VYPR

rpm package

suse/kernel-docs-azure&distro=SUSE Linux Enterprise Software Development Kit 12 SP3

pkg:rpm/suse/kernel-docs-azure&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3

Vulnerabilities (28)

  • CVE-2018-10877Jul 18, 2018
    affected < 4.4.155-4.16.1fixed 4.4.155-4.16.1

    Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.

  • CVE-2018-1129Jul 10, 2018
    affected < 4.4.155-4.16.1fixed 4.4.155-4.16.1

    A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, lumi

  • CVE-2018-1128Jul 10, 2018
    affected < 4.4.155-4.16.1fixed 4.4.155-4.16.1

    It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and p

  • CVE-2018-13095Jul 3, 2018
    affected < 4.4.155-4.16.1fixed 4.4.155-4.16.1

    An issue was discovered in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.17.3. A denial of service (memory corruption and BUG) can occur for a corrupted xfs image upon encountering an inode that is in extent format, but has more extents than fit in the inode fork.

  • CVE-2018-13094Jul 3, 2018
    affected < 4.4.155-4.16.1fixed 4.4.155-4.16.1

    An issue was discovered in fs/xfs/libxfs/xfs_attr_leaf.c in the Linux kernel through 4.17.3. An OOPS may occur for a corrupted xfs image after xfs_da_shrink_inode() is called with a NULL bp.

  • CVE-2018-13093Jul 3, 2018
    affected < 4.4.155-4.16.1fixed 4.4.155-4.16.1

    An issue was discovered in fs/xfs/xfs_icache.c in the Linux kernel through 4.17.3. There is a NULL pointer dereference and panic in lookup_slow() on a NULL inode->i_ops pointer when doing pathwalks on a corrupted xfs image. This occurs because of a lack of proper validation that

  • CVE-2018-12896Jul 2, 2018
    affected < 4.4.155-4.16.1fixed 4.4.155-4.16.1

    An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the a

  • CVE-2018-10940May 9, 2018
    affected < 4.4.155-4.16.1fixed 4.4.155-4.16.1

    The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers to use a incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED ioctl to read out kernel memory.

Page 2 of 2