CVE-2024-3618
published 2024-04-11CVE-2024-3618: A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown…
PriorityP346high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.71%
49.2th percentile
A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file /control/activate_case.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-260274 is the identifier assigned to this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mayurik | advocate_office_management_system | — | — |
| sourcecodester | kortex_lite_advocate_office_management_system | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:L/Au:M/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-27048 kernel: wifi: brcm80211: handle pmk_op allocation failure
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-27048 [MEDIUM] CVE-2024-27048 kernel: wifi: brcm80211: handle pmk_op allocation failure
CVE-2024-27048 kernel: wifi: brcm80211: handle pmk_op allocation failure
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcm80211: handle pmk_op allocation failure
The Linux kernel CVE team has assigned CVE-2024-27048 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050114-CVE-2024-27048-016f@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278432]
---
It's a small (32 bytes) GFP_KERNEL memory allocation. It just won't fail in practice.
I suggest impact Low.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red
Bugzilla
CVE-2024-27052 kernel: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work
bugzilla·2024-05-01·CVSS 7.4
CVE-2024-27052 [HIGH] CVE-2024-27052 kernel: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work
CVE-2024-27052 kernel: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work
In the Linux kernel, the following vulnerability has been resolved:
wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work
The Linux kernel CVE team has assigned CVE-2024-27052 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050115-CVE-2024-27052-fb6d@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278418]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
This i
Bugzilla
CVE-2024-26964 kernel: usb: xhci: Add error handling in xhci_map_urb_for_dma
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-26964 [MEDIUM] CVE-2024-26964 kernel: usb: xhci: Add error handling in xhci_map_urb_for_dma
CVE-2024-26964 kernel: usb: xhci: Add error handling in xhci_map_urb_for_dma
In the Linux kernel, the following vulnerability has been resolved:
usb: xhci: Add error handling in xhci_map_urb_for_dma
The Linux kernel CVE team has assigned CVE-2024-26964 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050130-CVE-2024-26964-54c8@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278170]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The resu
Bugzilla
CVE-2024-27056 kernel: wifi: iwlwifi: mvm: ensure offloading TID queue exists
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-27056 [MEDIUM] CVE-2024-27056 kernel: wifi: iwlwifi: mvm: ensure offloading TID queue exists
CVE-2024-27056 kernel: wifi: iwlwifi: mvm: ensure offloading TID queue exists
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: ensure offloading TID queue exists
The Linux kernel CVE team has assigned CVE-2024-27056 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050115-CVE-2024-27056-98c0@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278410]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
This i
Bugzilla
CVE-2024-27059 kernel: USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-27059 [MEDIUM] CVE-2024-27059 kernel: USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command
CVE-2024-27059 kernel: USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command
In the Linux kernel, the following vulnerability has been resolved:
USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command
The Linux kernel CVE team has assigned CVE-2024-27059 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050130-CVE-2024-27059-baaa@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278399]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-
Bugzilla
CVE-2022-48669 kernel: powerpc/pseries: Fix potential memleak in papr_get_attr()
bugzilla·2024-05-01·CVSS 5.5
CVE-2022-48669 [MEDIUM] CVE-2022-48669 kernel: powerpc/pseries: Fix potential memleak in papr_get_attr()
CVE-2022-48669 kernel: powerpc/pseries: Fix potential memleak in papr_get_attr()
In the Linux kernel, the following vulnerability has been resolved:
powerpc/pseries: Fix potential memleak in papr_get_attr()
The Linux kernel CVE team has assigned CVE-2022-48669 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050131-CVE-2022-48669-15cf@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278538]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2022-48669 is: CHECK Maybe valid. Check manually. with impact LOW (that is a
Bugzilla
CVE-2024-26973 kernel: fat: fix uninitialized field in nostale filehandles
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-26973 [MEDIUM] CVE-2024-26973 kernel: fat: fix uninitialized field in nostale filehandles
CVE-2024-26973 kernel: fat: fix uninitialized field in nostale filehandles
In the Linux kernel, the following vulnerability has been resolved:
fat: fix uninitialized field in nostale filehandles
The Linux kernel CVE team has assigned CVE-2024-26973 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050132-CVE-2024-26973-54a3@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278357]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result o
Bugzilla
CVE-2024-26933 kernel: USB: core: Fix deadlock in port "disable" sysfs attribute
bugzilla·2024-05-01·CVSS 7.8
CVE-2024-26933 [HIGH] CVE-2024-26933 kernel: USB: core: Fix deadlock in port "disable" sysfs attribute
CVE-2024-26933 kernel: USB: core: Fix deadlock in port "disable" sysfs attribute
In the Linux kernel, the following vulnerability has been resolved:
USB: core: Fix deadlock in port "disable" sysfs attribute
The Linux kernel CVE team has assigned CVE-2024-26933 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050123-CVE-2024-26933-c18d@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278241]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
Bugzilla
CVE-2024-27014 kernel: net/mlx5e: Prevent deadlock while disabling aRFS
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-27014 [MEDIUM] CVE-2024-27014 kernel: net/mlx5e: Prevent deadlock while disabling aRFS
CVE-2024-27014 kernel: net/mlx5e: Prevent deadlock while disabling aRFS
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Prevent deadlock while disabling aRFS
The Linux kernel CVE team has assigned CVE-2024-27014 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050149-CVE-2024-27014-d2dc@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278269]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
This issue has bee
Bugzilla
CVE-2024-26934 kernel: USB: core: Fix deadlock in usb_deauthorize_interface()
bugzilla·2024-05-01·CVSS 7.8
CVE-2024-26934 [HIGH] CVE-2024-26934 kernel: USB: core: Fix deadlock in usb_deauthorize_interface()
CVE-2024-26934 kernel: USB: core: Fix deadlock in usb_deauthorize_interface()
In the Linux kernel, the following vulnerability has been resolved:
USB: core: Fix deadlock in usb_deauthorize_interface()
The Linux kernel CVE team has assigned CVE-2024-26934 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050123-CVE-2024-26934-e2fc@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278238]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The re
Bugzilla
CVE-2024-26872 kernel: RDMA/srpt: Do not register event handler until srpt device is fully setup
bugzilla·2024-04-17·CVSS 7.0
CVE-2024-26872 [HIGH] CVE-2024-26872 kernel: RDMA/srpt: Do not register event handler until srpt device is fully setup
CVE-2024-26872 kernel: RDMA/srpt: Do not register event handler until srpt device is fully setup
In the Linux kernel, the following vulnerability has been resolved:
RDMA/srpt: Do not register event handler until srpt device is fully setup
The Linux kernel CVE team has assigned CVE-2024-26872 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041738-CVE-2024-26872-2d38@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275708]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.
