VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (16,579)

  • CVE-2024-26951HigMay 1, 2024
    affected >= 5.6.0, < 5.10.215fixed 5.10.215

    In the Linux kernel, the following vulnerability has been resolved: wireguard: netlink: check for dangling peer via is_dead instead of empty list If all peers are removed via wg_peer_remove_all(), rather than setting peer_list to empty, the peer is added to a temporary list wit

  • CVE-2024-26950HigMay 1, 2024
    affected >= 5.6.0, < 5.10.215fixed 5.10.215

    In the Linux kernel, the following vulnerability has been resolved: wireguard: netlink: access device through ctx instead of peer The previous commit fixed a bug that led to a NULL peer->device being dereferenced. It's actually easier and faster performance-wise to instead get

  • CVE-2024-26949MedMay 1, 2024
    affected < 6.7.12fixed 6.7.12

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/pm: Fix NULL pointer dereference when get power limit Because powerplay_table initialization is skipped under sriov case, We check and set default lower and upper OD value if powerplay_table is NULL.

  • CVE-2024-26948MedMay 1, 2024
    affected >= 4.15.0, < 6.6.158fixed 6.6.158

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add a dc_state NULL check in dc_state_release [How] Check wheather state is NULL before releasing it.

  • CVE-2024-26947MedMay 1, 2024
    affected >= 5.14.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses Since commit a4d5613c4dc6 ("arm: extend pfn_valid to take into account freed memory map alignment") changes the semantics of pfn_valid

  • CVE-2024-26946MedMay 1, 2024
    affected >= 5.18.0, < 6.1.84fixed 6.1.84

    In the Linux kernel, the following vulnerability has been resolved: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address Read from an unsafe address with copy_from_kernel_nofault() in arch_adjust_kprobe_addr() because this function is used before checking the

  • CVE-2024-26945HigMay 1, 2024
    affected >= 6.8.0, < 6.8.3fixed 6.8.3

    In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix nr_cpus < nr_iaa case If nr_cpus < nr_iaa, the calculated cpus_per_iaa will be 0, which causes a divide-by-0 in rebalance_wq_table(). Make sure cpus_per_iaa is 1 in that case, and also in the

  • CVE-2024-26944HigMay 1, 2024
    affected >= 5.18.0, < 6.8.3fixed 6.8.3

    In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix use-after-free in do_zone_finish() Shinichiro reported the following use-after-free triggered by the device replace operation in fstests btrfs/070. BTRFS info (device nullb1): scrub: finishe

  • CVE-2024-26943MedMay 1, 2024
    affected >= 6.1.0, < 6.1.84fixed 6.1.84

    In the Linux kernel, the following vulnerability has been resolved: nouveau/dmem: handle kcalloc() allocation failure The kcalloc() in nouveau_dmem_evict_chunk() will return null if the physical memory has run out. As a result, if we dereference src_pfns, dst_pfns or dma_addrs,

  • CVE-2024-26942MedMay 1, 2024
    affected >= 6.8.0, < 6.8.3fixed 6.8.3

    In the Linux kernel, the following vulnerability has been resolved: net: phy: qcom: at803x: fix kernel panic with at8031_probe On reworking and splitting the at803x driver, in splitting function of at803x PHYs it was added a NULL dereference bug where priv is referenced before

  • CVE-2024-26941MedMay 1, 2024
    affected >= 6.8.0, < 6.8.3fixed 6.8.3

    In the Linux kernel, the following vulnerability has been resolved: drm/dp: Fix divide-by-zero regression on DP MST unplug with nouveau Fix a regression when using nouveau and unplugging a StarTech MSTDP122DP DisplayPort 1.2 MST hub (the same regression does not appear when usi

  • CVE-2024-26940MedMay 1, 2024
    affected >= 5.19.0, < 6.1.84fixed 6.1.84

    In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed The driver creates /sys/kernel/debug/dri/0/mob_ttm even when the corresponding ttm_resource_manager is not allocated. This leads to a crash w

  • CVE-2024-26939HigMay 1, 2024
    affected >= 5.19.0, < 6.1.88fixed 6.1.88

    In the Linux kernel, the following vulnerability has been resolved: drm/i915/vma: Fix UAF on destroy against retire race Object debugging tools were sporadically reporting illegal attempts to free a still active i915 VMA object when parking a GT believed to be idle. [161.35944

  • CVE-2024-26938MedMay 1, 2024
    affected >= 6.5.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: Tolerate devdata==NULL in intel_bios_encoder_supports_dp_dual_mode() If we have no VBT, or the VBT didn't declare the encoder in question, we won't have the 'devdata' for the encoder. Instead of

  • CVE-2024-26937MedMay 1, 2024
    affected >= 5.4.0, < 5.4.274fixed 5.4.274

    In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Reset queue_priority_hint on parking Originally, with strict in order execution, we could complete execution only when the queue was empty. Preempt-to-busy allows replacement of an active request t

  • CVE-2024-26936HigMay 1, 2024
    affected >= 5.15.0, < 5.15.159fixed 5.15.159

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate request buffer size in smb2_allocate_rsp_buf() The response buffer should be allocated in smb2_allocate_rsp_buf before validating request. But the fields in payload as well as smb2 header is use

  • CVE-2024-26935MedMay 1, 2024
    affected < 5.4.274fixed 5.4.274

    In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix unremoved procfs host directory regression Commit fc663711b944 ("scsi: core: Remove the /proc/scsi/${proc_name} directory earlier") fixed a bug related to modules loading/unloading, by adding a

  • CVE-2024-26934HigMay 1, 2024
    affected >= 4.4.0, < 4.19.312fixed 4.19.312

    In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix deadlock in usb_deauthorize_interface() Among the attribute file callback routines in drivers/usb/core/sysfs.c, the interface_authorized_store() function is the only one which acquires a device l

  • CVE-2024-26933HigMay 1, 2024
    affected >= 6.0.0, < 6.1.84fixed 6.1.84

    In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix deadlock in port "disable" sysfs attribute The show and store callback routines for the "disable" sysfs attribute file in port.c acquire the device lock for the port's parent hub device. This ca

  • CVE-2024-26932HigMay 1, 2024
    affected >= 6.8.0, < 6.8.3fixed 6.8.3

    In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: fix double-free issue in tcpm_port_unregister_pd() When unregister pd capabilitie in tcpm, KASAN will capture below double -free issue. The root cause is the same capabilitiy will be kfreed tw

Page 801 of 829