VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (16,579)

  • CVE-2024-26931HigMay 1, 2024
    affected >= 4.11.0, < 4.19.312fixed 4.19.312

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix command flush on cable pull System crash due to command failed to flush back to SCSI layer. BUG: unable to handle kernel NULL pointer dereference at 0000000000000000 PGD 0 P4D 0 Oops: 000

  • CVE-2024-26930HigMay 1, 2024
    affected >= 6.3.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix double free of the ha->vp_map pointer Coverity scan reported potential risk of double free of the pointer ha->vp_map. ha->vp_map was freed in qla2x00_mem_alloc(), and again freed in function

  • CVE-2023-52648MedMay 1, 2024
    affected >= 5.19.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Unmap the surface before resetting it on a plane state Switch to a new plane state requires unreferencing of all held surfaces. In the work required for mob cursors the mapped surfaces started being

  • CVE-2023-52647MedMay 1, 2024
    affected >= 6.4.0, < 6.6.24fixed 6.6.24

    In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Check whether crossbar pad is non-NULL before access When translating source to sink streams in the crossbar subdev, the driver tries to locate the remote subdev connected to the sink pad.

  • CVE-2022-48668LowApr 28, 2024
    affected >= 5.13.0, < 5.19.12fixed 5.19.12

    In the Linux kernel, the following vulnerability has been resolved: smb3: fix temporary data corruption in collapse range collapse range doesn't discard the affected cached region so can risk temporarily corrupting the file data. This fixes xfstest generic/031 I also decided t

  • CVE-2022-48667LowApr 28, 2024
    affected >= 5.13.0, < 5.19.12fixed 5.19.12

    In the Linux kernel, the following vulnerability has been resolved: smb3: fix temporary data corruption in insert range insert range doesn't discard the affected cached region so can risk temporarily corrupting file data. Also includes some minor cleanup (avoiding rereading in

  • CVE-2022-48666CriApr 28, 2024
    affected >= 5.7.0, < 5.10.223fixed 5.10.223

    In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free There are two .exit_cmd_priv implementations. Both implementations use resources associated with the SCSI host. Make sure that these resources are still available when .exit_cmd

  • CVE-2022-48665HigApr 28, 2024
    affected >= 5.19.0, < 5.19.12fixed 5.19.12

    In the Linux kernel, the following vulnerability has been resolved: exfat: fix overflow for large capacity partition Using int type for sector index, there will be overflow in a large capacity partition. For example, if storage with sector size of 512 bytes and partition capac

  • CVE-2022-48664MedApr 28, 2024
    affected >= 4.20.0, < 5.10.147fixed 5.10.147

    In the Linux kernel, the following vulnerability has been resolved: btrfs: fix hang during unmount when stopping a space reclaim worker Often when running generic/562 from fstests we can hang during unmount, resulting in a trace like this: Sep 07 11:52:00 debian9 unknown: ru

  • CVE-2022-48663MedApr 28, 2024
    affected >= 5.10.144, < 5.10.146fixed 5.10.146

    In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: fix NULL pointer dereference when removing debugfs We now remove the device's debugfs entries when unbinding the driver. This now causes a NULL-pointer dereference on module exit because the platf

  • CVE-2022-48662HigApr 28, 2024
    affected >= 5.12.0, < 5.15.72fixed 5.15.72

    In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Really move i915_gem_context.link under ref protection i915_perf assumes that it can use the i915_gem_context reference to protect its i915->gem.contexts.list iteration. However, this requires tha

  • CVE-2022-48661MedApr 28, 2024
    affected >= 5.15.0, < 5.15.71fixed 5.15.71

    In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: Fix potential resource leakage when register a chip If creation of software node fails, the locally allocated string array is left unfreed. Free it on error path.

  • CVE-2022-48660MedApr 28, 2024
    affected >= 5.9.0, < 5.10.146fixed 5.10.146

    In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: Set lineevent_state::irq after IRQ register successfully When running gpio test on nxp-ls1028 platform with below command gpiomon --num-events=3 --rising-edge gpiochip1 25 There will be a warning

  • CVE-2022-48659MedApr 28, 2024
    affected >= 2.6.22, < 4.9.330fixed 4.9.330

    In the Linux kernel, the following vulnerability has been resolved: mm/slub: fix to return errno if kmalloc() fails In create_unique_id(), kmalloc(, GFP_KERNEL) can fail due to out-of-memory, if it fails, return errno correctly rather than triggering panic via BUG_ON(); kernel

  • CVE-2022-48658HigApr 28, 2024
    affected >= 5.15.0, < 5.15.71fixed 5.15.71

    In the Linux kernel, the following vulnerability has been resolved: mm: slub: fix flush_cpu_slab()/__free_slab() invocations in task context. Commit 5a836bf6b09f ("mm: slub: move flush_cpu_slab() invocations __free_slab() invocations out of IRQ context") moved all flush_cpu_sla

  • CVE-2022-48657HigApr 28, 2024
    affected >= 5.7.0, < 5.10.150fixed 5.10.150

    In the Linux kernel, the following vulnerability has been resolved: arm64: topology: fix possible overflow in amu_fie_setup() cpufreq_get_hw_max_freq() returns max frequency in kHz as *unsigned int*, while freq_inv_set_max_ratio() gets passed this frequency in Hz as 'u64'. Mult

  • CVE-2022-48656MedApr 28, 2024
    affected >= 5.6.0, < 5.10.146fixed 5.10.146

    In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma-private: Fix refcount leak bug in of_xudma_dev_get() We should call of_node_put() for the reference returned by of_parse_phandle() in fail path or when it is not used anymore. Here we onl

  • CVE-2022-48655HigApr 28, 2024
    affected >= 5.4.0, < 5.4.277fixed 5.4.277

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface can potentially lead to out-o

  • CVE-2022-48654HigApr 28, 2024
    affected >= 5.2.0, < 5.4.215fixed 5.4.215

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find() nf_osf_find() incorrectly returns true on mismatch, this leads to copying uninitialized memory area in nft_osf which can be used to leak stale

  • CVE-2022-48653MedApr 28, 2024
    affected >= 5.14.0, < 5.15.71fixed 5.15.71

    In the Linux kernel, the following vulnerability has been resolved: ice: Don't double unplug aux on peer initiated reset In the IDC callback that is accessed when the aux drivers request a reset, the function to unplug the aux devices is called. This function is also called in

Page 802 of 829