VYPR

rpm package

suse/kernel-syms&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP1

pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1

Vulnerabilities (364)

  • CVE-2017-9077HigMay 19, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.

  • CVE-2017-9076HigMay 19, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.

  • CVE-2017-9075HigMay 19, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.

  • CVE-2017-9074HigMay 19, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact

  • CVE-2017-7487HigMay 14, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface.

  • CVE-2017-8925MedMay 12, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.

  • CVE-2017-8924MedMay 12, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial

  • CVE-2017-7472MedMay 11, 2017
    affected < 3.12.74-60.64.110.1fixed 3.12.74-60.64.110.1

    The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.

  • CVE-2017-8890HigMay 10, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.

  • CVE-2017-8831MedMay 8, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequence-number value, aka a "do

  • CVE-2017-8106MedApr 24, 2017
    affected < 3.12.74-60.64.40.1fixed 3.12.74-60.64.40.1

    The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer.

  • CVE-2017-7645HigApr 18, 2017
    affected < 3.12.74-60.64.40.1fixed 3.12.74-60.64.40.1

    The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and fs/nfsd/nfsxdr.c.

  • CVE-2017-7889HigApr 17, 2017
    affected < 3.12.74-60.64.63.1fixed 3.12.74-60.64.63.1

    The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions) via an application

  • CVE-2017-7616MedApr 10, 2017
    affected < 3.12.74-60.64.40.1fixed 3.12.74-60.64.40.1

    Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation.

  • CVE-2017-2671MedApr 5, 2017
    affected < 3.12.74-60.64.40.1fixed 3.12.74-60.64.40.1

    The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the

  • CVE-2017-2647HigMar 31, 2017
    affected < 3.12.74-60.64.40.1fixed 3.12.74-60.64.40.1

    The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyri

  • CVE-2017-7308HigMar 29, 2017
    affected < 3.12.74-60.64.40.1fixed 3.12.74-60.64.40.1

    The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_N

  • CVE-2017-7294HigMar 29, 2017
    affected < 3.12.74-60.64.40.1fixed 3.12.74-60.64.40.1

    The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does not validate addition of certain levels data, which allows local users to trigger an integer overflow and out-of-bounds write, and cause a denial of service (s

  • CVE-2017-7273MedMar 27, 2017
    affected < 3.12.74-60.64.110.1fixed 3.12.74-60.64.110.1

    The cp_report_fixup function in drivers/hid/hid-cypress.c in the Linux kernel 3.2 and 4.x before 4.9.4 allows physically proximate attackers to cause a denial of service (integer underflow) or possibly have unspecified other impact via a crafted HID report.

  • CVE-2017-7261MedMar 24, 2017
    affected < 3.12.74-60.64.40.1fixed 3.12.74-60.64.40.1

    The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to cause a denial of service (ZERO_SIZE_PTR dereference, and GPF and possibly panic

Page 12 of 19