VYPR

rpm package

suse/kgraft-patch-SLE12-SP3_Update_36&distro=SUSE OpenStack Cloud Crowbar 8

pkg:rpm/suse/kgraft-patch-SLE12-SP3_Update_36&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208

Vulnerabilities (21)

  • CVE-2020-25668May 26, 2021
    affected < 1-4.5.1fixed 1-4.5.1

    A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.

  • CVE-2020-14351Dec 3, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data confidenti

  • CVE-2020-14381Dec 3, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiali

  • CVE-2020-25656Dec 2, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidential

  • CVE-2020-12352Nov 23, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

  • CVE-2020-25705Nov 17, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well

  • CVE-2020-8694Nov 12, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-25645Oct 13, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic u

  • CVE-2020-25641Oct 6, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic priv

  • CVE-2020-25643Oct 6, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threa

  • CVE-2020-26088Sep 24, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.

  • CVE-2020-14390Sep 18, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.

  • CVE-2020-0432Sep 17, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android

  • CVE-2020-0431Sep 17, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android

  • CVE-2020-0404Sep 17, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Produ

  • CVE-2020-0427Sep 17, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAnd

  • CVE-2020-25284Sep 13, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.

  • CVE-2020-25212Sep 9, 2020
    affected < 1-4.5.1fixed 1-4.5.1

    A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

  • CVE-2019-19063Nov 18, 2019
    affected < 1-4.5.1fixed 1-4.5.1

    Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption), aka CID-3f9361695113.

  • CVE-2019-6133Jan 11, 2019
    affected < 1-4.5.1fixed 1-4.5.1

    In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.

Page 1 of 2