VYPR

rpm package

suse/kernel-syms&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP5

pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5

Vulnerabilities (1,486)

  • CVE-2019-16994Sep 30, 2019
    affected < 4.12.14-122.17.1fixed 4.12.14-122.17.1

    In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev, which may cause denial of service, aka CID-07f12b26e21a.

  • CVE-2019-16746Sep 24, 2019
    affected < 4.12.14-122.12.1fixed 4.12.14-122.12.1

    An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.

  • CVE-2019-14821Sep 19, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first

  • CVE-2019-14835Sep 17, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the

  • CVE-2019-15031Sep 13, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then access

  • CVE-2019-15030Sep 13, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbe

  • CVE-2019-16231Sep 11, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • CVE-2019-16233Sep 11, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • CVE-2019-9455Sep 6, 2019
    affected < 4.12.14-122.23.1fixed 4.12.14-122.23.1

    In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2019-9458Sep 6, 2019
    affected < 4.12.14-122.20.1fixed 4.12.14-122.20.1

    In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2019-9456Sep 6, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2017-18595Sep 4, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c.

  • CVE-2019-15916Sep 4, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    An issue was discovered in the Linux kernel before 5.0.1. There is a memory leak in register_queue_kobjects() in net/core/net-sysfs.c, which will cause denial of service.

  • CVE-2019-15213Aug 19, 2019
    affected < 4.12.14-122.12.1fixed 4.12.14-122.12.1

    An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.

  • CVE-2019-9506Aug 14, 2019
    affected < 4.12.14-122.7.1fixed 4.12.14-122.7.1

    The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inje

  • CVE-2018-20836May 7, 2019
    affected < 4.12.14-122.20.1fixed 4.12.14-122.20.1

    An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.

  • CVE-2019-3900Apr 25, 2019
    affected < 4.12.14-122.88.1fixed 4.12.14-122.88.1

    An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could

  • CVE-2019-3874Mar 25, 2019
    affected < 4.12.14-122.88.1fixed 4.12.14-122.88.1

    The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.

  • CVE-2018-20669Mar 18, 2019
    affected < 4.12.14-122.57.1fixed 4.12.14-122.57.1

    An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary kern

  • CVE-2019-3701Jan 3, 2019
    affected < 4.12.14-122.20.1fixed 4.12.14-122.20.1

    An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can create a CAN frame mod

Page 74 of 75