VYPR

rpm package

suse/kernel-syms&distro=SUSE OpenStack Cloud Crowbar 8

pkg:rpm/suse/kernel-syms&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208

Vulnerabilities (347)

  • CVE-2020-8992Feb 14, 2020
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.

  • CVE-2020-8647Feb 6, 2020
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.

  • CVE-2020-8648Feb 6, 2020
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.

  • CVE-2020-8649Feb 6, 2020
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.

  • CVE-2019-14615Jan 17, 2020
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.

  • CVE-2019-19332Jan 9, 2020
    affected < 4.4.180-94.113.1fixed 4.4.180-94.113.1

    An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access t

  • CVE-2019-20096Dec 30, 2019
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.

  • CVE-2019-20054Dec 28, 2019
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links, aka CID-23da9588037e.

  • CVE-2019-19965Dec 25, 2019
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.

  • CVE-2019-19966Dec 25, 2019
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.

  • CVE-2019-5108Dec 23, 2019
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to d

  • CVE-2019-19767Dec 12, 2019
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.

  • CVE-2019-19768Dec 12, 2019
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer).

  • CVE-2019-19447Dec 8, 2019
    affected < 4.4.180-94.116.1fixed 4.4.180-94.116.1

    In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.

  • CVE-2019-19523Dec 3, 2019
    affected < 4.4.180-94.113.1fixed 4.4.180-94.113.1

    In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79.

  • CVE-2019-19524Dec 3, 2019
    affected < 4.4.180-94.113.1fixed 4.4.180-94.113.1

    In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/input/ff-memless.c driver, aka CID-fa3a5a1880c9.

  • CVE-2019-19525Dec 3, 2019
    affected < 4.4.180-94.113.1fixed 4.4.180-94.113.1

    In the Linux kernel before 5.3.6, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/ieee802154/atusb.c driver, aka CID-7fd25e6fc035.

  • CVE-2019-19527Dec 3, 2019
    affected < 4.4.180-94.113.1fixed 4.4.180-94.113.1

    In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driver, aka CID-9c09b214f30e.

  • CVE-2019-19530Dec 3, 2019
    affected < 4.4.180-94.113.1fixed 4.4.180-94.113.1

    In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/class/cdc-acm.c driver, aka CID-c52873e5a1ef.

  • CVE-2019-19531Dec 3, 2019
    affected < 4.4.180-94.113.1fixed 4.4.180-94.113.1

    In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/yurex.c driver, aka CID-fc05481b2fca.

Page 12 of 18