VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (16,370)

  • CVE-2024-42303MedAug 17, 2024
    affected >= 6.3.0, < 6.6.44fixed 6.6.44

    In the Linux kernel, the following vulnerability has been resolved: media: imx-pxp: Fix ERR_PTR dereference in pxp_probe() devm_regmap_init_mmio() can fail, add a check and bail out in case of error.

  • CVE-2024-42302HigAug 17, 2024
    affected < 5.10.224fixed 5.10.224

    In the Linux kernel, the following vulnerability has been resolved: PCI/DPC: Fix use-after-free on concurrent DPC and hot-removal Keith reports a use-after-free when a DPC event occurs concurrently to hot-removal of the same portion of the hierarchy: The dpc_handler() awaits r

  • CVE-2024-42301HigAug 17, 2024
    affected >= 2.6.12, < 4.19.320fixed 4.19.320

    In the Linux kernel, the following vulnerability has been resolved: dev/parport: fix the array out-of-bounds risk Fixed array out-of-bounds issues caused by sprintf by replacing it with snprintf for safer data copying, ensuring the destination buffer is not overflowed. Below i

  • CVE-2024-42300HigAug 17, 2024
    affected >= 6.10.0, < 6.10.3fixed 6.10.3

    In the Linux kernel, the following vulnerability has been resolved: erofs: fix race in z_erofs_get_gbuf() In z_erofs_get_gbuf(), the current task may be migrated to another CPU between `z_erofs_gbuf_id()` and `spin_lock(&gbuf->lock)`. Therefore, z_erofs_put_gbuf() will trigger

  • CVE-2024-42299HigAug 17, 2024
    affected >= 5.15.0, < 5.15.165fixed 5.15.165

    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Update log->page_{mask,bits} if log->page_size changed If an NTFS file system is mounted to another system with different PAGE_SIZE from the original system, log->page_size will change in log_replay()

  • CVE-2024-42298MedAug 17, 2024
    affected >= 6.4.0, < 6.6.44fixed 6.6.44

    In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value devm_kasprintf() can return a NULL pointer on failure but this returned value is not checked. Fix this lack and check the returned value.

  • CVE-2024-42297HigAug 17, 2024
    affected >= 3.8.0, < 4.19.320fixed 4.19.320

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to don't dirty inode for readonly filesystem syzbot reports f2fs bug as below: kernel BUG at fs/f2fs/inode.c:933! RIP: 0010:f2fs_evict_inode+0x1576/0x1590 fs/f2fs/inode.c:933 Call Trace: evict+0x2a4

  • CVE-2024-42296HigAug 17, 2024
    affected >= 3.8.0, < 5.15.165fixed 5.15.165

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix return value of f2fs_convert_inline_inode() If device is readonly, make f2fs_convert_inline_inode() return EROFS instead of zero, otherwise it may trigger panic during writeback of inline inode's dirt

  • CVE-2024-42295MedAug 17, 2024
    affected >= 2.6.30, < 4.19.320fixed 4.19.320

    In the Linux kernel, the following vulnerability has been resolved: nilfs2: handle inconsistent state in nilfs_btnode_create_block() Syzbot reported that a buffer state inconsistency was detected in nilfs_btnode_create_block(), triggering a kernel bug. It is not appropriate to

  • CVE-2024-42294MedAug 17, 2024
    affected >= 6.5.0, < 6.6.44fixed 6.6.44

    In the Linux kernel, the following vulnerability has been resolved: block: fix deadlock between sd_remove & sd_release Our test report the following hung task: [ 2538.459400] INFO: task "kworker/0:0":7 blocked for more than 188 seconds. [ 2538.459427] Call trace: [ 2538.459430

  • CVE-2024-42293HigAug 17, 2024
    affected >= 6.9.0, < 6.10.3fixed 6.10.3

    In the Linux kernel, the following vulnerability has been resolved: arm64: mm: Fix lockless walks with static and dynamic page-table folding Lina reports random oopsen originating from the fast GUP code when 16K pages are used with 4-level page-tables, the fourth level being fo

  • CVE-2024-42292HigAug 17, 2024
    affected >= 4.15.0, < 4.19.320fixed 4.19.320

    In the Linux kernel, the following vulnerability has been resolved: kobject_uevent: Fix OOB access within zap_modalias_env() zap_modalias_env() wrongly calculates size of memory block to move, so will cause OOB memory access issue if variable MODALIAS is not the last one within

  • CVE-2024-42291MedAug 17, 2024
    affected >= 5.13.0, < 5.15.172fixed 5.15.172

    In the Linux kernel, the following vulnerability has been resolved: ice: Add a per-VF limit on number of FDIR filters While the iavf driver adds a s/w limit (128) on the number of FDIR filters that the VF can request, a malicious VF driver can request more than that and exhaust

  • CVE-2024-42290MedAug 17, 2024
    affected >= 5.0.0, < 5.4.282fixed 5.4.282

    In the Linux kernel, the following vulnerability has been resolved: irqchip/imx-irqsteer: Handle runtime power management correctly The power domain is automatically activated from clk_prepare(). However, on certain platforms like i.MX8QM and i.MX8QXP, the power-on handling inv

  • CVE-2024-42289MedAug 17, 2024
    affected >= 4.18.0, < 4.19.320fixed 4.19.320

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: During vport delete send async logout explicitly During vport delete, it is observed that during unload we hit a crash because of stale entries in outstanding command array. For all these stale

  • CVE-2024-42288HigAug 17, 2024
    affected >= 4.20.0, < 5.4.282fixed 5.4.282

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix for possible memory corruption Init Control Block is dereferenced incorrectly. Correctly dereference ICB

  • CVE-2024-42287HigAug 17, 2024
    affected < 5.4.282fixed 5.4.282

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Complete command early within lock A crash was observed while performing NPIV and FW reset, BUG: kernel NULL pointer dereference, address: 000000000000001c #PF: supervisor read access in kerne

  • CVE-2024-42286HigAug 17, 2024
    affected >= 4.19.0, < 4.19.320fixed 4.19.320

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: validate nvme_local_port correctly The driver load failed with error message, qla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef and with a kernel crash, BUG: unable to ha

  • CVE-2024-42285CriAug 17, 2024
    affected >= 4.8.0, < 4.19.320fixed 4.19.320

    In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs iw_conn_req_handler() associates a new struct rdma_id_private (conn_id) with an existing struct iw_cm_id (cm_id) as follows: conn_id->cm_id.

  • CVE-2024-42284CriAug 17, 2024
    affected >= 4.1.0, < 4.19.320fixed 4.19.320

    In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero value from tipc_udp_addr2str() on error tipc_udp_addr2str() should return non-zero value if the UDP media address is invalid. Otherwise, a buffer overflow access can occur in tipc_media_ad

Page 718 of 819