VYPR

rpm package

suse/kgraft-patch-SLE12-SP3_Update_37&distro=SUSE OpenStack Cloud 8

pkg:rpm/suse/kgraft-patch-SLE12-SP3_Update_37&distro=SUSE%20OpenStack%20Cloud%208

Vulnerabilities (25)

  • CVE-2020-28915Nov 18, 2020
    affected < 1-4.3.1fixed 1-4.3.1

    A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.

  • CVE-2020-25285Sep 13, 2020
    affected < 1-4.3.1fixed 1-4.3.1

    A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.

  • CVE-2020-25211Sep 9, 2020
    affected < 1-4.3.1fixed 1-4.3.1

    In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c, aka CID-1cc5ef

  • CVE-2020-11668Apr 9, 2020
    affected < 1-4.3.1fixed 1-4.3.1

    In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.

  • CVE-2018-10902Aug 21, 2018
    affected < 1-4.3.1fixed 1-4.3.1

    It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local a

Page 2 of 2