rpm package
suse/kernel-source-rt&distro=SUSE Linux Enterprise Micro 5.5
pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.5
Vulnerabilities (4,559)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-53229 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix invalid drv_sta_pre_rcu_remove calls for non-uploaded sta Avoid potential data corruption issues caused by uninitialized driver private data structures. | ||
| CVE-2023-53226 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix OOB and integer underflow when rx packets Make sure mwifiex_process_mgmt_packet, mwifiex_process_sta_rx_packet and mwifiex_process_uap_rx_packet, mwifiex_uap_queue_bridged_pkt and mwifiex_pro | ||
| CVE-2023-53223 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: Add missing check for alloc_ordered_workqueue Add check for the return value of alloc_ordered_workqueue as it may return NULL pointer and cause NULL pointer dereference. Patchwork: https://patchwo | ||
| CVE-2023-53222 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: jfs: jfs_dmap: Validate db_l2nbperpage while mounting In jfs_dmap.c at line 381, BLKTODMAP is used to get a logical block number inside dbFree(). db_l2nbperpage, which is the log2 number of blocks per page, is | ||
| CVE-2023-53219 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: netup_unidvb: fix use-after-free at del_timer() When Universal DVB card is detaching, netup_unidvb_dma_fini() uses del_timer() to stop dma->timeout timer. But when timer handler netup_unidvb_dma_timeout( | ||
| CVE-2023-53216 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: arm64: efi: Make efi_rt_lock a raw_spinlock Running a rt-kernel base on 6.2.0-rc3-rt1 on an Ampere Altra outputs the following: BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt | ||
| CVE-2023-53215 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched/fair: Don't balance task to its current running CPU We've run into the case that the balancer tries to balance a migration disabled task and trigger the warning in set_task_cpu() like below: ----------- | ||
| CVE-2023-53213 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of-bounds read that occurs in kmemdup() called from brcmf_get_assoc_ies(). The bug could occur when assoc_info->req_len, data from | ||
| CVE-2023-53210 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: md/raid5-cache: fix null-ptr-deref for r5l_flush_stripe_to_raid() r5l_flush_stripe_to_raid() will check if the list 'flushing_ios' is empty, and then submit 'flush_bio', however, r5l_log_flush_endio() is cleari | ||
| CVE-2023-53205 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do check for target CPU == -1, but this might change at the time we are going to use it. Hold the physical target CPU in a local vari | ||
| CVE-2023-53201 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound of the mbox producer index correctly. Currently the wraparound happens once u32 max is reached. Bit 31 of the producer index r | ||
| CVE-2023-53199 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: clean up skbs if ath9k_hif_usb_rx_stream() fails Syzkaller detected a memory leak of skbs in ath9k_hif_usb_rx_stream(). While processing skbs in ath9k_hif_usb_rx_stream(), the already allo | ||
| CVE-2022-50289 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix memory leak in ocfs2_stack_glue_init() ocfs2_table_header should be free in ocfs2_stack_glue_init() if ocfs2_sysfs_init() failed, otherwise kmemleak will report memleak. BUG: memory leak unreference | ||
| CVE-2022-50288 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: qlcnic: prevent ->dcb use-after-free on qlcnic_dcb_enable() failure adapter->dcb would get silently freed inside qlcnic_dcb_enable() in case qlcnic_dcb_attach() would return an error, which always happens under | ||
| CVE-2022-50287 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: fix a memory leak in generate_lfp_data_ptrs When (size != 0 || ptrs->lvds_ entries != 3), the program tries to free() the ptrs. However, the ptrs is not created by calling kzmalloc(), but is obta | ||
| CVE-2022-50286 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline When converting files with inline data to extents, delayed allocations made on a file system created with both the bigalloc and inline o | ||
| CVE-2022-50282 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: chardev: fix error handling in cdev_device_add() While doing fault injection test, I got the following report: ------------[ cut here ]------------ kobject: '(null)' (0000000039956980): is not initialized, yet | ||
| CVE-2022-50280 | — | < 5.14.21-150500.13.115.1 | 5.14.21-150500.13.115.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propag | ||
| CVE-2022-50279 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: Fix global-out-of-bounds bug in _rtl8812ae_phy_set_txpower_limit() There is a global-out-of-bounds reported by KASAN: BUG: KASAN: global-out-of-bounds in _rtl8812ae_eq_n_byte.part.0+0x3d/0x8 | ||
| CVE-2022-50278 | — | < 5.14.21-150500.13.109.1 | 5.14.21-150500.13.109.1 | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: PNP: fix name memory leak in pnp_alloc_dev() After commit 1fa5ae857bb1 ("driver core: get rid of struct device's bus_id string array"), the name of device is allocated dynamically, move dev_set_name() after pnp |
- CVE-2023-53229Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix invalid drv_sta_pre_rcu_remove calls for non-uploaded sta Avoid potential data corruption issues caused by uninitialized driver private data structures.
