VYPR

rpm package

almalinux/kernel-tools-libs-devel

pkg:rpm/almalinux/kernel-tools-libs-devel

Vulnerabilities (1,491)

  • CVE-2021-27364HigMar 7, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.

  • CVE-2021-27363MedMar 7, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via t

  • CVE-2021-20194HigFeb 23, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BP

  • CVE-2020-24504MedFeb 17, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-24503MedFeb 17, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-24502MedFeb 17, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may allow an authenticated user to potentially enable a denial of service via local access.

  • CVE-2020-12362HigFeb 17, 2021
    affected < 4.18.0-305.el8fixed 4.18.0-305.el8

    Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-26708HigFeb 5, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-tr

  • CVE-2021-3348HigFeb 1, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3d71.

  • CVE-2021-3347HigJan 29, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.

  • CVE-2020-28374HigJan 13, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack c

  • CVE-2021-0342MedJan 11, 2021
    affected < 4.18.0-305.el8fixed 4.18.0-305.el8

    In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges required. User interaction is not required for exploitation. Product: Android; Versions: Android kernel; Androi

  • CVE-2020-27835MedJan 7, 2021
    affected < 4.18.0-305.el8fixed 4.18.0-305.el8

    A use after free in the Linux kernel infiniband hfi1 driver in versions prior to 5.10-rc6 was found in the way user calls Ioctl after open dev file and fork. A local user could use this flaw to crash the system.

  • CVE-2020-36158HigJan 5, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.

  • CVE-2020-27777MedDec 15, 2020
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase

  • CVE-2020-0466HigDec 14, 2020
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    In do_epoll_ctl and ep_loop_check_proc of eventpoll.c, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion

  • CVE-2020-27786HigDec 11, 2020
    affected < 4.18.0-305.el8fixed 4.18.0-305.el8

    A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use causes the flow of ex

  • CVE-2020-29661HigDec 9, 2020
    affected < 4.18.0-240.15.1.el8_3fixed 4.18.0-240.15.1.el8_3

    A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.

  • CVE-2020-29660MedDec 9, 2020
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.

  • CVE-2020-14381HigDec 3, 2020
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiali

Page 71 of 75