rpm package
suse/kernel-default-base&distro=SUSE Linux Enterprise Module for Basesystem 15 SP6
pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6
Vulnerabilities (3,752)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-36915 | Hig | 7.1 | < 6.4.0-150600.23.14.2.150600.12.4.3 | 6.4.0-150600.23.14.2.150600.12.4.3 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix nfc_llcp_setsockopt() unsafe copies syzbot reported unsafe calls to copy_from_sockptr() [1] Use copy_safe_from_sockptr() instead. [1] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset | |
| CVE-2024-36914 | Hig | 7.8 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip on writeback when it's not applicable [WHY] dynamic memory safety error detector (KASAN) catches and generates error messages "BUG: KASAN: slab-out-of-bounds" as writeback connector does n | |
| CVE-2024-36913 | Cri | 9.3 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned | |
| CVE-2024-36912 | Cri | 9.6 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and t | |
| CVE-2024-36911 | Cri | 9.8 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory | |
| CVE-2024-36910 | Hig | 8.4 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Don't free decrypted memory In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting m | |
| CVE-2024-36909 | Cri | 9.3 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error i | |
| CVE-2024-36908 | Med | 5.5 | < 6.4.0-150600.23.33.1.150600.12.14.1 | 6.4.0-150600.23.33.1.150600.12.14.1 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: blk-iocost: do not WARN if iocg was already offlined In iocg_pay_debt(), warn is triggered if 'active_list' is empty, which is intended to confirm iocg is active when it has debt. However, warn can be triggered | |
| CVE-2024-36906 | Hig | 7.8 | < 6.4.0-150600.23.7.3.150600.12.2.7 | 6.4.0-150600.23.7.3.150600.12.2.7 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: ARM: 9381/1: kasan: clear stale stack poison We found below OOB crash: [ 33.452494] ================================================================== [ 33.453513] BUG: KASAN: stack-out-of-bounds in refres | |
| CVE-2024-36905 | Med | 5.5 | < 6.4.0-150600.23.30.1.150600.12.12.6 | 6.4.0-150600.23.30.1.150600.12.12.6 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets TCP_SYN_RECV state is really special, it is only used by cross-syn connections, mostly used by fuzzers. In the following crash [1], syzbot managed to | |
| CVE-2024-36904 | Hig | 7.8 | < 6.4.0-150600.23.14.2.150600.12.4.3 | 6.4.0-150600.23.14.2.150600.12.4.3 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp: Use refcount_inc_not_zero() in tcp_twsk_unique(). Anderson Nascimento reported a use-after-free splat in tcp_twsk_unique() with nice analysis. Since commit ec94c2696f0b ("tcp/dccp: avoid one atomic operat | |
| CVE-2024-36903 | Med | 5.5 | < 6.4.0-150600.23.14.2.150600.12.4.3 | 6.4.0-150600.23.14.2.150600.12.4.3 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check FLOWI_FLAG_KNOWN_NH on fl6->flowi6_flags in | |
| CVE-2024-36902 | Med | 5.5 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action() syzbot is able to trigger the following crash [1], caused by unsafe ip6_dst_idev() use. Indeed ip6_dst_idev() can return NULL, and must a | |
| CVE-2024-36901 | Med | 5.5 | < 6.4.0-150600.23.17.1.150600.12.6.2 | 6.4.0-150600.23.17.1.150600.12.6.2 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent NULL dereference in ip6_output() According to syzbot, there is a chance that ip6_dst_idev() returns NULL in ip6_output(). Most places in IPv6 stack deal with a NULL idev just fine, but not here. | |
| CVE-2024-36900 | Med | 5.5 | < 6.4.0-150600.23.14.2.150600.12.4.3 | 6.4.0-150600.23.14.2.150600.12.4.3 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when devlink reload during initialization The devlink reload process will access the hardware resources, but the register operation is done before the hardware is initialized. So, pr | |
| CVE-2024-36899 | Hig | 7.0 | < 6.4.0-150600.23.14.2.150600.12.4.3 | 6.4.0-150600.23.14.2.150600.12.4.3 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: Fix use after free in lineinfo_changed_notify The use-after-free issue occurs as follows: when the GPIO chip device file is being closed by invoking gpio_chrdev_release(), watched_lines is freed | |
| CVE-2024-36898 | Hig | 7.1 | < 6.4.0-150600.23.7.3.150600.12.2.7 | 6.4.0-150600.23.7.3.150600.12.2.7 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix uninitialised kfifo If a line is requested with debounce, and that results in debouncing in software, and the line is subsequently reconfigured to enable edge detection then the allocation of | |
| CVE-2024-36897 | Med | 5.5 | < 6.4.0-150600.23.7.3.150600.12.2.7 | 6.4.0-150600.23.7.3.150600.12.2.7 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Atom Integrated System Info v2_2 for DCN35 New request from KMD/VBIOS in order to support new UMA carveout model. This fixes a null dereference from accessing Ctx->dc_bios->integrated_info whil | |
| CVE-2024-36896 | Cri | 9.1 | < 6.4.0-150600.23.7.3.150600.12.2.7 | 6.4.0-150600.23.7.3.150600.12.2.7 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix access violation during port device removal Testing with KASAN and syzkaller revealed a bug in port.c:disable_store(): usb_hub_to_struct_hub() can return NULL if the hub that the port belongs to | |
