VYPR

rpm package

opensuse/kernel-source&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed

Vulnerabilities (1,862)

  • CVE-2021-3744MedMar 4, 2022
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.

  • CVE-2021-3640HigMar 3, 2022
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable fau

  • CVE-2021-3753MedFeb 16, 2022
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_ioctl (KDSETMDE). The highest threat from this vulnerability is to data confidenti

  • CVE-2022-0185HigKEVFeb 11, 2022
    affected < 5.16.2-1.1fixed 5.16.2-1.1

    A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced

  • CVE-2022-24958HigFeb 11, 2022
    affected < 5.16.10-1.1fixed 5.16.10-1.1

    drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

  • CVE-2021-43976MedNov 17, 2021
    affected < 5.15.6-1.3fixed 5.15.6-1.3

    In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).

  • CVE-2017-5123HigNov 2, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.

  • CVE-2021-3653HigSep 29, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" field, this issue co

  • CVE-2021-38166HigAug 7, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.

  • CVE-2021-37576HigJul 26, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.

  • CVE-2021-33909HigJul 20, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.

  • CVE-2021-3491HigJun 4, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc//mem. This could be used to create a heap overflow leading to arbitrary code executi

  • CVE-2021-3490HigJun 4, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fixed via commit 049c4

  • CVE-2021-3489HigJun 4, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via co

  • CVE-2020-25668HigMay 26, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.

  • CVE-2021-3483HigMay 17, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confidentiality, integrity, as we

  • CVE-2021-32606HigMay 11, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)

  • CVE-2020-26141MedMay 11, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 network

  • CVE-2020-24588LowMay 11, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is manda

  • CVE-2020-24587LowMay 11, 2021
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends f

Page 84 of 94