has been resolved: mm: vmalloc: check if a hash-index is in cpu_possible_mask The problem is that there are systems where cpu_possible_mask has gaps between set CPUs, for example SPARC. In this scenario addr_to_vb_xa() hash func

  • CVE-2024-41031MedJul 29, 2024
    affected >= 5.18.0, < 6.6.41fixed 6.6.41

    In the Linux kernel, the following vulnerability has been resolved: mm/filemap: skip to create PMD-sized page cache if needed On ARM64, HPAGE_PMD_ORDER is 13 when the base page size is 64KB. The PMD-sized page cache can't be supported by xarray as the following error messages

  • CVE-2024-41030MedJul 29, 2024
    affected >= 5.15.0, < 6.1.100fixed 6.1.100

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: discard write access to the directory open may_open() does not allow a directory to be opened with the write access. However, some writing flags set by client result in adding write access on server, mak

  • CVE-2024-41029MedJul 29, 2024
    affected >= 6.8.0, < 6.9.10fixed 6.9.10

    In the Linux kernel, the following vulnerability has been resolved: nvmem: core: limit cell sysfs permissions to main attribute ones The cell sysfs attribute should not provide more access to the nvmem data than the main attribute itself. For example if nvme_config::root_only w

  • CVE-2024-41028HigJul 29, 2024
    affected >= 6.1.0, < 6.1.100fixed 6.1.100

    In the Linux kernel, the following vulnerability has been resolved: platform/x86: toshiba_acpi: Fix array out-of-bounds access In order to use toshiba_dmi_quirks[] together with the standard DMI matching functions, it must be terminated by a empty entry. Since this entry is mi

  • CVE-2024-41027LowJul 29, 2024
    affected >= 5.7.0, < 5.15.163fixed 5.15.163

    In the Linux kernel, the following vulnerability has been resolved: Fix userfaultfd_api to return EINVAL as expected Currently if we request a feature that is not set in the Kernel config we fail silently and return all the available features. However, the man page indicates w

  • CVE-2024-41026HigJul 29, 2024
    affected >= 6.9.0, < 6.9.10fixed 6.9.10

    In the Linux kernel, the following vulnerability has been resolved: mmc: davinci_mmc: Prevent transmitted data size from exceeding sgm's length No check is done on the size of the data to be transmiited. This causes a kernel panic when this size exceeds the sg_miter's length.

  • CVE-2024-41025MedJul 29, 2024
    affected >= 6.2.0, < 6.6.41fixed 6.6.41

    In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix memory leak in audio daemon attach operation Audio PD daemon send the name as part of the init IOCTL call. This name needs to be copied to kernel for which memory is allocated. This memory is

Page 617 of 706