VYPR

rpm package

almalinux/kernel-tools-libs-devel

pkg:rpm/almalinux/kernel-tools-libs-devel

Vulnerabilities (1,699)

  • CVE-2021-29154HigApr 8, 2021
    affected < 4.18.0-372.9.1.el8fixed 4.18.0-372.9.1.el8

    BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.

  • CVE-2021-30002MedApr 2, 2021
    affected < 4.18.0-425.3.1.el8fixed 4.18.0-425.3.1.el8

    An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.

  • CVE-2021-29650MedMar 30, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of a new table value, a

  • CVE-2021-29646MedMar 30, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes, aka CID-0217ed2848e8.

  • CVE-2020-35508MedMar 26, 2021
    affected < 4.18.0-305.el8fixed 4.18.0-305.el8

    A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a pri

  • CVE-2021-28971MedMar 22, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.

  • CVE-2021-28950MedMar 20, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.

  • CVE-2021-27365HigMar 7, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up t

  • CVE-2021-27364HigMar 7, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.

  • CVE-2021-27363MedMar 7, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via t

  • CVE-2021-20194HigFeb 23, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BP

  • CVE-2020-24504MedFeb 17, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-24503MedFeb 17, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-24502MedFeb 17, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may allow an authenticated user to potentially enable a denial of service via local access.

  • CVE-2020-12362HigFeb 17, 2021
    affected < 4.18.0-305.el8fixed 4.18.0-305.el8

    Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-26708HigFeb 5, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-tr

  • CVE-2021-3348HigFeb 1, 2021
    affected < 4.18.0-348.el8fixed 4.18.0-348.el8

    nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3d71.

  • CVE-2021-3347HigJan 29, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.

  • CVE-2020-28374HigJan 13, 2021
    affected < 4.18.0-240.22.1.el8_3fixed 4.18.0-240.22.1.el8_3

    In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack c

  • CVE-2021-0342MedJan 11, 2021
    affected < 4.18.0-305.el8fixed 4.18.0-305.el8

    In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges required. User interaction is not required for exploitation. Product: Android; Versions: Android kernel; Androi

Page 81 of 85