VYPR

rpm package

suse/kgraft-patch-SLE12-SP2_Update_28&distro=SUSE OpenStack Cloud 7

pkg:rpm/suse/kgraft-patch-SLE12-SP2_Update_28&distro=SUSE%20OpenStack%20Cloud%207

Vulnerabilities (6)

  • CVE-2019-2024Jun 19, 2019
    affected < 1-3.3.1fixed 1-3.3.1

    In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use after free issue. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID:

  • CVE-2019-7222Mar 17, 2019
    affected < 1-3.3.1fixed 1-3.3.1

    The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

  • CVE-2019-7221Mar 17, 2019
    affected < 1-3.3.1fixed 1-3.3.1

    The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.

  • CVE-2019-9213Mar 5, 2019
    affected < 1-3.3.1fixed 1-3.3.1

    In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the wrong task.

  • CVE-2019-6974Feb 15, 2019
    affected < 1-3.3.1fixed 1-3.3.1

    In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.

  • CVE-2018-14633Sep 25, 2018
    affected < 1-3.3.1fixed 1-3.3.1

    A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes