VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,996)

  • CVE-2024-39485MedJul 5, 2024
    affected >= 6.6.0, < 6.6.34fixed 6.6.34

    In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Properly re-initialise notifier entry in unregister The notifier_entry of a notifier is not re-initialised after unregistering the notifier. This leads to dangling pointers being left there s

  • CVE-2024-39484MedJul 5, 2024
    affected >= 2.6.33, < 5.10.221fixed 5.10.221

    In the Linux kernel, the following vulnerability has been resolved: mmc: davinci: Don't strip remove function when driver is builtin Using __exit for the remove function results in the remove callback being discarded with CONFIG_MMC_DAVINCI=y. When such a device gets unbound (e

  • CVE-2024-39483HigJul 5, 2024
    affected >= 6.4.0, < 6.6.34fixed 6.6.34

    In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked When requesting an NMI window, WARN on vNMI support being enabled if and only if NMIs are actually masked, i.e. if the vCPU is already handling a

  • CVE-2024-39482HigJul 5, 2024
    affected >= 3.10.0, < 5.10.221fixed 5.10.221

    In the Linux kernel, the following vulnerability has been resolved: bcache: fix variable length array abuse in btree_iter btree_iter is used in two ways: either allocated on the stack with a fixed size MAX_BSETS, or from a mempool with a dynamic size based on the specific cache

  • CVE-2024-39481HigJul 5, 2024
    affected >= 6.1.0, < 6.1.94fixed 6.1.94

    In the Linux kernel, the following vulnerability has been resolved: media: mc: Fix graph walk in media_pipeline_start The graph walk tries to follow all links, even if they are not between pads. This causes a crash with, e.g. a MEDIA_LNK_FL_ANCILLARY_LINK link. Fix this by all

  • CVE-2024-39480HigJul 5, 2024
    affected >= 2.6.35, < 4.19.316fixed 4.19.316

    In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the Tab key, kdb will use strncpy() to insert the completed symbol into the command buffer. Unfortunately it

  • CVE-2024-39479HigJul 5, 2024
    affected >= 6.2.0, < 6.6.34fixed 6.6.34

    In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon and hwmon drvdata (on which hwmon depends) are device managed resources, the expectation, on device unbind, is that hwmon will be released before drvdata. However

  • CVE-2024-39478HigJul 5, 2024
    affected >= 6.5.0, < 6.6.156fixed 6.6.156

    In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in subsequent operations.

  • CVE-2024-39477HigJul 5, 2024
    affected >= 6.9.0, < 6.9.5fixed 6.9.5

    In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: do not call vma_add_reservation upon ENOMEM sysbot reported a splat [1] on __unmap_hugepage_range(). This is because vma_needs_reservation() can return -ENOMEM if allocate_file_region_entries() fai

  • CVE-2024-39476MedJul 5, 2024
    affected < 4.19.316fixed 4.19.316

    In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING Xiao reported that lvm2 test lvconvert-raid-takeover.sh can hang with small possibility, the root cause is exactly the same as

  • CVE-2024-39475MedJul 5, 2024
    affected < 4.19.316fixed 4.19.316

    In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Handle err return when savagefb_check_var failed The commit 04e5eac8f3ab("fbdev: savage: Error out if pixclock equals zero") checks the value of pixclock to avoid divide-by-zero error. However th

  • CVE-2024-39474MedJul 5, 2024
    affected >= 5.17.0, < 6.1.95fixed 6.1.95

    In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL commit a421ef303008 ("mm: allow !GFP_KERNEL allocations for kvmalloc") includes support for __GFP_NOFAIL, but it presents a conflict wit

  • CVE-2024-39473MedJul 5, 2024
    affected >= 6.4.0, < 6.6.34fixed 6.6.34

    In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension If a process module does not have base config extension then the same format applies to all of it's inputs and the proc

  • CVE-2024-39472HigJul 5, 2024
    affected >= 5.10.0, < 5.15.165fixed 5.15.165

    In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the legacy h_size fixup Commit a70f9fe52daa ("xfs: detect and handle invalid iclog size set by mkfs") added a fixup for incorrect h_size values used for the initial u

  • CVE-2024-39471HigJun 25, 2024
    affected >= 5.4.0, < 5.4.278fixed 5.4.278

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add error handle to avoid out-of-bounds if the sdma_v4_0_irq_id_to_seq return -EINVAL, the process should be stop to avoid out-of-bounds read, so directly return -EINVAL.

  • CVE-2024-39470MedJun 25, 2024
    affected < 6.6.34fixed 6.6.34

    In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix a possible null pointer dereference in eventfs_find_events() In function eventfs_find_events,there is a potential null pointer that may be caused by calling update_events_attr which will perform so

  • CVE-2024-39469HigJun 25, 2024
    affected >= 2.6.30, < 4.19.317fixed 4.19.317

    In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors The error handling in nilfs_empty_dir() when a directory folio/page read fails is incorrect, as in the old ext2 implementation, and if the f

  • CVE-2024-39468HigJun 25, 2024
    affected >= 5.14.0, < 5.15.162fixed 5.15.162

    In the Linux kernel, the following vulnerability has been resolved: smb: client: fix deadlock in smb2_find_smb_tcon() Unlock cifs_tcp_ses_lock before calling cifs_put_smb_ses() to avoid such deadlock.

  • CVE-2024-39467HigJun 25, 2024
    affected >= 3.8.0, < 5.4.278fixed 5.4.278

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode() syzbot reports a kernel bug as below: F2FS-fs (loop0): Mounted with checkpoint version = 48b305e4 ===========================================

  • CVE-2024-39466MedJun 25, 2024
    affected >= 5.15.0, < 5.15.161fixed 5.15.161

    In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/qcom/lmh: Check for SCM availability at probe Up until now, the necessary scm availability check has not been performed, leading to possible null pointer dereferences (which did happen for me on

Page 724 of 800