VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (14,027)

  • CVE-2024-27078MedMay 1, 2024
    affected >= 3.18.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: media: v4l2-tpg: fix some memleaks in tpg_alloc In tpg_alloc, resources should be deallocated in each and every error-handling paths, since they are allocated in for statements. Otherwise there would be memleak

  • CVE-2024-27077MedMay 1, 2024
    affected >= 4.19.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity The entity->name (i.e. name) is allocated in v4l2_m2m_register_entity but isn't freed in its following error-handling paths. This patch adds such d

  • CVE-2024-27076MedMay 1, 2024
    affected >= 5.4.0, < 5.4.273fixed 5.4.273

    In the Linux kernel, the following vulnerability has been resolved: media: imx: csc/scaler: fix v4l2_ctrl_handler memory leak Free the memory allocated in v4l2_ctrl_handler_init on release.

  • CVE-2024-27075HigMay 1, 2024
    affected >= 4.16.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: avoid stack overflow warnings with clang A previous patch worked around a KASAN issue in stv0367, now a similar problem showed up with clang: drivers/media/dvb-frontends/stv0367.c:1222:12

  • CVE-2024-27074MedMay 1, 2024
    affected >= 3.10.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: media: go7007: fix a memleak in go7007_load_encoder In go7007_load_encoder, bounce(i.e. go->boot_fw), is allocated without a deallocation thereafter. After the following call chain: saa7134_go7007_init |-> g

  • CVE-2024-27073HigMay 1, 2024
    affected >= 2.6.12, < 5.4.273fixed 5.4.273

    In the Linux kernel, the following vulnerability has been resolved: media: ttpci: fix two memleaks in budget_av_attach When saa7146_register_device and saa7146_vv_init fails, budget_av_attach should free the resources it allocates, like the error-handling of ttpci_budget_init d

  • CVE-2024-27072MedMay 1, 2024
    affected >= 3.11.0, < 5.10.227fixed 5.10.227

    In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Remove useless locks in usbtv_video_free() Remove locks calls in usbtv_video_free() because are useless and may led to a deadlock as reported here: https://syzkaller.appspot.com/x/bisect.txt?x=166

  • CVE-2024-27071MedMay 1, 2024
    affected >= 6.8.0, < 6.8.2fixed 6.8.2

    In the Linux kernel, the following vulnerability has been resolved: backlight: hx8357: Fix potential NULL pointer dereference The "im" pins are optional. Add missing check in the hx8357_probe().

  • CVE-2024-27070HigMay 1, 2024
    affected >= 6.8.0, < 6.8.2fixed 6.8.2

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid use-after-free issue in f2fs_filemap_fault syzbot reports a f2fs bug as below: BUG: KASAN: slab-use-after-free in f2fs_filemap_fault+0xd1/0x2c0 fs/f2fs/file.c:49 Read of size 8 at addr ffff8

  • CVE-2024-27069MedMay 1, 2024
    affected >= 6.8.0, < 6.8.2fixed 6.8.2

    In the Linux kernel, the following vulnerability has been resolved: ovl: relax WARN_ON in ovl_verify_area() syzbot hit an assertion in copy up data loop which looks like it is the result of a lower file whose size is being changed underneath overlayfs. This type of use case is

  • CVE-2024-27068MedMay 1, 2024
    affected >= 6.3.0, < 6.6.23fixed 6.6.23

    In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/mediatek/lvts_thermal: Fix a memory leak in an error handling path If devm_krealloc() fails, then 'efuse' is leaking. So free it to avoid a leak.

  • CVE-2024-27067MedMay 1, 2024
    affected < 6.6.23fixed 6.6.23

    In the Linux kernel, the following vulnerability has been resolved: xen/evtchn: avoid WARN() when unbinding an event channel When unbinding a user event channel, the related handler might be called a last time in case the kernel was built with CONFIG_DEBUG_SHIRQ. This might cau

  • CVE-2024-27066HigMay 1, 2024
    affected >= 6.6.0, < 6.6.23fixed 6.6.23

    In the Linux kernel, the following vulnerability has been resolved: virtio: packed: fix unmap leak for indirect desc table When use_dma_api and premapped are true, then the do_unmap is false. Because the do_unmap is false, vring_unmap_extra_packed is not called by detach_buf_p

  • CVE-2024-27065HigMay 1, 2024
    affected < 5.4.273fixed 5.4.273

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: do not compare internal table flags on updates Restore skipping transaction if table update does not modify flags.

  • CVE-2024-27064MedMay 1, 2024
    affected >= 6.4.0, < 6.6.23fixed 6.6.23

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix a memory leak in nf_tables_updchain If nft_netdev_register_hooks() fails, the memory associated with nft_stats is not freed, causing a memory leak. This patch fixes it by moving nft_s

  • CVE-2024-27063MedMay 1, 2024
    affected >= 6.5.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: leds: trigger: netdev: Fix kernel panic on interface rename trig notify Commit d5e01266e7f5 ("leds: trigger: netdev: add additional specific link speed mode") in the various changes, reworked the way to set the

  • CVE-2024-27062HigMay 1, 2024
    affected >= 4.3.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: nouveau: lock the client object tree. It appears the client object tree has no locking unless I've missed something else. Fix races around adding/removing client objects, mostly vram bar mappings. 4562.099306

  • CVE-2024-27061HigMay 1, 2024
    affected >= 6.6.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ce - Fix use after free in unprepare sun8i_ce_cipher_unprepare should be called before crypto_finalize_skcipher_request, because client callbacks may immediately free memory, that isn't needed any

  • CVE-2024-27060MedMay 1, 2024
    affected >= 6.7.0, < 6.7.12fixed 6.7.12

    In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix NULL pointer dereference in tb_port_update_credits() Olliver reported that his system crashes when plugging in Thunderbolt 1 device: BUG: kernel NULL pointer dereference, address: 00000000000

  • CVE-2024-27059MedMay 1, 2024
    affected >= 2.6.12, < 4.19.312fixed 4.19.312

    In the Linux kernel, the following vulnerability has been resolved: USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command The isd200 sub-driver in usb-storage uses the HEADS and SECTORS values in the ATA ID information to calculate cylinder and head values when crea

Page 667 of 702