VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,762)

  • CVE-2024-26791HigApr 4, 2024
    affected >= 3.8.0, < 4.19.309fixed 4.19.309

    In the Linux kernel, the following vulnerability has been resolved: btrfs: dev-replace: properly validate device names There's a syzbot report that device name buffers passed to device replace are not properly checked for string termination which could lead to a read out of bou

  • CVE-2024-26790MedApr 4, 2024
    affected >= 5.1.0, < 5.4.271fixed 5.4.271

    In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-qdma: fix SoC may hang on 16 byte unaligned read There is chip (ls1028a) errata: The SoC may hang on 16 byte unaligned read transactions by QDMA. Unaligned read transactions initiated by QDMA m

  • CVE-2024-26789HigApr 4, 2024
    affected >= 5.18.0, < 6.1.81fixed 6.1.81

    In the Linux kernel, the following vulnerability has been resolved: crypto: arm64/neonbs - fix out-of-bounds access on short input The bit-sliced implementation of AES-CTR operates on blocks of 128 bytes, and will fall back to the plain NEON version for tail blocks or inputs th

  • CVE-2024-26788MedApr 4, 2024
    affected >= 5.1.0, < 5.4.271fixed 5.4.271

    In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-qdma: init irq after reg initialization Initialize the qDMA irqs after the registers are configured so that interrupts that may have been pending from a primary kernel don't get processed by the

  • CVE-2024-26787MedApr 4, 2024
    affected >= 4.20.0, < 5.10.213fixed 5.10.213

    In the Linux kernel, the following vulnerability has been resolved: mmc: mmci: stm32: fix DMA API overlapping mappings warning Turning on CONFIG_DMA_API_DEBUG_SG results in the following warning: DMA-API: mmci-pl18x 48220000.mmc: cacheline tracking EEXIST, overlapping mappings

  • CVE-2024-26786HigApr 4, 2024
    affected >= 6.6.0, < 6.6.21fixed 6.6.21

    In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix iopt_access_list_id overwrite bug Syzkaller reported the following WARN_ON: WARNING: CPU: 1 PID: 4738 at drivers/iommu/iommufd/io_pagetable.c:1360 Call Trace: iommufd_access_change_ioas+0x2

  • CVE-2024-26785MedApr 4, 2024
    affected >= 6.6.0, < 6.6.55fixed 6.6.55

    In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix protection fault in iommufd_test_syz_conv_iova Syzkaller reported the following bug: general protection fault, probably for non-canonical address 0xdffffc0000000038: 0000 [#1] SMP KASAN KASAN:

  • CVE-2024-26784MedApr 4, 2024
    affected >= 6.7.0, < 6.7.9fixed 6.7.9

    In the Linux kernel, the following vulnerability has been resolved: pmdomain: arm: Fix NULL dereference on scmi_perf_domain removal On unloading of the scmi_perf_domain module got the below splat, when in the DT provided to the system under test the '#power-domain-cells' proper

  • CVE-2024-26783MedApr 4, 2024
    affected >= 5.18.0, < 6.1.140fixed 6.1.140

    In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: fix a bug calling wakeup_kswapd() with a wrong zone index With numa balancing on, when a numa system is running where a numa node doesn't have its local memory so it has no managed zones, the followi

  • CVE-2024-26782CriApr 4, 2024
    affected >= 5.6.0, < 5.10.212fixed 5.10.212

    In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the new socket has the same value as the origin

  • CVE-2024-26781MedApr 4, 2024
    affected >= 5.10.211, < 5.10.212fixed 5.10.212

    In the Linux kernel, the following vulnerability has been resolved: mptcp: fix possible deadlock in subflow diag Syzbot and Eric reported a lockdep splat in the subflow diag: WARNING: possible circular locking dependency detected 6.8.0-rc4-syzkaller-00212-g40b9385dd8e6 #

  • CVE-2024-26780MedApr 4, 2024
    affected >= 6.1.78, < 6.1.81fixed 6.1.81

    In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix task hung while purging oob_skb in GC. syzbot reported a task hung; at the same time, GC was looping infinitely in list_for_each_entry_safe() for OOB skb. [0] syzbot demonstrated that the list_fo

  • CVE-2024-26750MedApr 4, 2024
    affected >= 5.15.149, < 5.15.151fixed 5.15.151

    In the Linux kernel, the following vulnerability has been resolved: af_unix: Drop oob_skb ref before purging queue in GC. syzbot reported another task hung in __unix_gc(). [0] The current while loop assumes that all of the left candidates have oob_skb and calling kfree_skb(oo

  • CVE-2024-26746MedApr 4, 2024
    affected >= 6.4.0, < 6.6.21fixed 6.6.21

    In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Ensure safe user copy of completion record If CONFIG_HARDENED_USERCOPY is enabled, copying completion record from event log cache to user triggers a kernel bug. [ 1987.159822] usercopy: Kernel

  • CVE-2024-26745MedApr 4, 2024
    affected >= 6.0.0, < 6.1.81fixed 6.1.81

    In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: IOMMU table is not initialized for kdump over SR-IOV When kdump kernel tries to copy dump data over SR-IOV, LPAR panics due to NULL pointer exception: Kernel attempted to read user pag

  • CVE-2024-26779HigApr 3, 2024
    affected >= 4.2.0, < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix race condition on enabling fast-xmit fast-xmit must only be enabled after the sta has been uploaded to the driver, otherwise it could end up passing the not-yet-uploaded sta via drv_tx calls

  • CVE-2024-26778MedApr 3, 2024
    affected >= 2.6.12, < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Error out if pixclock equals zero The userspace program could pass any values to the driver through ioctl() interface. If the driver doesn't check the value of pixclock, it may cause divide-by-ze

  • CVE-2024-26777MedApr 3, 2024
    affected >= 2.6.12, < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: fbdev: sis: Error out if pixclock equals zero The userspace program could pass any values to the driver through ioctl() interface. If the driver doesn't check the value of pixclock, it may cause divide-by-zero

  • CVE-2024-26776MedApr 3, 2024
    affected >= 5.6.0, < 5.10.211fixed 5.10.211

    In the Linux kernel, the following vulnerability has been resolved: spi: hisi-sfc-v3xx: Return IRQ_NONE if no interrupts were detected Return IRQ_NONE from the interrupt handler when no interrupt was detected. Because an empty interrupt will cause a null pointer error: Una

  • CVE-2024-26775MedApr 3, 2024
    affected >= 5.11.0, < 5.15.189fixed 5.15.189

    In the Linux kernel, the following vulnerability has been resolved: aoe: avoid potential deadlock at set_capacity Move set_capacity() outside of the section procected by (&d->lock). To avoid possible interrupt unsafe locking scenario: CPU0 CPU1

Page 770 of 789