| CVE-2024-36895 | Hig | 7.8 | < 6.4.0-150600.23.7.3.150600.12.2.7 | 6.4.0-150600.23.7.3.150600.12.2.7 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: use correct buffer size when parsing configfs lists This commit fixes uvc gadget support on 32-bit platforms. Commit 0df28607c5cb ("usb: gadget: uvc: Generalise helper functions for reuse") i |
- affected < 6.4.0-150600.23.14.2.150600.12.4.3fixed 6.4.0-150600.23.14.2.150600.12.4.3
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix nfc_llcp_setsockopt() unsafe copies syzbot reported unsafe calls to copy_from_sockptr() [1] Use copy_safe_from_sockptr() instead. [1] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip on writeback when it's not applicable [WHY] dynamic memory safety error detector (KASAN) catches and generates error messages "BUG: KASAN: slab-out-of-bounds" as writeback connector does n
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and t
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Don't free decrypted memory In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting m
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error i
- affected < 6.4.0-150600.23.33.1.150600.12.14.1fixed 6.4.0-150600.23.33.1.150600.12.14.1
In the Linux kernel, the following vulnerability has been resolved: blk-iocost: do not WARN if iocg was already offlined In iocg_pay_debt(), warn is triggered if 'active_list' is empty, which is intended to confirm iocg is active when it has debt. However, warn can be triggered
- affected < 6.4.0-150600.23.7.3.150600.12.2.7fixed 6.4.0-150600.23.7.3.150600.12.2.7
In the Linux kernel, the following vulnerability has been resolved: ARM: 9381/1: kasan: clear stale stack poison We found below OOB crash: [ 33.452494] ================================================================== [ 33.453513] BUG: KASAN: stack-out-of-bounds in refres
- affected < 6.4.0-150600.23.30.1.150600.12.12.6fixed 6.4.0-150600.23.30.1.150600.12.12.6
In the Linux kernel, the following vulnerability has been resolved: tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets TCP_SYN_RECV state is really special, it is only used by cross-syn connections, mostly used by fuzzers. In the following crash [1], syzbot managed to
- affected < 6.4.0-150600.23.14.2.150600.12.4.3fixed 6.4.0-150600.23.14.2.150600.12.4.3
In the Linux kernel, the following vulnerability has been resolved: tcp: Use refcount_inc_not_zero() in tcp_twsk_unique(). Anderson Nascimento reported a use-after-free splat in tcp_twsk_unique() with nice analysis. Since commit ec94c2696f0b ("tcp/dccp: avoid one atomic operat
- affected < 6.4.0-150600.23.14.2.150600.12.4.3fixed 6.4.0-150600.23.14.2.150600.12.4.3
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check FLOWI_FLAG_KNOWN_NH on fl6->flowi6_flags in
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action() syzbot is able to trigger the following crash [1], caused by unsafe ip6_dst_idev() use. Indeed ip6_dst_idev() can return NULL, and must a
- affected < 6.4.0-150600.23.17.1.150600.12.6.2fixed 6.4.0-150600.23.17.1.150600.12.6.2
In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent NULL dereference in ip6_output() According to syzbot, there is a chance that ip6_dst_idev() returns NULL in ip6_output(). Most places in IPv6 stack deal with a NULL idev just fine, but not here.
- affected < 6.4.0-150600.23.14.2.150600.12.4.3fixed 6.4.0-150600.23.14.2.150600.12.4.3
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when devlink reload during initialization The devlink reload process will access the hardware resources, but the register operation is done before the hardware is initialized. So, pr
- affected < 6.4.0-150600.23.14.2.150600.12.4.3fixed 6.4.0-150600.23.14.2.150600.12.4.3
In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: Fix use after free in lineinfo_changed_notify The use-after-free issue occurs as follows: when the GPIO chip device file is being closed by invoking gpio_chrdev_release(), watched_lines is freed
- affected < 6.4.0-150600.23.7.3.150600.12.2.7fixed 6.4.0-150600.23.7.3.150600.12.2.7
In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix uninitialised kfifo If a line is requested with debounce, and that results in debouncing in software, and the line is subsequently reconfigured to enable edge detection then the allocation of
- affected < 6.4.0-150600.23.7.3.150600.12.2.7fixed 6.4.0-150600.23.7.3.150600.12.2.7
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Atom Integrated System Info v2_2 for DCN35 New request from KMD/VBIOS in order to support new UMA carveout model. This fixes a null dereference from accessing Ctx->dc_bios->integrated_info whil
- affected < 6.4.0-150600.23.7.3.150600.12.2.7fixed 6.4.0-150600.23.7.3.150600.12.2.7
In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix access violation during port device removal Testing with KASAN and syzkaller revealed a bug in port.c:disable_store(): usb_hub_to_struct_hub() can return NULL if the hub that the port belongs to
- affected < 6.4.0-150600.23.7.3.150600.12.2.7fixed 6.4.0-150600.23.7.3.150600.12.2.7
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: use correct buffer size when parsing configfs lists This commit fixes uvc gadget support on 32-bit platforms. Commit 0df28607c5cb ("usb: gadget: uvc: Generalise helper functions for reuse") i
Page 155 of 188