VYPR

rpm package

suse/kgraft-patch-SLE12-SP2_Update_24&distro=SUSE Linux Enterprise Server 12 SP2-LTSS

pkg:rpm/suse/kgraft-patch-SLE12-SP2_Update_24&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS

Vulnerabilities (24)

  • CVE-2018-13406Jul 6, 2018
    affected < 1-3.7.1fixed 1-3.7.1

    An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used.

  • CVE-2018-13405Jul 6, 2018
    affected < 1-3.7.1fixed 1-3.7.1

    The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the no

  • CVE-2018-13053Jul 2, 2018
    affected < 1-3.7.1fixed 1-3.7.1

    The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used.

  • CVE-2018-5814Jun 12, 2018
    affected < 1-3.7.1fixed 1-3.7.1

    In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling probe, disconnect, and rebind operations can be exploited to trigger a use-after-free condition or a NULL pointer dereference by sending multiple USB over IP pa

Page 2 of 2