VYPR

rpm package

opensuse/kernel-source&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed

Vulnerabilities (1,862)

  • CVE-2015-8660MedDec 28, 2015
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.

  • CVE-2015-7885LowDec 28, 2015
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

  • CVE-2015-7884LowDec 28, 2015
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

  • CVE-2015-1333Aug 31, 2015
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.

  • CVE-2014-8133Dec 17, 2014
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, via a crafted applicat

  • CVE-2014-0196MedKEVMay 7, 2014
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering

  • CVE-2014-0038Feb 6, 2014
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.

  • CVE-2011-1180CriJun 8, 2013
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging connectivit

  • CVE-2013-2850Jun 7, 2013
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possi

  • CVE-2011-4604Jun 7, 2013
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The bat_socket_read function in net/batman-adv/icmp_socket.c in the Linux kernel before 3.3 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted batman-adv ICMP packet.

  • CVE-2013-0913Mar 18, 2013
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of servic

  • CVE-2013-0160Feb 18, 2013
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device.

  • CVE-2013-0231Feb 13, 2013
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some o

  • CVE-2012-3520Oct 3, 2012
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.

  • CVE-2012-3412Oct 3, 2012
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.

  • CVE-2012-0056Jan 27, 2012
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc//mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

  • CVE-2011-2203Jan 27, 2012
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The hfs_find_init function in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and Oops) by mounting an HFS file system with a malformed MDB extent record.

  • CVE-2011-1581May 26, 2011
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The bond_select_queue function in drivers/net/bonding/bond_main.c in the Linux kernel before 2.6.39, when a network device with a large number of receive queues is installed but the default tx_queues setting is used, does not properly restrict queue indexes, which allows remote a

  • CVE-2011-1577May 3, 2011
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    Heap-based buffer overflow in the is_gpt_valid function in fs/partitions/efi.c in the Linux kernel 2.6.38 and earlier allows physically proximate attackers to cause a denial of service (OOPS) or possibly have unspecified other impact via a crafted size of the EFI GUID partition-t

  • CVE-2011-0711Mar 1, 2011
    affected < 4.8.13-1.1fixed 4.8.13-1.1

    The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.