VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (15,762)

  • CVE-2024-26711MedApr 3, 2024
    affected >= 6.2.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad4130: zero-initialize clock init data The clk_init_data struct does not have all its members initialized, causing issues when trying to expose the internal clock on the CLK pin. Fix this by zero-in

  • CVE-2024-26710MedApr 3, 2024
    affected >= 6.1.75, < 6.1.76fixed 6.1.76

    In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Limit KASAN thread size increase to 32KB KASAN is seen to increase stack usage, to the point that it was reported to lead to stack overflow on some 32-bit machines (see link). To avoid overflows

  • CVE-2024-26709MedApr 3, 2024
    affected >= 6.7.0, < 6.7.6fixed 6.7.6

    In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the missing iommu_group_put() during platform domain attach The function spapr_tce_platform_iommu_attach_dev() is missing to call iommu_group_put() when the domain is already set. This refcou

  • CVE-2024-26708MedApr 3, 2024
    affected >= 6.2.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: mptcp: really cope with fastopen race Fastopen and PM-trigger subflow shutdown can race, as reported by syzkaller. In my first attempt to close such race, I missed the fact that the subflow status can change a

  • CVE-2024-26707MedApr 3, 2024
    affected >= 5.9.0, < 5.10.210fixed 5.10.210

    In the Linux kernel, the following vulnerability has been resolved: net: hsr: remove WARN_ONCE() in send_hsr_supervision_frame() Syzkaller reported [1] hitting a warning after failing to allocate resources for skb in hsr_init_skb(). Since a WARN_ONCE() call will not help much i

  • CVE-2024-26706HigApr 3, 2024
    affected >= 4.11.0, < 6.1.79fixed 6.1.79

    In the Linux kernel, the following vulnerability has been resolved: parisc: Fix random data corruption from exception handler The current exception handler implementation, which assists when accessing user space memory, may exhibit random data corruption if the compiler decides

  • CVE-2024-26705MedApr 3, 2024
    affected >= 6.6.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: parisc: BTLB: Fix crash when setting up BTLB at CPU bringup When using hotplug and bringing up a 32-bit CPU, ask the firmware about the BTLB information to set up the static (block) TLB entries. For that write

  • CVE-2024-26704HigApr 3, 2024
    affected >= 3.18.0, < 4.19.307fixed 4.19.307

    In the Linux kernel, the following vulnerability has been resolved: ext4: fix double-free of blocks due to wrong extents moved_len In ext4_move_extents(), moved_len is only updated when all moves are successfully executed, and only discards orig_inode and donor_inode preallocat

  • CVE-2024-26703MedApr 3, 2024
    affected >= 6.5.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: tracing/timerlat: Move hrtimer_init to timerlat_fd open() Currently, the timerlat's hrtimer is initialized at the first read of timerlat_fd, and destroyed at close(). It works, but it causes an error if the use

  • CVE-2024-26702MedApr 3, 2024
    affected >= 5.0.0, < 5.4.269fixed 5.4.269

    In the Linux kernel, the following vulnerability has been resolved: iio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRC Recently, we encounter kernel crash in function rm3100_common_probe caused by out of bound access of array rm3100_samp_rates

  • CVE-2024-26700MedApr 3, 2024
    affected >= 4.15.0, < 6.1.82fixed 6.1.82

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix MST Null Ptr for RV The change try to fix below error specific to RV platform: BUG: kernel NULL pointer dereference, address: 0000000000000008 PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP NOPTI

  • CVE-2024-26699HigApr 3, 2024
    affected >= 6.7.0, < 6.7.6fixed 6.7.6

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr [Why] There is a potential memory access violation while iterating through array of dcn35 clks. [How] Limit iteration per array size.

  • CVE-2024-26698MedApr 3, 2024
    affected >= 5.8.0, < 5.10.210fixed 5.10.210

    In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Fix race condition between netvsc_probe and netvsc_remove In commit ac5047671758 ("hv_netvsc: Disable NAPI before closing the VMBus channel"), napi_disable was getting called for all channels, includ

  • CVE-2024-26697HigApr 3, 2024
    affected >= 2.6.30, < 4.19.307fixed 4.19.307

    In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix data corruption in dsync block recovery for small block sizes The helper function nilfs_recovery_copy_block() of nilfs_recovery_dsync_blocks(), which recovers data from logs created by data sync wri

  • CVE-2024-26696MedApr 3, 2024
    affected >= 3.9.0, < 4.19.307fixed 4.19.307

    In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix hang in nilfs_lookup_dirty_data_buffers() Syzbot reported a hang issue in migrate_pages_batch() called by mbind() and nilfs_lookup_dirty_data_buffers() called in the log writer of nilfs2. While mig

  • CVE-2024-26695MedApr 3, 2024
    affected < 5.10.210fixed 5.10.210

    In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix null pointer dereference in __sev_platform_shutdown_locked The SEV platform device can be shutdown with a null psp_master, e.g., using DEBUG_TEST_DRIVER_REMOVE. Found using KASAN: [ 137.148

  • CVE-2024-26694HigApr 3, 2024
    affected >= 6.4.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix double-free bug The storage for the TLV PC register data wasn't done like all the other storage in the drv->fw area, which is cleared at the end of deallocation. Therefore, the freeing must a

  • CVE-2024-26693MedApr 3, 2024
    affected >= 6.4.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix a crash when we run out of stations A DoS tool that injects loads of authentication frames made our AP crash. The iwl_mvm_is_dup() function couldn't find the per-queue dup_data which was

  • CVE-2024-26692HigApr 3, 2024
    affected >= 6.3.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard maximum write size negotiated The conversion to netfs in the 6.3 kernel caused a regression when maximum write size is set by the server to an unexpected value wh

  • CVE-2024-26691MedApr 3, 2024
    affected >= 3.11.0, < 6.6.18fixed 6.6.18

    In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix circular locking dependency The rule inside kvm enforces that the vcpu->mutex is taken *inside* kvm->lock. The rule is violated by the pkvm_create_hyp_vm() which acquires the kvm->lock while alr

Page 774 of 789