VYPR

rpm package

suse/kernel-default-base&distro=SUSE Linux Enterprise Module for Basesystem 15 SP6

pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6

Vulnerabilities (3,752)

  • CVE-2025-38215MedJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var If fb_add_videomode() in do_register_framebuffer() fails to allocate memory for fb_videomode, it will later lead to a null-ptr

  • CVE-2025-38214MedJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var If fb_add_videomode() in fb_set_var() fails to allocate memory for fb_videomode, later it may lead to a null-ptr dereference in fb_videomod

  • CVE-2025-38212HigJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: ipc: fix to protect IPCS lookups using RCU syzbot reported that it discovered a use-after-free vulnerability, [0] [0]: https://lore.kernel.org/all/[email protected]/ idr_for_each() i

  • CVE-2025-38211CriJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction The commit 59c68ac31e15 ("iw_cm: free cm_id resources on the last deref") simplified cm_id resource management by freeing cm_id once all ref

  • CVE-2025-38210MedJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: configfs-tsm-report: Fix NULL dereference of tsm_ops Unlike sysfs, the lifetime of configfs objects is controlled by userspace. There is no mechanism for the kernel to find and delete all created config-items.

  • CVE-2025-38208MedJul 4, 2025
    affected < 6.4.0-150600.23.70.1.150600.12.30.2fixed 6.4.0-150600.23.70.1.150600.12.30.2

    In the Linux kernel, the following vulnerability has been resolved: smb: client: add NULL check in automount_fullpath page is checked for null in __build_path_from_dentry_optional_prefix when tcon->origin_fullpath is not set. However, the check is missing when it is set. Add a

  • CVE-2025-38206HigJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() exfat_create_upcase_table() : return error exfat_free_upcase_table() : fre

  • CVE-2025-38205MedJul 4, 2025
    affected < 6.4.0-150600.23.70.1.150600.12.30.2fixed 6.4.0-150600.23.70.1.150600.12.30.2

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 [Why] If the dummy values in `populate_dummy_dml_surface_cfg()` aren't updated then they can lead to a divide by zero in downstream callers

  • CVE-2025-38204HigJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds read in add_missing_indices stbl is s8 but it must contain offsets into slot which can go from 0 to 127. Added a bound check for that error and return -EIO if the check fails

  • CVE-2025-38203MedJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: jfs: Fix null-ptr-deref in jfs_ioc_trim [ Syzkaller Report ] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000087: 0000 [#1 KASAN: null-ptr-deref in range [0x0000000000000438-0

  • CVE-2025-38202MedJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() bpf_map_lookup_percpu_elem() helper is also available for sleepable bpf program. When BPF JIT is disabled or under 32-bit host, bpf_map_look

  • CVE-2025-38201HigJul 4, 2025
    affected < 6.4.0-150600.23.70.1.150600.12.30.2fixed 6.4.0-150600.23.70.1.150600.12.30.2

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX Otherwise, it is possible to hit WARN_ON_ONCE in __kvmalloc_node_noprof() when resizing hashtable because __GFP_NOWARN is unset. Similar to:

  • CVE-2025-38200MedJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: i40e: fix MMIO write access to an invalid page in i40e_clear_hw When the device sends a specific input, an integer underflow can occur, leading to MMIO write access to an invalid page. Prevent the integer unde

  • CVE-2025-38198HigJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: fbcon: Make sure modelist not set on unregistered console It looks like attempting to write to the "store_modes" sysfs node will run afoul of unregistered consoles: UBSAN: array-index-out-of-bounds in drivers/

  • CVE-2025-38197HigJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell_rbu: Fix list usage Pass the correct list head to list_for_each_entry*() when looping through the packet list. Without this patch, reading the packet data via sysfs will show the data incorr

  • CVE-2025-38194MedJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: jffs2: check that raw node were preallocated before writing summary Syzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault injection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doe

  • CVE-2025-38193HigJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: reject invalid perturb period Gerrard Tai reported that SFQ perturb_period has no range check yet, and this can be used to trigger a race condition fixed in a separate patch. We want to mak

  • CVE-2025-38192HigJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: net: clear the dst when changing skb protocol A not-so-careful NAT46 BPF program can crash the kernel if it indiscriminately flips ingress packets from v4 to v6: BUG: kernel NULL pointer dereference, address

  • CVE-2025-38190MedJul 4, 2025
    affected < 6.4.0-150600.23.70.1.150600.12.30.2fixed 6.4.0-150600.23.70.1.150600.12.30.2

    In the Linux kernel, the following vulnerability has been resolved: atm: Revert atm_account_tx() if copy_from_iter_full() fails. In vcc_sendmsg(), we account skb->truesize to sk->sk_wmem_alloc by atm_account_tx(). It is expected to be reverted by atm_pop_raw() later called by

  • CVE-2025-38188MedJul 4, 2025
    affected < 6.4.0-150600.23.65.1.150600.12.28.4fixed 6.4.0-150600.23.65.1.150600.12.28.4

    In the Linux kernel, the following vulnerability has been resolved: drm/msm/a7xx: Call CP_RESET_CONTEXT_STATE Calling this packet is necessary when we switch contexts because there are various pieces of state used by userspace to synchronize between BR and BV that are persisten

Page 41 of 188