rpm package
suse/kernel-default-base&distro=SUSE Linux Enterprise Module for Basesystem 15 SP6
pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6
Vulnerabilities (3,752)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-41011 | Hig | 7.8 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | Jul 18, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page with large pages We don't get the right offset in that case. The GPU has an unused 4K area of the register BAR space into which you can remap registers. We re | |
| CVE-2024-41010 | Hig | 7.8 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix too early release of tcx_entry Pedro Pinto and later independently also Hyunwoo Kim and Wongi Lee reported an issue that the tcx_entry can be released too early leading to a use after free (UAF) when a | |
| CVE-2024-41009 | Hig | 7.8 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overrunning reservations in ringbuf The BPF ring buffer internally is implemented as a power-of-2 sized circular buffer, with two logical and ever-increasing counters: consumer_pos is the consumer coun | |
| CVE-2023-52886 | Med | 6.4 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 16, 2024 | In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 dr | |
| CVE-2024-41007 | Hig | 7.5 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 15, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero, tcp_retransmit_timer() can retransmit a packet every two jiffies (2 ms for HZ=1 | |
| CVE-2023-52885 | Hig | 8.1 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 14, 2024 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock retaining a freed lis | |
| CVE-2024-41006 | Med | 5.5 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a memory leak in nr_heartbeat_expiry() syzbot reported a memory leak in nr_create() [0]. Commit 409db27e3a2e ("netrom: Fix use-after-free of a listening socket.") added sock_hold() to the nr_heartb | |
| CVE-2024-41005 | Med | 4.7 | < 6.4.0-150600.23.47.2.150600.12.20.2 | 6.4.0-150600.23.47.2.150600.12.20.2 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: netpoll: Fix race condition in netpoll_owner_active KCSAN detected a race condition in netpoll: BUG: KCSAN: data-race in net_rx_action / netpoll_send_skb write (marked) to 0xffff8881164168b0 of 4 bytes by in | |
| CVE-2024-41004 | Med | 5.5 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: tracing: Build event generation tests only as modules The kprobes and synth event generation test modules add events and lock (get a reference) those event file reference in module init function, and unlock and | |
| CVE-2024-41002 | Med | 5.5 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - Fix memory leak for sec resource release The AIV is one of the SEC resources. When releasing resources, it need to release the AIV resources at the same time. Otherwise, memory leakage o | |
| CVE-2024-41001 | Med | 5.5 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: io_uring/sqpoll: work around a potential audit memory leak kmemleak complains that there's a memory leak related to connect handling: unreferenced object 0xffff0001093bdf00 (size 128): comm "iou-sqp-455", pid | |
| CVE-2024-41000 | Hig | 7.8 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: block/ioctl: prefer different overflow check Running syzkaller with the newly reintroduced signed integer overflow sanitizer shows this report: [ 62.982337] ------------[ cut here ]------------ [ 62.985692 | |
| CVE-2024-40999 | Cri | 9.8 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: ena: Add validation for completion descriptors consistency Validate that `first` flag is set only for the first descriptor in multi-buffer packets. In case of an invalid descriptor, a reset will occur. A n | |
| CVE-2024-40998 | Med | 5.5 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super() In the following concurrency we will access the uninitialized rs->lock: ext4_fill_super ext4_register_sysfs // sysfs registered | |
| CVE-2024-40997 | Med | 5.5 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: fix memory leak on CPU EPP exit The cpudata memory from kzalloc() in amd_pstate_epp_cpu_init() is not freed in the analogous exit function, so fix that. [ rjw: Subject and changelog edits | |
| CVE-2024-40995 | Med | 5.5 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() syzbot found hanging tasks waiting on rtnl_lock [1] A reproducer is available in the syzbot bug. When a request to add multiple actions | |
| CVE-2024-40994 | Hig | 7.8 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: ptp: fix integer overflow in max_vclocks_store On 32bit systems, the "4 * max" multiply can overflow. Use kcalloc() to do the allocation to prevent this. | |
| CVE-2024-40992 | Hig | 7.5 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder length checking for UD request packets According to the IBA specification: If a UD request packet is detected with an invalid length, the request shall be an invalid request and it shall | |
