VYPR

rpm package

opensuse/kernel-source&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed

Vulnerabilities (3,335)

  • CVE-2026-93250HigSep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix use-after-free in vxlan_mdb_flush() vxlan_mdb_flush() iterates over the MDB entries using hlist_for_each_entry_safe(), which only tolerates the removal of the current entry. Contrary to the comm

  • CVE-2026-93249Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: spi: amlogic-spisg: Make sure clk_init_data is fully initialized The clk_init_data structure contains several mutually-exclusive members for different methods to specify the possible parents of a clock, prompti

  • CVE-2026-93248Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: drm/xe: don't WARN on kernel job timeout when device already wedged igt@xe_wedged@wedged-at-any-timeout wedges the device in mode 2 (UPON_ANY_HANG_NO_RESET) and then rebinds the driver. During unbind, a GSC pro

  • CVE-2026-93247Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference 'uuid_count' member of struct 'discovery_state' is assigned and read without any locks, so there is a chance of situation when uuid_count != 0, but

  • CVE-2026-93246Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix out-of-bounds read setting MSI-X irq affinity rvu_register_interrupts() walks every MSI-X vector and uses strstr() to match "Mbox" or "FLR" in irq_name before pinning those interrupts to CPU 0

  • CVE-2026-93245Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: apparmor: policy_int make sure list heads are initialized before fail path If profile create fails before policy_init is complete the list heads are not properly initialized causing profile_free() sanity checks

  • CVE-2026-93244Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: simpledrm: Improve stride validation Validate the computed stride against the maximum value INT_MAX.

  • CVE-2026-93243Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: properly account locked pages secretmem accounts folios by treating memory as if it were mlock()'d and thus limited by the RLIMIT_MEMLOCK limit. However the folios are unevictable and remain so u

  • CVE-2026-93242Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() qla24xx_process_response_queue() advances ring_ptr past the head IOCB before dispatching, so by the time __qla_consume_iocb() runs, rin

  • CVE-2026-93241Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done At Meta, we are seeing instances where an OOM killed job is stuck in the exit path for several hours. In one particular case, th

  • CVE-2026-93240Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: memcg: make the v1 soft limit knob inert The v1 soft limit has been deprecated since v6.12 and nobody has reported depending on it. Start the removal by decoupling the interface from the implementation: keep m

  • CVE-2026-93239Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: arm64: mm: Fix the lockless page-table walk in show_pte() show_pte() walks page tables locklessly and can run with interrupts enabled. A concurrent teardown can free a table page while it is being walked. It ca

  • CVE-2026-93238Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap The DECLARE_BITMAP(apm_filtered, AP_DEVICES) macro allocates the bitmap on the stack without zero-initializing it. In vfio_ap_mdev_hot_plug_

  • CVE-2026-93237HigSep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add DIRECT_MAP_PHYSMEM_END definition get_free_mem_region() and mhp_get_pluggable_range() bound their search to DIRECT_MAP_PHYSMEM_END. LoongArch does not define it, so the fallback in include/linux/

  • CVE-2026-93236Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common When VIDIOC_TRY_FMT is called with an unsupported pixel format on the OUTPUT queue, vdec_try_fmt_common() falls back to V4L2_PIX_FMT_MPEG2. Howe

  • CVE-2026-93235Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to zero post-EOF data when extending file size generic/794 4s ... - output mismatch (see /share/git/fstests/results//generic/794.out.bad) --- tests/generic/794.out 2026-06-12 08:46:32.766426241

  • CVE-2026-93234Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: drm/gud: validate TV mode names before creating enum property The GUD protocol returns TV mode names as fixed-size GUD_CONNECTOR_TV_MODE_NAME_LEN entries and requires each name to be NUL-terminated. gud_connec

  • CVE-2026-93233Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dmem: fix callocated underflow on large folio split nouveau_dmem_folio_free() drops chunk->callocated once per freed folio, while a large (compound) device-private folio is only counted once when it

  • CVE-2026-93232Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages Patch series "mm: Refactor bootmem gigantic hugepage allocation", v4. This series is split out from the earlier larger series "mm: Generali

  • CVE-2026-93231Sep 24, 2026
    affected < 7.2.8-1.1fixed 7.2.8-1.1

    In the Linux kernel, the following vulnerability has been resolved: lockd: fix swapped arguments in nlmsvc_match_ip() When releasing locks by server IP address via /proc/fs/nfsd/unlock_ip, nlmsvc_unlock_all_by_ip() calls nlm_traverse_files() with the server sockaddr as the opaq

Page 2 of 167