rpm package
suse/kernel-default-base&distro=SUSE Linux Enterprise Micro 5.5
pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Micro%205.5
Vulnerabilities (4,617)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-3777 | — | < 5.14.21-150500.55.36.1.150500.6.15.3 | 5.14.21-150500.55.36.1.150500.6.15.3 | Sep 6, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release | ||
| CVE-2023-4569 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Aug 28, 2023 | A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak. | ||
| CVE-2023-4459 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Aug 21, 2023 | A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel. This issue may allow a local attacker with normal user privilege to cause a denial of service due to a missing sani | ||
| CVE-2023-4389 | — | < 5.14.21-150500.55.31.1.150500.6.13.1 | 5.14.21-150500.55.31.1.150500.6.13.1 | Aug 16, 2023 | A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel informati | ||
| CVE-2023-4387 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Aug 16, 2023 | A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleaning up vmxnet3_rq_cleanup_all, | ||
| CVE-2023-40283 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Aug 14, 2023 | An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled. | ||
| CVE-2023-25775 | — | < 5.14.21-150500.55.39.1.150500.6.17.1 | 5.14.21-150500.55.39.1.150500.6.17.1 | Aug 11, 2023 | Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | ||
| CVE-2023-4273 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Aug 9, 2023 | A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a si | ||
| CVE-2023-20588 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Aug 8, 2023 | A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. | ||
| CVE-2023-4194 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Aug 7, 2023 | A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following ups | ||
| CVE-2023-4147 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Aug 7, 2023 | A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system. | ||
| CVE-2023-4133 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Aug 3, 2023 | A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of ser | ||
| CVE-2023-3772 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Jul 25, 2023 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of s | ||
| CVE-2023-33951 | — | < 5.14.21-150500.55.91.1.150500.6.41.1 | 5.14.21-150500.55.91.1.150500.6.41.1 | Jul 24, 2023 | A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information | ||
| CVE-2023-3567 | — | < 5.14.21-150500.55.100.1.150500.6.47.1 | 5.14.21-150500.55.100.1.150500.6.47.1 | Jul 24, 2023 | A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. | ||
| CVE-2023-33952 | — | < 5.14.21-150500.55.91.1.150500.6.41.1 | 5.14.21-150500.55.91.1.150500.6.41.1 | Jul 24, 2023 | A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which may allow a local priv | ||
| CVE-2023-2860 | — | < 5.14.21-150500.55.62.2.150500.6.27.2 | 5.14.21-150500.55.62.2.150500.6.27.2 | Jul 24, 2023 | An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated | ||
| CVE-2023-3863 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Jul 24, 2023 | A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue. | ||
| CVE-2023-3610 | — | < 5.14.21-150500.55.28.1.150500.6.11.2 | 5.14.21-150500.55.28.1.150500.6.11.2 | Jul 21, 2023 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Flaw in the error handling of bound chains causes a use-after-free in the abort path of NFT_MSG_NEWRULE. The vulnerability requires CAP_NET | ||
| CVE-2023-0160 | — | < 5.14.21-150500.55.59.1.150500.6.25.7 | 5.14.21-150500.55.59.1.150500.6.25.7 | Jul 18, 2023 | A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system. |
- CVE-2023-3777Sep 6, 2023affected < 5.14.21-150500.55.36.1.150500.6.15.3fixed 5.14.21-150500.55.36.1.150500.6.15.3
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release
- CVE-2023-4569Aug 28, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.
- CVE-2023-4459Aug 21, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel. This issue may allow a local attacker with normal user privilege to cause a denial of service due to a missing sani
- CVE-2023-4389Aug 16, 2023affected < 5.14.21-150500.55.31.1.150500.6.13.1fixed 5.14.21-150500.55.31.1.150500.6.13.1
A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel informati
- CVE-2023-4387Aug 16, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleaning up vmxnet3_rq_cleanup_all,
- CVE-2023-40283Aug 14, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.
- CVE-2023-25775Aug 11, 2023affected < 5.14.21-150500.55.39.1.150500.6.17.1fixed 5.14.21-150500.55.39.1.150500.6.17.1
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- CVE-2023-4273Aug 9, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a si
- CVE-2023-20588Aug 8, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
- CVE-2023-4194Aug 7, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following ups
- CVE-2023-4147Aug 7, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.
- CVE-2023-4133Aug 3, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of ser
- CVE-2023-3772Jul 25, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of s
- CVE-2023-33951Jul 24, 2023affected < 5.14.21-150500.55.91.1.150500.6.41.1fixed 5.14.21-150500.55.91.1.150500.6.41.1
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information
- CVE-2023-3567Jul 24, 2023affected < 5.14.21-150500.55.100.1.150500.6.47.1fixed 5.14.21-150500.55.100.1.150500.6.47.1
A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.
- CVE-2023-33952Jul 24, 2023affected < 5.14.21-150500.55.91.1.150500.6.41.1fixed 5.14.21-150500.55.91.1.150500.6.41.1
A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which may allow a local priv
- CVE-2023-2860Jul 24, 2023affected < 5.14.21-150500.55.62.2.150500.6.27.2fixed 5.14.21-150500.55.62.2.150500.6.27.2
An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated
- CVE-2023-3863Jul 24, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue.
- CVE-2023-3610Jul 21, 2023affected < 5.14.21-150500.55.28.1.150500.6.11.2fixed 5.14.21-150500.55.28.1.150500.6.11.2
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Flaw in the error handling of bound chains causes a use-after-free in the abort path of NFT_MSG_NEWRULE. The vulnerability requires CAP_NET
- CVE-2023-0160Jul 18, 2023affected < 5.14.21-150500.55.59.1.150500.6.25.7fixed 5.14.21-150500.55.59.1.150500.6.25.7
A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.
Page 228 of 231