VYPR

rpm package

opensuse/kernel-azure&distro=openSUSE Leap 15.4

pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2015.4

Vulnerabilities (315)

  • CVE-2022-4382Jan 10, 2023
    affected < 5.14.21-150400.14.34.1fixed 5.14.21-150400.14.34.1

    A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could be triggered by yanking out a device that is running the gadgetfs side.

  • CVE-2022-4379Jan 10, 2023
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial

  • CVE-2022-2196Jan 9, 2023
    affected < 5.14.21-150400.14.49.1fixed 5.14.21-150400.14.49.1

    A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker a

  • CVE-2022-4378Jan 5, 2023
    affected < 5.14.21-150400.14.28.1fixed 5.14.21-150400.14.28.1

    A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

  • CVE-2022-4662Dec 22, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    A flaw incorrect access control in the Linux kernel USB core subsystem was found in the way user attaches usb device. A local user could use this flaw to crash the system.

  • CVE-2022-47520Dec 18, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in the WILC1000 wireless driver can trigger an out-of-bounds read when parsing a Robust Security Network (RSN) information element from a Netlink

  • CVE-2022-3115Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. malidp_crtc_reset in drivers/gpu/drm/arm/malidp_crtc.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.

  • CVE-2022-3114Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. imx_register_uart_clocks in drivers/clk/imx/clk.c lacks check of the return value of kcalloc() and will cause the null pointer dereference.

  • CVE-2022-3113Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.

  • CVE-2022-3112Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. amvdec_set_canvases in drivers/staging/media/meson/vdec/vdec_helpers.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.

  • CVE-2022-3111Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. free_charger_irq() in drivers/power/supply/wm8350_power.c lacks free of WM8350_IRQ_CHG_FAST_RDY, which is registered in wm8350_init_charger().

  • CVE-2022-3108Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. kfd_parse_subtype_iolink in drivers/gpu/drm/amd/amdkfd/kfd_crat.c lacks check of the return value of kmemdup().

  • CVE-2022-3107Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. netvsc_get_ethtool_stats in drivers/net/hyperv/netvsc_drv.c lacks check of the return value of kvmalloc_array() and will cause the null pointer dereference.

  • CVE-2022-3106Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the return value of kmalloc().

  • CVE-2022-3105Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. uapi_finalize in drivers/infiniband/core/uverbs_uapi.c lacks check of kmalloc_array().

  • CVE-2022-3104Dec 14, 2022
    affected < 5.14.21-150400.14.31.1fixed 5.14.21-150400.14.31.1

    An issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks check of the return value of kmalloc() and will cause the null pointer dereference.

  • CVE-2022-42329Dec 7, 2022
    affected < 5.14.21-150400.14.28.1fixed 5.14.21-150400.14.28.1

    Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free

  • CVE-2022-42328Dec 7, 2022
    affected < 5.14.21-150400.14.28.1fixed 5.14.21-150400.14.28.1

    Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock when trying to free

  • CVE-2022-3643Dec 7, 2022
    affected < 5.14.21-150400.14.28.1fixed 5.14.21-150400.14.28.1

    Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption in the rest of the Linux networ

  • CVE-2022-4269Dec 5, 2022
    affected < 5.14.21-150400.14.52.1fixed 5.14.21-150400.14.52.1

    A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the transport protocol in

Page 9 of 16