| CVE-2024-40990 | Hig | 7.8 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Add check for srq max_sge attribute max_sge attribute is passed by the user, and is inserted and used unchecked, so verify that the value doesn't exceed maximum allowed value before using it. | |
| CVE-2024-40989 | Hig | 7.8 | < 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 | Jul 12, 2024 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Disassociate vcpus from redistributor region on teardown When tearing down a redistributor region, make sure we don't have any dangling pointer to that region stored in a vcpu. |
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page with large pages We don't get the right offset in that case. The GPU has an unused 4K area of the register BAR space into which you can remap registers. We re
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix too early release of tcx_entry Pedro Pinto and later independently also Hyunwoo Kim and Wongi Lee reported an issue that the tcx_entry can be released too early leading to a use after free (UAF) when a
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overrunning reservations in ringbuf The BPF ring buffer internally is implemented as a power-of-2 sized circular buffer, with two logical and ever-increasing counters: consumer_pos is the consumer coun
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 dr
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero, tcp_retransmit_timer() can retransmit a packet every two jiffies (2 ms for HZ=1
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock retaining a freed lis
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a memory leak in nr_heartbeat_expiry() syzbot reported a memory leak in nr_create() [0]. Commit 409db27e3a2e ("netrom: Fix use-after-free of a listening socket.") added sock_hold() to the nr_heartb
- affected < 6.4.0-150600.23.47.2.150600.12.20.2fixed 6.4.0-150600.23.47.2.150600.12.20.2
In the Linux kernel, the following vulnerability has been resolved: netpoll: Fix race condition in netpoll_owner_active KCSAN detected a race condition in netpoll: BUG: KCSAN: data-race in net_rx_action / netpoll_send_skb write (marked) to 0xffff8881164168b0 of 4 bytes by in
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: tracing: Build event generation tests only as modules The kprobes and synth event generation test modules add events and lock (get a reference) those event file reference in module init function, and unlock and
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - Fix memory leak for sec resource release The AIV is one of the SEC resources. When releasing resources, it need to release the AIV resources at the same time. Otherwise, memory leakage o
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: io_uring/sqpoll: work around a potential audit memory leak kmemleak complains that there's a memory leak related to connect handling: unreferenced object 0xffff0001093bdf00 (size 128): comm "iou-sqp-455", pid
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: block/ioctl: prefer different overflow check Running syzkaller with the newly reintroduced signed integer overflow sanitizer shows this report: [ 62.982337] ------------[ cut here ]------------ [ 62.985692
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: net: ena: Add validation for completion descriptors consistency Validate that `first` flag is set only for the first descriptor in multi-buffer packets. In case of an invalid descriptor, a reset will occur. A n
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super() In the following concurrency we will access the uninitialized rs->lock: ext4_fill_super ext4_register_sysfs // sysfs registered
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: fix memory leak on CPU EPP exit The cpudata memory from kzalloc() in amd_pstate_epp_cpu_init() is not freed in the analogous exit function, so fix that. [ rjw: Subject and changelog edits
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() syzbot found hanging tasks waiting on rtnl_lock [1] A reproducer is available in the syzbot bug. When a request to add multiple actions
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: ptp: fix integer overflow in max_vclocks_store On 32bit systems, the "4 * max" multiply can overflow. Use kcalloc() to do the allocation to prevent this.
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder length checking for UD request packets According to the IBA specification: If a UD request packet is detected with an invalid length, the request shall be an invalid request and it shall
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Add check for srq max_sge attribute max_sge attribute is passed by the user, and is inserted and used unchecked, so verify that the value doesn't exceed maximum allowed value before using it.
- affected < 6.4.0-150600.23.22.1.150600.12.8.3fixed 6.4.0-150600.23.22.1.150600.12.8.3
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Disassociate vcpus from redistributor region on teardown When tearing down a redistributor region, make sure we don't have any dangling pointer to that region stored in a vcpu.
Page 140 of 188