VYPR

rpm package

opensuse/dtb-aarch64&distro=openSUSE Leap 15.4

pkg:rpm/opensuse/dtb-aarch64&distro=openSUSE%20Leap%2015.4

Vulnerabilities (364)

  • CVE-2023-23586Feb 17, 2023
    affected < 5.3.18-150300.59.124.1fixed 5.3.18-150300.59.124.1

    Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process. timens_install calls current_is_single_threaded to determine if the current process is single-threaded, but this call does not consider io_uring's io_worker thr

  • CVE-2023-25012Feb 1, 2023
    affected < 5.14.21-150400.24.55.1fixed 5.14.21-150400.24.55.1

    The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long.

  • CVE-2023-0266KEVJan 30, 2023
    affected < 5.3.18-150300.59.109.1fixed 5.3.18-150300.59.109.1

    A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgradin

  • CVE-2022-4139Jan 27, 2023
    affected < 5.14.21-150400.24.38.1fixed 5.14.21-150400.24.38.1

    An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system.

  • CVE-2023-0394Jan 24, 2023
    affected < 5.3.18-150300.59.118.1fixed 5.3.18-150300.59.118.1

    A NULL pointer dereference flaw was found in rawv6_push_pending_frames in net/ipv6/raw.c in the network subcomponent in the Linux kernel. This flaw causes the system to crash.

  • CVE-2023-0122Jan 17, 2023
    affected < 5.14.21-150400.24.46.1fixed 5.14.21-150400.24.46.1

    A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in nvmet_setup_auth(), allows an attacker to perform a Pre-Auth Denial of Service (DoS) attack on a remote machine. Affected versions v6.0-rc1 to v6.0-rc3, fixed in v6.0-rc4.

  • CVE-2022-47929Jan 17, 2023
    affected < 5.3.18-150300.59.109.1fixed 5.3.18-150300.59.109.1

    In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands. This aff

  • CVE-2022-41858Jan 17, 2023
    affected < 5.14.21-150400.24.38.1fixed 5.14.21-150400.24.38.1

    A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information.

  • CVE-2023-23559Jan 13, 2023
    affected < 5.3.18-150300.59.115.1fixed 5.3.18-150300.59.115.1

    In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.

  • CVE-2023-23455Jan 12, 2023
    affected < 5.3.18-150300.59.109.1fixed 5.3.18-150300.59.109.1

    atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).

  • CVE-2023-23454Jan 12, 2023
    affected < 5.3.18-150300.59.109.1fixed 5.3.18-150300.59.109.1

    cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).

  • CVE-2022-3628Jan 12, 2023
    affected < 5.14.21-150400.24.33.1fixed 5.14.21-150400.24.33.1

    A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious USB device. This can allow a local user to crash the system or escalate their privileges.

  • CVE-2022-4382Jan 10, 2023
    affected < 5.14.21-150400.24.46.1fixed 5.14.21-150400.24.46.1

    A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could be triggered by yanking out a device that is running the gadgetfs side.

  • CVE-2022-4379Jan 10, 2023
    affected < 5.14.21-150400.24.41.1fixed 5.14.21-150400.24.41.1

    A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial

  • CVE-2022-2196Jan 9, 2023
    affected < 5.14.21-150400.24.63.1fixed 5.14.21-150400.24.63.1

    A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker a

  • CVE-2022-4378Jan 5, 2023
    affected < 5.14.21-150400.24.38.1fixed 5.14.21-150400.24.38.1

    A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

  • CVE-2022-4662Dec 22, 2022
    affected < 5.14.21-150400.24.41.1fixed 5.14.21-150400.24.41.1

    A flaw incorrect access control in the Linux kernel USB core subsystem was found in the way user attaches usb device. A local user could use this flaw to crash the system.

  • CVE-2022-47520Dec 18, 2022
    affected < 5.14.21-150400.24.41.1fixed 5.14.21-150400.24.41.1

    An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in the WILC1000 wireless driver can trigger an out-of-bounds read when parsing a Robust Security Network (RSN) information element from a Netlink

  • CVE-2022-3115Dec 14, 2022
    affected < 5.14.21-150400.24.41.1fixed 5.14.21-150400.24.41.1

    An issue was discovered in the Linux kernel through 5.16-rc6. malidp_crtc_reset in drivers/gpu/drm/arm/malidp_crtc.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.

  • CVE-2022-3114Dec 14, 2022
    affected < 5.14.21-150400.24.41.1fixed 5.14.21-150400.24.41.1

    An issue was discovered in the Linux kernel through 5.16-rc6. imx_register_uart_clocks in drivers/clk/imx/clk.c lacks check of the return value of kcalloc() and will cause the null pointer dereference.

Page 9 of 19