VYPR

rpm package

almalinux/kernel-tools-libs-devel

pkg:rpm/almalinux/kernel-tools-libs-devel

Vulnerabilities (1,491)

  • CVE-2019-18809MedNov 7, 2019
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.

  • CVE-2019-18808MedNov 7, 2019
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.

  • CVE-2019-16233MedSep 11, 2019
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • CVE-2019-16231MedSep 11, 2019
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • CVE-2019-9458HigSep 6, 2019
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2019-9455LowSep 6, 2019
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2019-15925HigSep 4, 2019
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.

  • CVE-2019-15917HigSep 4, 2019
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() fails in hci_uart_set_proto() in drivers/bluetooth/hci_ldisc.c.

  • CVE-2019-12614MedJun 3, 2019
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).

  • CVE-2018-13405HigJul 6, 2018
    affected < 4.18.0-372.9.1.el8fixed 4.18.0-372.9.1.el8

    The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the no

  • CVE-2017-5715MedJan 4, 2018
    affected < 4.18.0-372.9.1.el8fixed 4.18.0-372.9.1.el8

    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

Page 75 of 75