VYPR

rpm package

suse/kernel-default&distro=SUSE Linux Enterprise Live Patching 12 SP5

pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5

Vulnerabilities (3,305)

  • CVE-2021-4149MedMar 23, 2022
    affected < 4.12.14-122.110.1fixed 4.12.14-122.110.1

    A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.

  • CVE-2022-27666HigMar 23, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

  • CVE-2022-1011HigMar 18, 2022
    affected < 4.12.14-122.121.2fixed 4.12.14-122.121.2

    A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.

  • CVE-2021-45868MedMar 18, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file.

  • CVE-2021-39713HigMar 16, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel

  • CVE-2021-39711MedMar 16, 2022
    affected < 4.12.14-122.124.3fixed 4.12.14-122.124.3

    In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android k

  • CVE-2022-23960MedMar 13, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow th

  • CVE-2022-26966MedMar 12, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.

  • CVE-2022-0002MedMar 11, 2022
    affected < 4.12.14-122.113.1fixed 4.12.14-122.113.1

    Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

  • CVE-2022-0001MedMar 11, 2022
    affected < 4.12.14-122.113.1fixed 4.12.14-122.113.1

    Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

  • CVE-2022-23042HigMar 10, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access

  • CVE-2022-23041HigMar 10, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access

  • CVE-2022-23040HigMar 10, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access

  • CVE-2022-23039HigMar 10, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access

  • CVE-2022-23038HigMar 10, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access

  • CVE-2022-23037HigMar 10, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access

  • CVE-2022-23036HigMar 10, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Several Linux PV device frontends are using the grant table interfaces for removing access

  • CVE-2022-0847HigKEVMar 10, 2022
    affected < 4.12.14-122.113.1fixed 4.12.14-122.113.1

    A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to

  • CVE-2021-3732MedMar 10, 2022
    affected < 4.12.14-122.88.1fixed 4.12.14-122.88.1

    A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.

  • CVE-2022-26490HigMar 6, 2022
    affected < 4.12.14-122.116.1fixed 4.12.14-122.116.1

    st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.

Page 148 of 166