VYPR

rpm package

opensuse/kernel-syms&distro=openSUSE Leap 15.5

pkg:rpm/opensuse/kernel-syms&distro=openSUSE%20Leap%2015.5

Vulnerabilities (1,895)

  • CVE-2023-3567Jul 24, 2023
    affected < 5.14.21-150500.55.19.1fixed 5.14.21-150500.55.19.1

    A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.

  • CVE-2023-33952Jul 24, 2023
    affected < 5.14.21-150500.55.7.1fixed 5.14.21-150500.55.7.1

    A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which may allow a local priv

  • CVE-2023-2860Jul 24, 2023
    affected < 5.14.21-150500.55.62.1fixed 5.14.21-150500.55.62.1

    An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated

  • CVE-2023-3863Jul 24, 2023
    affected < 5.14.21-150500.55.19.1fixed 5.14.21-150500.55.19.1

    A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue.

  • CVE-2023-2430Jul 23, 2023
    affected < 5.14.21-150500.55.7.1fixed 5.14.21-150500.55.7.1

    A vulnerability was found due to missing lock for IOPOLL flaw in io_cqring_event_overflow() in io_uring.c in Linux Kernel. This flaw allows a local attacker with user privilege to trigger a Denial of Service threat.

  • CVE-2023-3776Jul 21, 2023
    affected < 5.14.21-150500.55.19.1fixed 5.14.21-150500.55.19.1

    A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, fw_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_b

  • CVE-2023-3611Jul 21, 2023
    affected < 5.14.21-150500.55.19.1fixed 5.14.21-150500.55.19.1

    An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes wi

  • CVE-2023-3610Jul 21, 2023
    affected < 5.14.21-150500.55.28.1fixed 5.14.21-150500.55.28.1

    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Flaw in the error handling of bound chains causes a use-after-free in the abort path of NFT_MSG_NEWRULE. The vulnerability requires CAP_NET

  • CVE-2023-3609Jul 21, 2023
    affected < 5.14.21-150500.55.19.1fixed 5.14.21-150500.55.19.1

    A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf

  • CVE-2023-0160Jul 18, 2023
    affected < 5.14.21-150500.55.59.1fixed 5.14.21-150500.55.59.1

    A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.

  • CVE-2023-38409Jul 17, 2023
    affected < 5.14.21-150500.55.19.1fixed 5.14.21-150500.55.19.1

    An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points

  • CVE-2023-21400Jul 12, 2023
    affected < 5.14.21-150500.55.19.1fixed 5.14.21-150500.55.19.1

    In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-37453Jul 6, 2023
    affected < 5.14.21-150500.55.28.1fixed 5.14.21-150500.55.28.1

    An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c.

  • CVE-2023-35001Jul 5, 2023
    affected < 5.14.21-150500.55.12.1fixed 5.14.21-150500.55.12.1

    Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace

  • CVE-2023-31248Jul 5, 2023
    affected < 5.14.21-150500.55.12.1fixed 5.14.21-150500.55.12.1

    Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace

  • CVE-2023-1206Jun 30, 2023
    affected < 5.14.21-150500.55.31.1fixed 5.14.21-150500.55.31.1

    A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that acc

  • CVE-2023-3390Jun 28, 2023
    affected < 5.14.21-150500.55.12.1fixed 5.14.21-150500.55.12.1

    A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This fl

  • CVE-2023-3389Jun 28, 2023
    affected < 5.14.21-150500.55.7.1fixed 5.14.21-150500.55.7.1

    A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We recommend upgrading past commit ef7dfac51d8ed961b742218f526

  • CVE-2023-3090Jun 28, 2023
    affected < 5.14.21-150500.55.7.1fixed 5.14.21-150500.55.7.1

    A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_

  • CVE-2023-3358Jun 28, 2023
    affected < 5.14.21-150500.55.7.1fixed 5.14.21-150500.55.7.1

    A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system.

Page 90 of 95