VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (16,579)

  • CVE-2022-48674HigMay 3, 2024
    affected >= 5.0.0, < 5.15.68fixed 5.15.68

    In the Linux kernel, the following vulnerability has been resolved: erofs: fix pcluster use-after-free on UP platforms During stress testing with CONFIG_SMP disabled, KASAN reports as below: ================================================================== BUG: KASAN: use-aft

  • CVE-2022-48673CriMay 3, 2024
    affected >= 4.11.0, < 5.19.9fixed 5.19.9

    In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix possible access to freed memory in link clear After modifying the QP to the Error state, all RX WR would be completed with WC in IB_WC_WR_FLUSH_ERR status. Current implementation does not wait for

  • CVE-2022-48672HigMay 3, 2024
    affected >= 4.7.0, < 4.14.295fixed 4.14.295

    In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") forgot to fix up the depth check in the loop body in unflatten_dt_nodes() which m

  • CVE-2022-48671MedMay 3, 2024
    affected >= 5.4.213, < 5.4.215fixed 5.4.215

    In the Linux kernel, the following vulnerability has been resolved: cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all() syzbot is hitting percpu_rwsem_assert_held(&cpu_hotplug_lock) warning at cpuset_attach() [1], for commit 4f7e7236435ca0ab ("cgroup: Fix threadgro

  • CVE-2022-48670HigMay 3, 2024
    affected >= 5.18.0, < 5.19.10fixed 5.19.10

    In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to be decremented and .release callback will b

  • CVE-2024-27392HigMay 1, 2024
    affected >= 6.8.0, < 6.8.2fixed 6.8.2

    In the Linux kernel, the following vulnerability has been resolved: nvme: host: fix double-free of struct nvme_id_ns in ns_update_nuse() When nvme_identify_ns() fails, it frees the pointer to the struct nvme_id_ns before it returns. However, ns_update_nuse() calls kfree() for t

  • CVE-2024-27391MedMay 1, 2024
    affected >= 5.17.0, < 6.1.83fixed 6.1.83

    In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: do not realloc workqueue everytime an interface is added Commit 09ed8bfc5215 ("wilc1000: Rename workqueue from "WILC_wq" to "NETDEV-wq"") moved workqueue creation in wilc_netdev_ifc_init in orde

  • CVE-2024-27390MedMay 1, 2024
    affected >= 5.13.0, < 5.15.153fixed 5.15.153

    In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: remove one synchronize_net() barrier in ipv6_mc_down() As discussed in the past (commit 2d3916f31891 ("ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report()")) I think the synchronize

  • CVE-2024-27389HigMay 1, 2024
    affected >= 5.8.0, < 5.15.209fixed 5.15.209

    In the Linux kernel, the following vulnerability has been resolved: pstore: inode: Only d_invalidate() is needed Unloading a modular pstore backend with records in pstorefs would trigger the dput() double-drop warning: WARNING: CPU: 0 PID: 2569 at fs/dcache.c:762 dput.part.0

  • CVE-2024-27388CriMay 1, 2024
    affected >= 3.10.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some memleaks in gssx_dec_option_array The creds and oa->data need to be freed in the error-handling paths after their allocation. So this patch add these deallocations in the corresponding paths.

  • CVE-2024-27080MedMay 1, 2024
    affected < 6.6.26fixed 6.6.26

    In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race when detecting delalloc ranges during fiemap For fiemap we recently stopped locking the target extent range for the whole duration of the fiemap call, in order to avoid a deadlock in a scenario

  • CVE-2024-27079MedMay 1, 2024
    affected >= 5.18.0, < 6.8.2fixed 6.8.2

    In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix NULL domain on device release In the kdump kernel, the IOMMU operates in deferred_attach mode. In this mode, info->domain may not yet be assigned by the time the release_device function is calle

  • CVE-2024-27078MedMay 1, 2024
    affected >= 3.18.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: media: v4l2-tpg: fix some memleaks in tpg_alloc In tpg_alloc, resources should be deallocated in each and every error-handling paths, since they are allocated in for statements. Otherwise there would be memleak

  • CVE-2024-27077MedMay 1, 2024
    affected >= 4.19.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: media: v4l2-mem2mem: fix a memleak in v4l2_m2m_register_entity The entity->name (i.e. name) is allocated in v4l2_m2m_register_entity but isn't freed in its following error-handling paths. This patch adds such d

  • CVE-2024-27076MedMay 1, 2024
    affected >= 5.4.0, < 5.4.273fixed 5.4.273

    In the Linux kernel, the following vulnerability has been resolved: media: imx: csc/scaler: fix v4l2_ctrl_handler memory leak Free the memory allocated in v4l2_ctrl_handler_init on release.

  • CVE-2024-27075HigMay 1, 2024
    affected >= 4.16.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: avoid stack overflow warnings with clang A previous patch worked around a KASAN issue in stv0367, now a similar problem showed up with clang: drivers/media/dvb-frontends/stv0367.c:1222:12

  • CVE-2024-27074MedMay 1, 2024
    affected >= 3.10.0, < 4.19.311fixed 4.19.311

    In the Linux kernel, the following vulnerability has been resolved: media: go7007: fix a memleak in go7007_load_encoder In go7007_load_encoder, bounce(i.e. go->boot_fw), is allocated without a deallocation thereafter. After the following call chain: saa7134_go7007_init |-> g

  • CVE-2024-27073HigMay 1, 2024
    affected >= 2.6.12, < 5.4.273fixed 5.4.273

    In the Linux kernel, the following vulnerability has been resolved: media: ttpci: fix two memleaks in budget_av_attach When saa7146_register_device and saa7146_vv_init fails, budget_av_attach should free the resources it allocates, like the error-handling of ttpci_budget_init d

  • CVE-2024-27072MedMay 1, 2024
    affected >= 3.11.0, < 5.10.227fixed 5.10.227

    In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Remove useless locks in usbtv_video_free() Remove locks calls in usbtv_video_free() because are useless and may led to a deadlock as reported here: https://syzkaller.appspot.com/x/bisect.txt?x=166

  • CVE-2024-27071MedMay 1, 2024
    affected >= 6.8.0, < 6.8.2fixed 6.8.2

    In the Linux kernel, the following vulnerability has been resolved: backlight: hx8357: Fix potential NULL pointer dereference The "im" pins are optional. Add missing check in the hx8357_probe().

Page 794 of 829