- CVE-2023-53226Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix OOB and integer underflow when rx packets Make sure mwifiex_process_mgmt_packet, mwifiex_process_sta_rx_packet and mwifiex_process_uap_rx_packet, mwifiex_uap_queue_bridged_pkt and mwifiex_pro
- CVE-2023-53223Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: Add missing check for alloc_ordered_workqueue Add check for the return value of alloc_ordered_workqueue as it may return NULL pointer and cause NULL pointer dereference. Patchwork: https://patchwo
- CVE-2023-53222Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: jfs: jfs_dmap: Validate db_l2nbperpage while mounting In jfs_dmap.c at line 381, BLKTODMAP is used to get a logical block number inside dbFree(). db_l2nbperpage, which is the log2 number of blocks per page, is
- CVE-2023-53219Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: media: netup_unidvb: fix use-after-free at del_timer() When Universal DVB card is detaching, netup_unidvb_dma_fini() uses del_timer() to stop dma->timeout timer. But when timer handler netup_unidvb_dma_timeout(
- CVE-2023-53216Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: arm64: efi: Make efi_rt_lock a raw_spinlock Running a rt-kernel base on 6.2.0-rc3-rt1 on an Ampere Altra outputs the following: BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt
- CVE-2023-53215Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: sched/fair: Don't balance task to its current running CPU We've run into the case that the balancer tries to balance a migration disabled task and trigger the warning in set_task_cpu() like below: -----------
- CVE-2023-53213Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of-bounds read that occurs in kmemdup() called from brcmf_get_assoc_ies(). The bug could occur when assoc_info->req_len, data from
- CVE-2023-53210Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: md/raid5-cache: fix null-ptr-deref for r5l_flush_stripe_to_raid() r5l_flush_stripe_to_raid() will check if the list 'flushing_ios' is empty, and then submit 'flush_bio', however, r5l_log_flush_endio() is cleari
- CVE-2023-53205Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do check for target CPU == -1, but this might change at the time we are going to use it. Hold the physical target CPU in a local vari
- CVE-2023-53201Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound of the mbox producer index correctly. Currently the wraparound happens once u32 max is reached. Bit 31 of the producer index r
- CVE-2023-53199Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: clean up skbs if ath9k_hif_usb_rx_stream() fails Syzkaller detected a memory leak of skbs in ath9k_hif_usb_rx_stream(). While processing skbs in ath9k_hif_usb_rx_stream(), the already allo
- CVE-2022-50289Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix memory leak in ocfs2_stack_glue_init() ocfs2_table_header should be free in ocfs2_stack_glue_init() if ocfs2_sysfs_init() failed, otherwise kmemleak will report memleak. BUG: memory leak unreference
- CVE-2022-50288Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: qlcnic: prevent ->dcb use-after-free on qlcnic_dcb_enable() failure adapter->dcb would get silently freed inside qlcnic_dcb_enable() in case qlcnic_dcb_attach() would return an error, which always happens under
- CVE-2022-50287Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: fix a memory leak in generate_lfp_data_ptrs When (size != 0 || ptrs->lvds_ entries != 3), the program tries to free() the ptrs. However, the ptrs is not created by calling kzmalloc(), but is obta
- CVE-2022-50286Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline When converting files with inline data to extents, delayed allocations made on a file system created with both the bigalloc and inline o
- CVE-2022-50282Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: chardev: fix error handling in cdev_device_add() While doing fault injection test, I got the following report: ------------[ cut here ]------------ kobject: '(null)' (0000000039956980): is not initialized, yet
- CVE-2022-50280Sep 15, 2025affected < 5.14.21-150500.13.115.1fixed 5.14.21-150500.13.115.1
In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propag
- CVE-2022-50279Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: Fix global-out-of-bounds bug in _rtl8812ae_phy_set_txpower_limit() There is a global-out-of-bounds reported by KASAN: BUG: KASAN: global-out-of-bounds in _rtl8812ae_eq_n_byte.part.0+0x3d/0x8
- CVE-2022-50278Sep 15, 2025affected < 5.14.21-150500.13.109.1fixed 5.14.21-150500.13.109.1
In the Linux kernel, the following vulnerability has been resolved: PNP: fix name memory leak in pnp_alloc_dev() After commit 1fa5ae857bb1 ("driver core: get rid of struct device's bus_id string array"), the name of device is allocated dynamically, move dev_set_name() after pnp
Page 46 of 228