VYPR

rpm package

suse/kernel-default&distro=SUSE Linux Enterprise Server 12 SP2

pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2

Vulnerabilities (124)

  • CVE-2017-1000365HigJun 19, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects

  • CVE-2017-1000364HigJun 19, 2017
    affected < 4.4.59-92.20.2fixed 4.4.59-92.20.2

    An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduce

  • CVE-2017-1000380MedJun 17, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happ

  • CVE-2017-9242MedMay 27, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via crafted system calls.

  • CVE-2017-9150MedMay 22, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address information via crafted bpf system ca

  • CVE-2017-9077HigMay 19, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.

  • CVE-2017-9076HigMay 19, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.

  • CVE-2017-9075HigMay 19, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.

  • CVE-2017-9074HigMay 19, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact

  • CVE-2017-7487HigMay 14, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface.

  • CVE-2017-8925MedMay 12, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.

  • CVE-2017-8924MedMay 12, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial

  • CVE-2017-8890HigMay 10, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.

  • CVE-2017-8831MedMay 8, 2017
    affected < 4.4.90-92.45.1fixed 4.4.90-92.45.1

    The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequence-number value, aka a "do

  • CVE-2017-7618HigApr 10, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.

  • CVE-2017-7616MedApr 10, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation.

  • CVE-2017-2671MedApr 5, 2017
    affected < 4.4.59-92.17.3fixed 4.4.59-92.17.3

    The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the

  • CVE-2017-7374HigMar 31, 2017
    affected < 4.4.59-92.17.3fixed 4.4.59-92.17.3

    Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic trans

  • CVE-2017-7346MedMar 30, 2017
    affected < 4.4.74-92.29.1fixed 4.4.74-92.29.1

    The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call for a /dev/dri/renderD* devic

  • CVE-2017-7308HigMar 29, 2017
    affected < 4.4.59-92.17.3fixed 4.4.59-92.17.3

    The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_N

Page 4 of 7