VYPR

rpm package

suse/kernel-livepatch-SLE15-SP1_Update_36&distro=SUSE Linux Enterprise Live Patching 15 SP1

pkg:rpm/suse/kernel-livepatch-SLE15-SP1_Update_36&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP1

Vulnerabilities (47)

  • CVE-2022-41850Sep 30, 2022
    affected < 1-150100.3.5.1fixed 1-150100.3.5.1

    roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress.

  • CVE-2022-40768Sep 18, 2022
    affected < 1-150100.3.5.1fixed 1-150100.3.5.1

    drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.

  • CVE-2022-40307Sep 9, 2022
    affected < 1-150100.3.5.1fixed 1-150100.3.5.1

    An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.

  • CVE-2022-3169Sep 9, 2022
    affected < 1-150100.3.5.1fixed 1-150100.3.5.1

    A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_IOCTL_RESET and the NVME_IOCTL_SUBSYS_RESET through the device file of the driver, resulting in a PCIe link disconnect.

  • CVE-2022-2964Sep 9, 2022
    affected < 1-150100.3.5.1fixed 1-150100.3.5.1

    A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.

  • CVE-2022-2153Aug 31, 2022
    affected < 1-150100.3.5.1fixed 1-150100.3.5.1

    A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl

  • CVE-2021-4037Aug 24, 2022
    affected < 1-150100.3.5.1fixed 1-150100.3.5.1

    A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a direct

Page 3 of 3