VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,762)

  • CVE-2024-26731MedApr 3, 2024
    affected < 6.1.80fixed 6.1.80

    In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix NULL pointer dereference in sk_psock_verdict_data_ready() syzbot reported the following NULL pointer dereference issue [1]: BUG: kernel NULL pointer dereference, address: 0000000000000000

  • CVE-2024-26730HigApr 3, 2024
    affected >= 6.6.0, < 6.6.19fixed 6.6.19

    In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775) Fix access to temperature configuration registers The number of temperature configuration registers does not always match the total number of temperature registers. This can result in access er

  • CVE-2024-26729MedApr 3, 2024
    affected >= 6.7.0, < 6.7.7fixed 6.7.7

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential null pointer dereference in dc_dmub_srv Fixes potential null pointer dereference warnings in the dc_dmub_srv_cmd_list_queue_execute() and dc_dmub_srv_is_hw_pwr_up() functions. In

  • CVE-2024-26728HigApr 3, 2024
    affected >= 6.7.0, < 6.7.7fixed 6.7.7

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix null-pointer dereference on edid reading Use i2c adapter when there isn't aux_mode in dc_link to fix a null-pointer derefence that happens when running igt@kms_force_connector_basic in a sy

  • CVE-2023-52641MedApr 3, 2024
    affected >= 5.15.0, < 5.15.150fixed 5.15.150

    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame() It is preferable to exit through the out: label because internal debugging functions are located there.

  • CVE-2023-52640HigApr 3, 2024
    affected >= 5.15.0, < 5.15.150fixed 5.15.150

    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix oob in ntfs_listxattr The length of name cannot exceed the space occupied by ea.

  • CVE-2024-26727MedApr 3, 2024
    affected >= 5.9.0, < 5.10.210fixed 5.10.210

    In the Linux kernel, the following vulnerability has been resolved: btrfs: do not ASSERT() if the newly created subvolume already got read [BUG] There is a syzbot crash, triggered by the ASSERT() during subvolume creation: assertion failed: !anon_dev, in fs/btrfs/disk-io.c:13

  • CVE-2024-26726MedApr 3, 2024
    affected >= 3.12.0, < 5.15.187fixed 5.15.187

    In the Linux kernel, the following vulnerability has been resolved: btrfs: don't drop extent_map for free space inode on write error While running the CI for an unrelated change I hit the following panic with generic/648 on btrfs_holes_spacecache. assertion failed: block_start

  • CVE-2024-26725MedApr 3, 2024
    affected >= 6.7.0, < 6.7.6fixed 6.7.6

    In the Linux kernel, the following vulnerability has been resolved: dpll: fix possible deadlock during netlink dump operation Recently, I've been hitting following deadlock warning during dpll pin dump: [52804.637962] ====================================================== [528

  • CVE-2024-26724HigApr 3, 2024
    affected >= 6.7.0, < 6.7.6fixed 6.7.6

    In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DPLL, Fix possible use after free after delayed work timer triggers I managed to hit following use after free warning recently: [ 2169.711665] ========================================================

  • CVE-2024-26723HigApr 3, 2024
    affected >= 6.1.0, < 6.1.79fixed 6.1.79

    In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix crash when adding interface under a lag There is a crash when adding one of the lan966x interfaces under a lag interface. The issue can be reproduced like this: ip link add name bond0 type bond mii

  • CVE-2024-26722MedApr 3, 2024
    affected < 4.19.307fixed 4.19.307

    In the Linux kernel, the following vulnerability has been resolved: ASoC: rt5645: Fix deadlock in rt5645_jack_detect_work() There is a path in rt5645_jack_detect_work(), where rt5645->jd_mutex is left locked forever. That may lead to deadlock when rt5645_jack_detect_work() is c

  • CVE-2024-26721MedApr 3, 2024
    affected >= 6.7.0, < 6.7.6fixed 6.7.6

    In the Linux kernel, the following vulnerability has been resolved: drm/i915/dsc: Fix the macro that calculates DSCC_/DSCA_ PPS reg address Commit bd077259d0a9 ("drm/i915/vdsc: Add function to read any PPS register") defines a new macro to calculate the DSC PPS register address

  • CVE-2024-26719MedApr 3, 2024
    affected >= 6.2.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: nouveau: offload fence uevents work to workqueue This should break the deadlock between the fctx lock and the irq lock. This offloads the processing off the work from the irq into a workqueue.

  • CVE-2024-26718HigApr 3, 2024
    affected >= 5.9.0, < 5.15.169fixed 5.15.169

    In the Linux kernel, the following vulnerability has been resolved: dm-crypt, dm-verity: disable tasklets Tasklets have an inherent problem with memory corruption. The function tasklet_action_common calls tasklet_trylock, then it calls the tasklet callback and then it calls tas

  • CVE-2024-26717MedApr 3, 2024
    affected >= 5.12.0, < 5.15.149fixed 5.15.149

    In the Linux kernel, the following vulnerability has been resolved: HID: i2c-hid-of: fix NULL-deref on failed power up A while back the I2C HID implementation was split in an ACPI and OF part, but the new OF driver never initialises the client pointer which is dereferenced on p

  • CVE-2024-26716MedApr 3, 2024
    affected >= 6.5.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: usb: core: Prevent null pointer dereference in update_port_device_state Currently, the function update_port_device_state gets the usb_hub from udev->parent by calling usb_hub_to_struct_hub. However, in case the

  • CVE-2024-26715MedApr 3, 2024
    affected >= 4.6.0, < 5.15.149fixed 5.15.149

    In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Fix NULL pointer dereference in dwc3_gadget_suspend In current scenario if Plug-out and Plug-In performed continuously there could be a chance while checking for dwc->gadget_driver in dwc3_ga

  • CVE-2024-26714MedApr 3, 2024
    affected >= 5.15.0, < 6.1.79fixed 6.1.79

    In the Linux kernel, the following vulnerability has been resolved: interconnect: qcom: sc8180x: Mark CO0 BCM keepalive The CO0 BCM needs to be up at all times, otherwise some hardware (like the UFS controller) loses its connection to the rest of the SoC, resulting in a hang of

  • CVE-2024-26712HigApr 3, 2024
    affected >= 5.4.0, < 5.10.210fixed 5.10.210

    In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Fix addr error caused by page alignment In kasan_init_region, when k_start is not page aligned, at the begin of for loop, k_cur = k_start & PAGE_MASK is less than k_start, and then `va = block +

Page 773 of 789