VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (16,370)

  • CVE-2023-52868HigMay 21, 2024
    affected >= 2.6.25, < 4.14.330fixed 4.14.330

    In the Linux kernel, the following vulnerability has been resolved: thermal: core: prevent potential string overflow The dev->id value comes from ida_alloc() so it's a number between zero and INT_MAX. If it's too high then these sprintf()s will overflow.

  • CVE-2023-52867HigMay 21, 2024
    affected >= 4.13.0, < 4.14.330fixed 4.14.330

    In the Linux kernel, the following vulnerability has been resolved: drm/radeon: possible buffer overflow Buffer 'afmt_status' of size 6 could overflow, since index 'afmt_idx' is checked after access.

  • CVE-2023-52866HigMay 21, 2024
    affected >= 6.3.0, < 6.5.12fixed 6.5.12

    In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Fix user-memory-access bug in uclogic_params_ugee_v2_init_event_hooks() When CONFIG_HID_UCLOGIC=y and CONFIG_KUNIT_ALL_TESTS=y, launch kernel and then the below user-memory-access bug occurs. In

  • CVE-2023-52865MedMay 21, 2024
    affected >= 4.12.0, < 4.14.330fixed 4.14.330

    In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: clk-mt6797: Add check for mtk_alloc_clk_data Add the check for the return value of mtk_alloc_clk_data() in order to avoid NULL pointer dereference.

  • CVE-2023-52864HigMay 21, 2024
    affected >= 4.15.0, < 4.19.299fixed 4.19.299

    In the Linux kernel, the following vulnerability has been resolved: platform/x86: wmi: Fix opening of char device Since commit fa1f68db6ca7 ("drivers: misc: pass miscdevice pointer via file private data"), the miscdevice stores a pointer to itself inside filp->private_data, whi

  • CVE-2023-52863MedMay 21, 2024
    affected >= 5.7.0, < 5.10.201fixed 5.10.201

    In the Linux kernel, the following vulnerability has been resolved: hwmon: (axi-fan-control) Fix possible NULL pointer dereference axi_fan_control_irq_handler(), dependent on the private axi_fan_control_data structure, might be called before the hwmon device is registered. That

  • CVE-2023-52862MedMay 21, 2024
    affected >= 6.5.0, < 6.5.12fixed 6.5.12

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix null pointer dereference in error message This patch fixes a null pointer dereference in the error message that is printed when the Display Core (DC) fails to initialize. The original messa

  • CVE-2023-52861MedMay 21, 2024
    affected >= 5.19.0, < 6.1.63fixed 6.1.63

    In the Linux kernel, the following vulnerability has been resolved: drm: bridge: it66121: Fix invalid connector dereference Fix the NULL pointer dereference when no monitor is connected, and the sound card is opened from userspace. Instead return an empty buffer (of zeroes) as

  • CVE-2023-52860MedMay 21, 2024
    affected >= 6.0.0, < 6.1.63fixed 6.1.63

    In the Linux kernel, the following vulnerability has been resolved: drivers/perf: hisi: use cpuhp_state_remove_instance_nocalls() for hisi_hns3_pmu uninit process When tearing down a 'hisi_hns3' PMU, we mistakenly run the CPU hotplug callbacks after the device has been unregist

  • CVE-2023-52859HigMay 21, 2024
    affected >= 5.13.0, < 5.15.139fixed 5.15.139

    In the Linux kernel, the following vulnerability has been resolved: perf: hisi: Fix use-after-free when register pmu fails When we fail to register the uncore pmu, the pmu context may not been allocated. The error handing will call cpuhp_state_remove_instance() to call uncore p

  • CVE-2023-52858MedMay 21, 2024
    affected >= 5.0.0, < 5.4.261fixed 5.4.261

    In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: clk-mt7629: Add check for mtk_alloc_clk_data Add the check for the return value of mtk_alloc_clk_data() in order to avoid NULL pointer dereference.

  • CVE-2023-52857MedMay 21, 2024
    affected >= 5.14.0, < 6.1.132fixed 6.1.132

    In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Fix coverity issue with unintentional integer overflow 1. Instead of multiplying 2 variable of different types. Change to assign a value of one variable and then multiply the other variable. 2. A

  • CVE-2023-52856MedMay 21, 2024
    affected >= 5.13.0, < 5.15.139fixed 5.15.139

    In the Linux kernel, the following vulnerability has been resolved: drm/bridge: lt8912b: Fix crash on bridge detach The lt8912b driver, in its bridge detach function, calls drm_connector_unregister() and drm_connector_cleanup(). drm_connector_unregister() should be called only

  • CVE-2023-52855MedMay 21, 2024
    affected >= 4.2.0, < 4.14.330fixed 4.14.330

    In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: fix possible NULL pointer dereference caused by driver concurrency In _dwc2_hcd_urb_enqueue(), "urb->hcpriv = NULL" is executed without holding the lock "hsotg->lock". In _dwc2_hcd_urb_dequeue():

  • CVE-2023-52854HigMay 21, 2024
    affected >= 5.6.0, < 5.10.201fixed 5.10.201

    In the Linux kernel, the following vulnerability has been resolved: padata: Fix refcnt handling in padata_free_shell() In a high-load arm64 environment, the pcrypt_aead01 test in LTP can lead to system UAF (Use-After-Free) issues. Due to the lengthy analysis of the pcrypt_aead0

  • CVE-2023-52853MedMay 21, 2024
    affected >= 4.10.0, < 4.19.299fixed 4.19.299

    In the Linux kernel, the following vulnerability has been resolved: hid: cp2112: Fix duplicate workqueue initialization Previously the cp2112 driver called INIT_DELAYED_WORK within cp2112_gpio_irq_startup, resulting in duplicate initilizations of the workqueue on subsequent IRQ

  • CVE-2023-52852HigMay 21, 2024
    affected >= 5.14.0, < 5.15.139fixed 5.15.139

    In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to avoid use-after-free on dic Call trace: __memcpy+0x128/0x250 f2fs_read_multi_pages+0x940/0xf7c f2fs_mpage_readpages+0x5a8/0x624 f2fs_readahead+0x5c/0x110 page_cache_ra_unbounded+0x1b

  • CVE-2023-52851HigMay 21, 2024
    affected >= 5.19.0, < 6.1.63fixed 6.1.63

    In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Fix init stage error handling to avoid double free of same QP and UAF In the unlikely event that workqueue allocation fails and returns NULL in mlx5_mkey_cache_init(), delete the call to mlx5r_umr_reso

  • CVE-2023-52850MedMay 21, 2024
    affected >= 5.18.0, < 6.1.63fixed 6.1.63

    In the Linux kernel, the following vulnerability has been resolved: media: hantro: Check whether reset op is defined before use The i.MX8MM/N/P does not define the .reset op since reset of the VPU is done by genpd. Check whether the .reset op is defined before calling it to avo

  • CVE-2023-52849MedMay 21, 2024
    affected >= 5.15.0, < 5.15.139fixed 5.15.139

    In the Linux kernel, the following vulnerability has been resolved: cxl/mem: Fix shutdown order Ira reports that removing cxl_mock_mem causes a crash with the following trace: BUG: kernel NULL pointer dereference, address: 0000000000000044 [..] RIP: 0010:cxl_region_decode_r

Page 761 of 819