VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,027)

  • CVE-2024-35792HigMay 17, 2024
    affected >= 6.6.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: crypto: rk3288 - Fix use after free in unprepare The unprepare call must be carried out before the finalize call as the latter can free the request.

  • CVE-2024-35791HigMay 17, 2024
    affected < 5.10.215fixed 5.10.215

    In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region() Do the cache flush of converted pages in svm_register_enc_region() before dropping kvm->lock to fix use-after-free issues where regi

  • CVE-2024-35790MedMay 17, 2024
    affected >= 4.19.0, < 5.10.238fixed 5.10.238

    In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group The DisplayPort driver's sysfs nodes may be present to the userspace before typec_altmode_set_drvdata() completes

  • CVE-2024-35789HigMay 17, 2024
    affected < 4.19.312fixed 4.19.312

    In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes When moving a station out of a VLAN and deleting the VLAN afterwards, the fast_rx entry still holds a pointer to the VLAN's netdev, which can c

  • CVE-2024-35787HigMay 17, 2024
    affected >= 6.6.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix incorrect usage for sb_index Commit d7038f951828 ("md-bitmap: don't use ->index for pages backing the bitmap file") removed page->index from bitmap code, but left wrong code logic for clustere

  • CVE-2024-35786MedMay 17, 2024
    affected >= 6.6.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix stale locked mutex in nouveau_gem_ioctl_pushbuf If VM_BIND is enabled on the client the legacy submission ioctl can't be used, however if a client tries to do so regardless it will return an er

  • CVE-2024-35785HigMay 17, 2024
    affected < 5.10.215fixed 5.10.215

    In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix kernel panic caused by incorrect error handling The error path while failing to register devices on the TEE bus has a bug leading to kernel panic as follows: [ 15.398930] Unable to handle ker

  • CVE-2024-35784MedMay 17, 2024
    affected >= 2.6.29, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock with fiemap and extent locking While working on the patchset to remove extent locking I got a lockdep splat with fiemap and pagefaulting with my new extent lock replacement lock. This deadl

  • CVE-2024-27436MedMay 17, 2024
    affected >= 3.8.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Stop parsing channels bits when all channels are found. If a usb audio device sets more bits than the amount of channels it could write outside of the map array.

  • CVE-2024-27435HigMay 17, 2024
    affected >= 5.12.0, < 6.1.83fixed 6.1.83

    In the Linux kernel, the following vulnerability has been resolved: nvme: fix reconnection fail due to reserved tag allocation We found a issue on production environment while using NVMe over RDMA, admin_q reconnect failed forever while remote target and network is ok. After di

  • CVE-2024-27434HigMay 17, 2024
    affected >= 6.2.0, < 6.6.23fixed 6.6.23

    In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't set the MFP flag for the GTK The firmware doesn't need the MFP flag for the GTK, it can even make the firmware crash. in case the AP is configured with: group cipher TKIP and MFPC. We

  • CVE-2024-27433HigMay 17, 2024
    affected >= 6.4.0, < 6.6.23fixed 6.6.23

    In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: mt7622-apmixedsys: Fix an error handling path in clk_mt8135_apmixed_probe() 'clk_data' is allocated with mtk_devm_alloc_clk_data(). So calling mtk_free_clk_data() explicitly in the remove functio

  • CVE-2024-27432MedMay 17, 2024
    affected >= 5.13.0, < 5.15.153fixed 5.15.153

    In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix PPE hanging issue A patch to resolve an issue was found in MediaTek's GPL-licensed SDK: In the mtk_ppe_stop() function, the PPE scan mode is not disabled before disabling the PPE

  • CVE-2023-52660MedMay 17, 2024
    affected >= 5.6.0, < 6.1.83fixed 6.1.83

    In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ handling due to shared interrupts The driver requests the interrupts as IRQF_SHARED, so the interrupt handlers can be called at any time. If such a call happens while the ISP is powered d

  • CVE-2023-52659MedMay 17, 2024
    affected >= 6.5.0, < 6.6.23fixed 6.6.23

    In the Linux kernel, the following vulnerability has been resolved: x86/mm: Ensure input to pfn_to_kaddr() is treated as a 64-bit type On 64-bit platforms, the pfn_to_kaddr() macro requires that the input value is 64 bits in order to ensure that valid address bits don't get los

  • CVE-2024-27431HigMay 17, 2024
    affected >= 5.9.0, < 5.10.213fixed 5.10.213

    In the Linux kernel, the following vulnerability has been resolved: cpumap: Zero-initialise xdp_rxq_info struct before running XDP program When running an XDP program that is attached to a cpumap entry, we don't initialise the xdp_rxq_info data structure being used in the xdp_b

  • CVE-2024-27419MedMay 17, 2024
    affected >= 2.6.12, < 4.19.310fixed 4.19.310

    In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around sysctl_net_busy_read We need to protect the reader reading the sysctl value because the value can be changed concurrently.

  • CVE-2024-27418MedMay 17, 2024
    affected >= 5.15.0, < 6.1.81fixed 6.1.81

    In the Linux kernel, the following vulnerability has been resolved: net: mctp: take ownership of skb in mctp_local_output Currently, mctp_local_output only takes ownership of skb on success, and we may leak an skb if mctp_local_output fails in specific states; the skb ownership

  • CVE-2024-27417MedMay 17, 2024
    affected >= 4.20.0, < 5.4.271fixed 5.4.271

    In the Linux kernel, the following vulnerability has been resolved: ipv6: fix potential "struct net" leak in inet6_rtm_getaddr() It seems that if userspace provides a correct IFA_TARGET_NETNSID value but no IFA_ADDRESS and IFA_LOCAL attributes, inet6_rtm_getaddr() returns -EINV

  • CVE-2024-27416HigMay 17, 2024
    affected < 4.19.309fixed 4.19.309

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise

Page 663 of 702