VYPR

rpm package

suse/kgraft-patch-SLE12-SP1_Update_4&distro=SUSE Linux Enterprise Live Patching 12

pkg:rpm/suse/kgraft-patch-SLE12-SP1_Update_4&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012

Vulnerabilities (30)

  • CVE-2016-3139MedApr 27, 2016
    affected < 1-2.3fixed 1-2.3

    The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

  • CVE-2016-3134HigApr 27, 2016
    affected < 2-2.2fixed 2-2.2

    The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

  • CVE-2016-2782MedApr 27, 2016
    affected < 1-2.3fixed 1-2.3

    The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1

  • CVE-2016-2384MedApr 27, 2016
    affected < 1-2.3fixed 1-2.3

    Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor.

  • CVE-2016-2184MedApr 27, 2016
    affected < 1-2.3fixed 1-2.3

    The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value i

  • CVE-2016-2143HigApr 27, 2016
    affected < 1-2.3fixed 1-2.3

    The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted application, related to arch/s390/i

  • CVE-2015-8816MedApr 27, 2016
    affected < 1-2.3fixed 1-2.3

    The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspe

  • CVE-2015-8812CriApr 27, 2016
    affected < 1-2.3fixed 1-2.3

    drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.

  • CVE-2015-8709HigFeb 8, 2016
    affected < 1-2.3fixed 1-2.3

    kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. N

  • CVE-2013-7446MedDec 28, 2015
    affected < 2-2.2fixed 2-2.2

    Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.

Page 2 of 2