VYPR

rpm package

suse/kernel-default&distro=SUSE Linux Enterprise Live Patching 12 SP5

pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5

Vulnerabilities (3,305)

  • CVE-2022-0812MedAug 29, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information.

  • CVE-2022-2991MedAug 25, 2022
    affected < 4.12.14-122.150.1fixed 4.12.14-122.150.1

    A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local attacker to escalat

  • CVE-2021-4159MedAug 24, 2022
    affected < 4.12.14-122.261.1fixed 4.12.14-122.261.1

    A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory deta

  • CVE-2021-4037MedAug 24, 2022
    affected < 4.12.14-122.139.1fixed 4.12.14-122.139.1

    A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a direct

  • CVE-2021-3764MedAug 23, 2022
    affected < 4.12.14-122.91.2fixed 4.12.14-122.91.2

    A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is to system availability.

  • CVE-2021-3759MedAug 23, 2022
    affected < 4.12.14-122.88.1fixed 4.12.14-122.88.1

    A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highe

  • CVE-2021-3659MedAug 22, 2022
    affected < 4.12.14-122.83.1fixed 4.12.14-122.83.1

    A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability.

  • CVE-2022-26373MedAug 18, 2022
    affected < 4.12.14-122.133.1fixed 4.12.14-122.133.1

    Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

  • CVE-2022-2503MedAug 12, 2022
    affected < 4.12.14-122.136.1fixed 4.12.14-122.136.1

    Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads currently allow users with root privileges to switch out the target with an equiva

  • CVE-2022-20369MedAug 11, 2022
    affected < 4.12.14-122.133.1fixed 4.12.14-122.133.1

    In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An

  • CVE-2022-20368HigAug 11, 2022
    affected < 4.12.14-122.133.1fixed 4.12.14-122.133.1

    Product: AndroidVersions: Android kernelAndroid ID: A-224546354References: Upstream kernel

  • CVE-2022-1012HigAug 5, 2022
    affected < 4.12.14-122.127.1fixed 4.12.14-122.127.1

    A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem.

  • CVE-2022-36946HigJul 27, 2022
    affected < 4.12.14-122.130.1fixed 4.12.14-122.130.1

    nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.

  • CVE-2022-36879MedJul 27, 2022
    affected < 4.12.14-122.133.1fixed 4.12.14-122.133.1

    An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.

  • CVE-2020-36558MedJul 21, 2022
    affected < 4.12.14-122.130.1fixed 4.12.14-122.130.1

    A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault.

  • CVE-2020-36557MedJul 21, 2022
    affected < 4.12.14-122.130.1fixed 4.12.14-122.130.1

    A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lead to a use-after-free.

  • CVE-2021-33656MedJul 18, 2022
    affected < 4.12.14-122.130.1fixed 4.12.14-122.130.1

    When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.

  • CVE-2021-33655MedJul 18, 2022
    affected < 4.12.14-122.130.1fixed 4.12.14-122.130.1

    When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

  • CVE-2021-4135MedJul 14, 2022
    affected < 4.12.14-122.110.1fixed 4.12.14-122.110.1

    A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device such that function nsim_map_alloc_elem being called. A local user could use this flaw to get unauthorized access to some data.

  • CVE-2022-29901MedJul 12, 2022
    affected < 4.12.14-122.127.1fixed 4.12.14-122.127.1

    Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code exe

Page 145 of 166