rpm package
suse/kernel-rt_debug&distro=SUSE Real Time Module 15 SP4
pkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Real%20Time%20Module%2015%20SP4
Vulnerabilities (277)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-3523 | Med | 5.3 | < 5.14.21-150400.15.18.1 | 5.14.21-150400.15.18.1 | Oct 16, 2022 | A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to | |
| CVE-2022-3521 | Low | 2.6 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Oct 16, 2022 | A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VD | |
| CVE-2022-42722 | Med | 5.5 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Oct 14, 2022 | In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices. | |
| CVE-2022-42721 | Med | 5.5 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Oct 14, 2022 | A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code. | |
| CVE-2022-42720 | Hig | 7.8 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Oct 14, 2022 | Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code. | |
| CVE-2022-41674 | Hig | 8.1 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Oct 14, 2022 | An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c. | |
| CVE-2022-42719 | Hig | 8.8 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Oct 13, 2022 | A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code. | |
| CVE-2022-42703 | Med | 5.5 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Oct 9, 2022 | mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse. | |
| CVE-2022-3435 | Med | 4.3 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Oct 8, 2022 | A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is | |
| CVE-2022-41850 | Med | 4.7 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 30, 2022 | roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress. | |
| CVE-2022-41849 | Med | 4.2 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 30, 2022 | drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect. | |
| CVE-2022-41848 | Med | 4.2 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 30, 2022 | drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition between mgslpc_ioctl and mgslpc_detach. | |
| CVE-2022-3303 | Med | 4.7 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 27, 2022 | A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system, | |
| CVE-2022-41218 | Med | 5.5 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 21, 2022 | In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release. | |
| CVE-2022-3239 | Hig | 7.8 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 19, 2022 | A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards. A local user could use this flaw to crash the system or potentially escalate their privileges on the system. | |
| CVE-2022-40768 | Med | 5.5 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 18, 2022 | drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. | |
| CVE-2022-3176 | Hig | 7.8 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 16, 2022 | There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle POLL | |
| CVE-2022-40476 | Med | 5.5 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 14, 2022 | A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service. | |
| CVE-2022-2977 | Hig | 7.8 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 14, 2022 | A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possible to escalate priv | |
| CVE-2022-3202 | Hig | 7.1 | < 5.14.21-150400.15.5.1 | 5.14.21-150400.15.5.1 | Sep 14, 2022 | A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information. |
- affected < 5.14.21-150400.15.18.1fixed 5.14.21-150400.15.18.1
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VD
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition between mgslpc_ioctl and mgslpc_detach.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system,
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle POLL
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possible to escalate priv
- affected < 5.14.21-150400.15.5.1fixed 5.14.21-150400.15.5.1
A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.
Page 12 of 14