VYPR

linux package

kernel

pkg:linux/kernel

Vulnerabilities (16,579)

  • CVE-2024-26751MedApr 3, 2024
    affected >= 4.15.0, < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: ARM: ep93xx: Add terminator to gpiod_lookup_table Without the terminator, if a con_id is passed to gpio_find() that does not exist in the lookup table the function will not stop looping correctly, and eventuall

  • CVE-2024-26749HigApr 3, 2024
    affected >= 5.4.0, < 5.4.270fixed 5.4.270

    In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: fixed memory use after free at cdns3_gadget_ep_disable() ... cdns3_gadget_ep_free_request(&priv_ep->endpoint, &priv_req->request); list_del_init(&priv_req->list); ... 'priv_req' actually fr

  • CVE-2024-26748HigApr 3, 2024
    affected >= 5.4.0, < 5.4.270fixed 5.4.270

    In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: fix memory double free when handle zero packet 829 if (request->complete) { 830 spin_unlock(&priv_dev->lock); 831 usb_gadget_giveback_request(&priv_ep->endpoint, 832

  • CVE-2024-26747MedApr 3, 2024
    affected >= 4.19.0, < 5.10.211fixed 5.10.211

    In the Linux kernel, the following vulnerability has been resolved: usb: roles: fix NULL pointer issue when put module's reference In current design, usb role class driver will get usb_role_switch parent's module reference after the user get usb_role_switch device and put the r

  • CVE-2024-26744MedApr 3, 2024
    affected >= 3.3.0, < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Support specifying the srpt_service_guid parameter Make loading ib_srpt with this parameter set work. The current behavior is that setting that parameter while loading the ib_srpt kernel module trigg

  • CVE-2024-26743MedApr 3, 2024
    affected >= 4.11.0, < 5.10.211fixed 5.10.211

    In the Linux kernel, the following vulnerability has been resolved: RDMA/qedr: Fix qedr_create_user_qp error flow Avoid the following warning by making sure to free the allocated resources in case that qedr_init_user_queue() fail. -----------[ cut here ]----------- WARNING: CP

  • CVE-2024-26742HigApr 3, 2024
    affected >= 6.0.0, < 6.1.80fixed 6.1.80

    In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix disable_managed_interrupts Correct blk-mq registration issue with module parameter disable_managed_interrupts enabled. When we turn off the default PCI_IRQ_AFFINITY flag, the driver needs t

  • CVE-2024-26741MedApr 3, 2024
    affected >= 6.1.0, < 6.1.80fixed 6.1.80

    In the Linux kernel, the following vulnerability has been resolved: dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished(). syzkaller reported a warning [0] in inet_csk_destroy_sock() with no repro. WARN_ON(inet_sk(sk)->inet_num && !inet_csk(sk)->ics

  • CVE-2024-26740MedApr 3, 2024
    affected >= 4.10.0, < 6.6.19fixed 6.6.19

    In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: use the backlog for mirred ingress The test Davide added in commit ca22da2fbd69 ("act_mirred: use the backlog for nested calls to mirred ingress") hangs our testing VMs every 10 or so run

  • CVE-2024-26739HigApr 3, 2024
    affected >= 4.19.0, < 5.10.238fixed 5.10.238

    In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the skb, and haven't called tcf_mirred_forward(), yet, we need to tell the core to drop the skb by setting the retcod

  • CVE-2024-26738MedApr 3, 2024
    affected >= 6.4.0, < 6.6.19fixed 6.6.19

    In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: DLPAR add doesn't completely initialize pci_controller When a PCI device is dynamically added, the kernel oopses with a NULL pointer dereference: BUG: Kernel NULL pointer dereference o

  • CVE-2024-26737HigApr 3, 2024
    affected >= 5.15.0, < 5.15.150fixed 5.15.150

    In the Linux kernel, the following vulnerability has been resolved: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel The following race is possible between bpf_timer_cancel_and_free and bpf_timer_cancel. It will lead a UAF on the timer->timer. bpf_timer_c

  • CVE-2024-26736HigApr 3, 2024
    affected >= 4.15.0, < 5.4.270fixed 5.4.270

    In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow. Found by Linux Verification Center (linuxtesti

  • CVE-2024-26735MedApr 3, 2024
    affected >= 4.10.0, < 4.19.308fixed 4.19.308

    In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix possible use-after-free and null-ptr-deref The pernet operations structure for the subsystem must be registered before registering the generic netlink family.

  • CVE-2024-26734HigApr 3, 2024
    affected >= 6.3.0, < 6.6.19fixed 6.6.19

    In the Linux kernel, the following vulnerability has been resolved: devlink: fix possible use-after-free and memory leaks in devlink_init() The pernet operations structure for the subsystem must be registered before registering the generic netlink family. Make an unregister in

  • CVE-2024-26733MedApr 3, 2024
    affected >= 2.6.12, < 5.10.211fixed 5.10.211

    In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour entry and copies neigh->ha to struct arpr

  • CVE-2024-26732MedApr 3, 2024
    affected >= 6.7.0, < 6.7.7fixed 6.7.7

    In the Linux kernel, the following vulnerability has been resolved: net: implement lockless setsockopt(SO_PEEK_OFF) syzbot reported a lockdep violation [1] involving af_unix support of SO_PEEK_OFF. Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket sk_peek_o

  • CVE-2024-26731MedApr 3, 2024
    affected < 6.1.80fixed 6.1.80

    In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix NULL pointer dereference in sk_psock_verdict_data_ready() syzbot reported the following NULL pointer dereference issue [1]: BUG: kernel NULL pointer dereference, address: 0000000000000000

  • CVE-2024-26730HigApr 3, 2024
    affected >= 6.6.0, < 6.6.19fixed 6.6.19

    In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775) Fix access to temperature configuration registers The number of temperature configuration registers does not always match the total number of temperature registers. This can result in access er

  • CVE-2024-26729MedApr 3, 2024
    affected >= 6.7.0, < 6.7.7fixed 6.7.7

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential null pointer dereference in dc_dmub_srv Fixes potential null pointer dereference warnings in the dc_dmub_srv_cmd_list_queue_execute() and dc_dmub_srv_is_hw_pwr_up() functions. In

Page 813 of 829