VYPR

rpm package

almalinux/kernel-tools-libs-devel

pkg:rpm/almalinux/kernel-tools-libs-devel

Vulnerabilities (1,662)

  • CVE-2021-20317MedSep 27, 2021
    affected < 4.18.0-348.2.1.el8_5fixed 4.18.0-348.2.1.el8_5

    A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the s

  • CVE-2021-21781LowAug 18, 2021
    affected < 4.18.0-372.9.1.el8fixed 4.18.0-372.9.1.el8

    An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An

  • CVE-2021-3635MedAug 13, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.

  • CVE-2021-3573MedAug 13, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregister_dev() together with one of the calls hci_sock_blacklist_add(), hci_sock_blackl

  • CVE-2021-38201HigAug 8, 2021
    affected < 4.18.0-305.17.1.el8_4fixed 4.18.0-305.17.1.el8_4

    net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.

  • CVE-2021-3679MedAug 5, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources causin

  • CVE-2021-37576HigJul 26, 2021
    affected < 4.18.0-305.17.1.el8_4fixed 4.18.0-305.17.1.el8_4

    arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.

  • CVE-2021-37159MedJul 21, 2021
    affected < 4.18.0-372.9.1.el8fixed 4.18.0-372.9.1.el8

    hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.

  • CVE-2021-33909HigJul 20, 2021
    affected < 4.18.0-305.10.2.el8_4fixed 4.18.0-305.10.2.el8_4

    fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.

  • CVE-2021-3612HigJul 9, 2021
    affected < 4.18.0-372.9.1.el8fixed 4.18.0-372.9.1.el8

    An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highe

  • CVE-2021-22555HigKEVJul 7, 2021
    affected < 4.18.0-305.12.1.el8_4fixed 4.18.0-305.12.1.el8_4

    A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

  • CVE-2021-0512HigJun 21, 2021
    affected < 4.18.0-305.25.1.el8_4fixed 4.18.0-305.25.1.el8_4

    In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod

  • CVE-2021-0129MedJun 9, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access.

  • CVE-2021-3564MedJun 8, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.

  • CVE-2020-36386HigJun 7, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf.

  • CVE-2020-36385HigJun 7, 2021
    affected < 4.18.0-305.25.1.el8_4fixed 4.18.0-305.25.1.el8_4

    An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.

  • CVE-2021-3489HigJun 4, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via co

  • CVE-2021-3543MedJun 1, 2021
    affected < 4.18.0-305.3.1.el8_4fixed 4.18.0-305.3.1.el8_4

    A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.

  • CVE-2021-20239LowMay 28, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality.

  • CVE-2020-10774MedMay 27, 2021
    affected < 4.18.0-240.el8fixed 4.18.0-240.el8

    A memory disclosure flaw was found in the Linux kernel's versions before 4.18.0-193.el8 in the sysctl subsystem when reading the /proc/sys/kernel/rh_features file. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from this vuln

Page 77 of 84