VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (16,579)

  • CVE-2024-26771MedApr 3, 2024
    affected >= 4.4.0, < 5.10.211fixed 5.10.211

    In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: edma: Add some null pointer checks to the edma_probe devm_kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Ensure the allocation was successful by che

  • CVE-2024-26770MedApr 3, 2024
    affected >= 6.5.0, < 6.6.19fixed 6.6.19

    In the Linux kernel, the following vulnerability has been resolved: HID: nvidia-shield: Add missing null pointer checks to LED initialization devm_kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Ensure the allocation was successful

  • CVE-2024-26769HigApr 3, 2024
    affected >= 4.8.0, < 5.15.150fixed 5.15.150

    In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try to flush the nvmet_wq nested. Avoid this by deadlock by deferring the put work in

  • CVE-2024-26768HigApr 3, 2024
    affected >= 5.19.0, < 6.6.19fixed 6.6.19

    In the Linux kernel, the following vulnerability has been resolved: LoongArch: Change acpi_core_pic[NR_CPUS] to acpi_core_pic[MAX_CORE_PIC] With default config, the value of NR_CPUS is 64. When HW platform has more then 64 cpus, system will crash on these platforms. MAX_CORE_PI

  • CVE-2024-26767MedApr 3, 2024
    affected >= 6.1.0, < 6.1.130fixed 6.1.130

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fixed integer types and null check locations [why]: issues fixed: - comparison with wider integer type in loop condition which can cause infinite loops - pointer dereference before null check

  • CVE-2024-26766HigApr 3, 2024
    affected < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `descs` array to overflow. This reults in further crashes easily reproducible by `

  • CVE-2024-26765MedApr 3, 2024
    affected >= 5.19.0, < 6.1.80fixed 6.1.80

    In the Linux kernel, the following vulnerability has been resolved: LoongArch: Disable IRQ before init_fn() for nonboot CPUs Disable IRQ before init_fn() for nonboot CPUs when hotplug, in order to silence such warnings (and also avoid potential errors due to unexpected interrup

  • CVE-2024-26764LowApr 3, 2024
    affected >= 4.1.0, < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: fs/aio: Restrict kiocb_set_cancel_fn() to I/O submitted via libaio If kiocb_set_cancel_fn() is called for I/O submitted via io_uring, the following kernel warning appears: WARNING: CPU: 3 PID: 368 at fs/aio.c:

  • CVE-2024-26763HigApr 3, 2024
    affected >= 4.12.0, < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: dm-crypt: don't modify the data when using authenticated encryption It was said that authenticated encryption could produce invalid tag when the data that is being encrypted is modified [1]. So, fix this proble

  • CVE-2024-26762HigApr 3, 2024
    affected >= 6.7.0, < 6.7.7fixed 6.7.7

    In the Linux kernel, the following vulnerability has been resolved: cxl/pci: Skip to handle RAS errors if CXL.mem device is detached The PCI AER model is an awkward fit for CXL error handling. While the expectation is that a PCI device can escalate to link reset to recover from

  • CVE-2024-26761MedApr 3, 2024
    affected >= 5.19.0, < 6.1.80fixed 6.1.80

    In the Linux kernel, the following vulnerability has been resolved: cxl/pci: Fix disabling memory if DVSEC CXL Range does not match a CFMWS window The Linux CXL subsystem is built on the assumption that HPA == SPA. That is, the host physical address (HPA) the HDM decoder regist

  • CVE-2024-26760CriApr 3, 2024
    affected >= 5.19.0, < 6.1.80fixed 6.1.80

    In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc into a simple kmalloc wrapper"), a bio allocated by bio_kmalloc() must be freed by bio_uninit() and kfree().

  • CVE-2024-26759HigApr 3, 2024
    affected >= 4.15.0, < 6.1.80fixed 6.1.80

    In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix race when skipping swapcache When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads swapin the same entry at the same time, they get different pages (A, B). Before one thread (T0)

  • CVE-2024-26758MedApr 3, 2024
    affected >= 3.0.0, < 6.7.7fixed 6.7.7

    In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore suspended array in md_check_recovery() mddev_suspend() never stop sync_thread, hence it doesn't make sense to ignore suspended array in md_check_recovery(), which might cause sync_thread can't

  • CVE-2024-26757MedApr 3, 2024
    affected >= 4.8.0, < 6.7.7fixed 6.7.7

    In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore read-only array in md_check_recovery() Usually if the array is not read-write, md_check_recovery() won't register new sync_thread in the first place. And if the array is read-write and sync_thr

  • CVE-2024-26756MedApr 3, 2024
    affected >= 2.6.17, < 6.7.7fixed 6.7.7

    In the Linux kernel, the following vulnerability has been resolved: md: Don't register sync_thread for reshape directly Currently, if reshape is interrupted, then reassemble the array will register sync_thread directly from pers->run(), in this case 'MD_RECOVERY_RUNNING' is set

  • CVE-2024-26755MedApr 3, 2024
    affected >= 6.7.0, < 6.7.7fixed 6.7.7

    In the Linux kernel, the following vulnerability has been resolved: md: Don't suspend the array for interrupted reshape md_start_sync() will suspend the array if there are spares that can be added or removed from conf, however, if reshape is still in progress, this won't happen

  • CVE-2024-26754HigApr 3, 2024
    affected >= 4.7.0, < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: gtp: fix use-after-free and null-ptr-deref in gtp_genl_dump_pdp() The gtp_net_ops pernet operations structure for the subsystem must be registered before registering the generic netlink family. Syzkaller hit '

  • CVE-2024-26753HigApr 3, 2024
    affected < 5.10.212fixed 5.10.212

    In the Linux kernel, the following vulnerability has been resolved: crypto: virtio/akcipher - Fix stack overflow on memcpy sizeof(struct virtio_crypto_akcipher_session_para) is less than sizeof(struct virtio_crypto_op_ctrl_req::u), copying more bytes from stack variable leads s

  • CVE-2024-26752MedApr 3, 2024
    affected < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: l2tp: pass correct message length to ip6_append_data l2tp_ip6_sendmsg needs to avoid accounting for the transport header twice when splicing more data into an already partially-occupied skbuff. To manage this,

Page 812 of 829