VYPR

rpm package

suse/kernel-rt&distro=SUSE Linux Enterprise Real Time 12 SP3

pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2012%20SP3

Vulnerabilities (99)

  • CVE-2018-10124Apr 16, 2018
    affected < 4.4.128-3.11.1fixed 4.4.128-3.11.1

    The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service via an INT_MIN argument.

  • CVE-2018-10087Apr 13, 2018
    affected < 4.4.128-3.11.1fixed 4.4.128-3.11.1

    The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of the -INT_MIN value.

  • CVE-2017-18257Apr 4, 2018
    affected < 4.4.128-3.11.1fixed 4.4.128-3.11.1

    The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow and loop) via crafted use of the open and fallocate system calls with an FS_IOC_FIEMAP ioctl.

  • CVE-2017-13305Apr 4, 2018
    affected < 4.4.138-3.14.1fixed 4.4.138-3.14.1

    A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.

  • CVE-2018-1094Apr 2, 2018
    affected < 4.4.138-3.14.1fixed 4.4.138-3.14.1

    The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32c checksum driver, which allows attackers to cause a denial of service (ext4_xattr_inode_hash NULL pointer dereference and system crash) via a crafted ext4 imag

  • CVE-2018-1093Apr 2, 2018
    affected < 4.4.138-3.14.1fixed 4.4.138-3.14.1

    The ext4_valid_block_bitmap function in fs/ext4/balloc.c in the Linux kernel through 4.15.15 allows attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image because balloc.c and ialloc.c do not validate bitmap block numbers.

  • CVE-2018-1092Apr 2, 2018
    affected < 4.4.138-3.14.1fixed 4.4.138-3.14.1

    The ext4_iget function in fs/ext4/inode.c in the Linux kernel through 4.15.15 mishandles the case of a root directory with a zero i_links_count, which allows attackers to cause a denial of service (ext4_process_freed_data NULL pointer dereference and OOPS) via a crafted ext4 imag

  • CVE-2018-1091Mar 27, 2018
    affected < 4.4.128-3.11.1fixed 4.4.128-3.11.1

    In the flush_tmregs_to_thread function in arch/powerpc/kernel/ptrace.c in the Linux kernel before 4.13.5, a guest kernel crash can be triggered from unprivileged userspace during a core dump on a POWER host due to a missing processor feature check and an erroneous use of transact

  • CVE-2017-18249Mar 26, 2018
    affected < 4.4.138-3.14.1fixed 4.4.138-3.14.1

    The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.

  • CVE-2017-18241Mar 21, 2018
    affected < 4.4.138-3.14.1fixed 4.4.138-3.14.1

    fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a denial of service (NULL pointer dereference and panic) by using a noflush_merge option that triggers a NULL value for a flush_cmd_control data structure.

  • CVE-2018-8822Mar 20, 2018
    affected < 4.4.128-3.11.1fixed 4.4.128-3.11.1

    Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS servers to crash the

  • CVE-2018-8087Mar 13, 2018
    affected < 4.4.120-3.8.1fixed 4.4.120-3.8.1

    Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case.

  • CVE-2018-8043Mar 10, 2018
    affected < 4.4.128-3.11.1fixed 4.4.128-3.11.1

    The unimac_mdio_probe function in drivers/net/phy/mdio-bcm-unimac.c in the Linux kernel through 4.15.8 does not validate certain resource availability, which allows local users to cause a denial of service (NULL pointer dereference).

  • CVE-2018-7757Mar 8, 2018
    affected < 4.4.162-3.26.1fixed 4.4.162-3.26.1

    Memory leak in the sas_smp_get_phy_events function in drivers/scsi/libsas/sas_expander.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (memory consumption) via many read accesses to files in the /sys/class/sas_phy directory, as demonstrated by

  • CVE-2018-7740Mar 7, 2018
    affected < 4.4.128-3.11.1fixed 4.4.128-3.11.1

    The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system call.

  • CVE-2018-1065Mar 2, 2018
    affected < 4.4.138-3.14.1fixed 4.4.138-3.14.1

    The netfilter subsystem in the Linux kernel through 4.15.7 mishandles the case of a rule blob that contains a jump but lacks a user-defined chain, which allows local users to cause a denial of service (NULL pointer dereference) by leveraging the CAP_NET_RAW or CAP_NET_ADMIN capab

  • CVE-2017-18208Mar 1, 2018
    affected < 4.4.120-3.8.1fixed 4.4.120-3.8.1

    The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping.

  • CVE-2018-7492Feb 26, 2018
    affected < 4.4.138-3.14.1fixed 4.4.138-3.14.1

    A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST.

  • CVE-2018-7480Feb 25, 2018
    affected < 4.4.162-3.26.1fixed 4.4.162-3.26.1

    The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or possibly have unspecified other impact by triggering a creation failure.

  • CVE-2017-18174Feb 11, 2018
    affected < 4.4.120-3.8.1fixed 4.4.120-3.8.1

    In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.

Page 4 of 5