VYPR

rpm package

opensuse/kernel-source&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed

Vulnerabilities (1,862)

  • CVE-2026-63828HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connection in the SYN. apparmor_socket_sendmsg() on

  • CVE-2026-63827HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: apparmor: fix use-after-free in rawdata dedup loop aa_replace_profiles() walks ns->rawdata_list to dedup the incoming policy blob against entries already attached to existing profiles. Per the kernel-doc on str

  • CVE-2026-63826Jul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: fbdev: fix use-after-free in store_modes() store_modes() replaces a framebuffer's modelist with modes from userspace. On success it frees the old modelist with fb_destroy_modelist(). Two fields still point into

  • CVE-2026-63825CriJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent access crashes GCC's GCOV instrumentation can merge global branch counters with loop induction variables as an optimization. In inflate_fast(), the inner copy

  • CVE-2026-63824HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided. Fix the bug by allocating in

  • CVE-2026-63823HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper

  • CVE-2026-63822Jul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix warning when unbinding If there is an error during some initialization related to firmware, the buffers dp->tx_ring[i].tx_status are released. However this is released again when the device is

  • CVE-2026-63821Jul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: usb: fix memory leaks on USB write failures When rtw_usb_write_port() fails to submit a USB Request Block (URB) (e.g., due to device disconnect or ENOMEM), the completion callback is never executed

  • CVE-2026-63820Jul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix missing read bio submission on large folio error f2fs_read_data_large_folio() can keep a read bio across multiple readahead folios. If a later folio hits an error before any of its blocks are added t

  • CVE-2026-63819HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on f2fs_get_node_folio_ra() kernel BUG at fs/f2fs/file.c:845! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 0 PID: 5336 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(

  • CVE-2026-63818HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: validate orphan inode entry count f2fs_recover_orphan_inodes() trusts the orphan block entry_count when replaying orphan inodes from the checkpoint pack. A corrupted entry_count larger than F2FS_ORPHANS_P

  • CVE-2026-63817HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: validate compress cache inode only when enabled F2FS_COMPRESS_INO() uses NM_I(sbi)->max_nid as the synthetic inode number for the compressed page cache inode. That inode only exists when the compress_cach

  • CVE-2026-63816HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode - ioctl(F2FS_IOC_GARBAGE_COLLECT_RANGE) - shrink - f2fs_gc - gc_data_segment - ra_data_block(cow_inode) - mapping = F2FS_I(inode)->atomic_i

  • CVE-2026-63815HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: bound i_inline_xattr_size for non-inline-xattr inodes When the flexible_inline_xattr feature is enabled, do_read_inode() loads the on-disk i_inline_xattr_size unconditionally: if (f2fs_sb_has_flexible_i

  • CVE-2026-63814HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: validate ACL entry sizes in f2fs_acl_from_disk() f2fs_acl_count() only validates the aggregate ACL xattr length. A malformed ACL can still place ACL_USER or ACL_GROUP in a slot that only contains struct f

  • CVE-2026-63813HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block" This reverts commit 9609dd704725a40cd63d915f2ab6c44248a44598. The kernel panics are keeping to be reported especially when the f2

  • CVE-2026-63812HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() When __destroy_extent_node() sets the inode flag FI_NO_EXTENT, it does not reset the length of the largest extent to 0 and update the inode f

  • CVE-2026-63811Jul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: read COW data with the original inode during atomic write When updating an atomic-write file, f2fs_write_begin() may read the previously written data back from the COW inode: prepare_atomic_write_begin()

  • CVE-2026-63810Jul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: block: Avoid mounting the bdev pseudo-filesystem in userspace The bdev pseudo-filesystem is an internal kernel filesystem with which userspace should not interfere. Unregister it so that userspace cannot even a

  • CVE-2026-63809HigJul 19, 2026
    affected < 7.1.4-1.1fixed 7.1.4-1.1

    In the Linux kernel, the following vulnerability has been resolved: bpf: use kvfree() for replaced sysctl write buffer proc_sys_call_handler() allocates its temporary sysctl buffer with kvzalloc() and passes it to __cgroup_bpf_run_filter_sysctl(). Since kvzalloc() may fall back

Page 19 of 94