VYPR

rpm package

suse/kernel-syms&distro=SUSE Manager Server 4.3

pkg:rpm/suse/kernel-syms&distro=SUSE%20Manager%20Server%204.3

Vulnerabilities (1,882)

  • CVE-2022-3564Oct 17, 2022
    affected < 5.14.21-150400.24.167.1fixed 5.14.21-150400.24.167.1

    A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to

  • CVE-2022-3435Oct 8, 2022
    affected < 5.14.21-150400.24.141.1fixed 5.14.21-150400.24.141.1

    A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is

  • CVE-2022-3303Sep 27, 2022
    affected < 5.14.21-150400.24.158.1fixed 5.14.21-150400.24.158.1

    A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system,

  • CVE-2022-2977Sep 14, 2022
    affected < 5.14.21-150400.24.158.1fixed 5.14.21-150400.24.158.1

    A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possible to escalate priv

  • CVE-2022-2964Sep 9, 2022
    affected < 5.14.21-150400.24.128.1fixed 5.14.21-150400.24.128.1

    A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.

  • CVE-2022-2905Sep 9, 2022
    affected < 5.14.21-150400.24.170.1fixed 5.14.21-150400.24.170.1

    An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.

  • CVE-2022-1016Aug 29, 2022
    affected < 5.14.21-150400.24.161.1fixed 5.14.21-150400.24.161.1

    A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.

  • CVE-2022-1184Aug 29, 2022
    affected < 5.14.21-150400.24.158.1fixed 5.14.21-150400.24.158.1

    A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service.

  • CVE-2022-0168Aug 26, 2022
    affected < 5.14.21-150400.24.158.1fixed 5.14.21-150400.24.158.1

    A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet File System (CIFS) due to an incorrect return from the memdup_user function. This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to cr

  • CVE-2022-20368Aug 11, 2022
    affected < 5.14.21-150400.24.128.1fixed 5.14.21-150400.24.128.1

    Product: AndroidVersions: Android kernelAndroid ID: A-224546354References: Upstream kernel

  • CVE-2022-29900Jul 12, 2022
    affected < 5.14.21-150400.24.158.1fixed 5.14.21-150400.24.158.1

    Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

  • CVE-2022-29901Jul 12, 2022
    affected < 5.14.21-150400.24.158.1fixed 5.14.21-150400.24.158.1

    Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code exe

  • CVE-2022-20154Jun 15, 2022
    affected < 5.14.21-150400.24.116.1fixed 5.14.21-150400.24.116.1

    In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID:

  • CVE-2022-1679May 16, 2022
    affected < 5.14.21-150400.24.170.1fixed 5.14.21-150400.24.170.1

    A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.

  • CVE-2022-1048Apr 29, 2022
    affected < 5.14.21-150400.24.158.1fixed 5.14.21-150400.24.158.1

    A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalat

  • CVE-2022-0995Mar 25, 2022
    affected < 5.14.21-150400.24.158.1fixed 5.14.21-150400.24.158.1

    An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

  • CVE-2021-4148Mar 23, 2022
    affected < 5.14.21-150400.24.122.1fixed 5.14.21-150400.24.122.1

    A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.

  • CVE-2022-0854Mar 23, 2022
    affected < 5.14.21-150400.24.128.1fixed 5.14.21-150400.24.128.1

    A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.

  • CVE-2021-39698Mar 16, 2022
    affected < 5.14.21-150400.24.122.1fixed 5.14.21-150400.24.122.1

    In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android ke

  • CVE-2021-43527Dec 8, 2021
    affected < 5.14.21-150400.24.122.1fixed 5.14.21-150400.24.122.1

    NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted.

Page 94 of 95