Bugzilla
CVE-2024-26897 kernel: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete
bugzilla·2024-04-17·CVSS 4.7
CVE-2024-26897 [MEDIUM] CVE-2024-26897 kernel: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete
CVE-2024-26897 kernel: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete
The Linux kernel CVE team has assigned CVE-2024-26897 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041744-CVE-2024-26897-5382@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275656]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redha
Bugzilla
CVE-2024-26919 kernel: usb: ulpi: Fix debugfs directory leak
bugzilla·2024-04-17·CVSS 5.5
CVE-2024-26919 [MEDIUM] CVE-2024-26919 kernel: usb: ulpi: Fix debugfs directory leak
CVE-2024-26919 kernel: usb: ulpi: Fix debugfs directory leak
In the Linux kernel, the following vulnerability has been resolved:
usb: ulpi: Fix debugfs directory leak
The Linux kernel CVE team has assigned CVE-2024-26919 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041738-CVE-2024-26919-5100@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275780]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is d
Bugzilla
CVE-2024-26892 kernel: wifi: mt76: mt7921e: fix use-after-free in free_irq()
bugzilla·2024-04-17·CVSS 7.8
CVE-2024-26892 [HIGH] CVE-2024-26892 kernel: wifi: mt76: mt7921e: fix use-after-free in free_irq()
CVE-2024-26892 kernel: wifi: mt76: mt7921e: fix use-after-free in free_irq()
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921e: fix use-after-free in free_irq()
The Linux kernel CVE team has assigned CVE-2024-26892 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041743-CVE-2024-26892-809e@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275667]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
moved tr
Bugzilla
CVE-2024-26901 kernel: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
bugzilla·2024-04-17·CVSS 5.5
CVE-2024-26901 [MEDIUM] CVE-2024-26901 kernel: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
CVE-2024-26901 kernel: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
In the Linux kernel, the following vulnerability has been resolved:
do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
The Linux kernel CVE team has assigned CVE-2024-26901 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041745-CVE-2024-26901-34e7@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275646]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:362
Bugzilla
CVE-2021-47185 kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
bugzilla·2024-04-11·CVSS 4.4
CVE-2021-47185 [MEDIUM] CVE-2021-47185 kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
CVE-2021-47185 kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
In the Linux kernel, the following vulnerability has been resolved:
tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
The Linux kernel CVE team has assigned CVE-2021-47185 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041033-CVE-2021-47185-c363@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE
Bugzilla
CVE-2024-26743 kernel: RDMA/qedr: Fix qedr_create_user_qp error flow
bugzilla·2024-04-04·CVSS 5.5
CVE-2024-26743 [MEDIUM] CVE-2024-26743 kernel: RDMA/qedr: Fix qedr_create_user_qp error flow
CVE-2024-26743 kernel: RDMA/qedr: Fix qedr_create_user_qp error flow
In the Linux kernel, the following vulnerability has been resolved:
RDMA/qedr: Fix qedr_create_user_qp error flow
The Linux kernel CVE team has assigned CVE-2024-26743 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040301-CVE-2024-26743-6034@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273263]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic
Bugzilla
CVE-2024-26779 kernel: wifi: mac80211: fix race condition on enabling fast-xmit
bugzilla·2024-04-04·CVSS 5.5
CVE-2024-26779 [MEDIUM] CVE-2024-26779 kernel: wifi: mac80211: fix race condition on enabling fast-xmit
CVE-2024-26779 kernel: wifi: mac80211: fix race condition on enabling fast-xmit
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix race condition on enabling fast-xmit
The Linux kernel CVE team has assigned CVE-2024-26779 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040310-CVE-2024-26779-8030@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273224]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
Th
Bugzilla
CVE-2024-26744 kernel: RDMA/srpt: Support specifying the srpt_service_guid parameter
bugzilla·2024-04-04·CVSS 5.5
CVE-2024-26744 [MEDIUM] CVE-2024-26744 kernel: RDMA/srpt: Support specifying the srpt_service_guid parameter
CVE-2024-26744 kernel: RDMA/srpt: Support specifying the srpt_service_guid parameter
In the Linux kernel, the following vulnerability has been resolved:
RDMA/srpt: Support specifying the srpt_service_guid parameter
The Linux kernel CVE team has assigned CVE-2024-26744 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040301-CVE-2024-26744-d344@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273261]
---
Isn't this just a root-can-shoot-himself-in-the-foot bug? Why is it a CVE?
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Ente
Bugzilla
CVE-2024-26694 kernel: wifi: iwlwifi: fix double-free bug
bugzilla·2024-04-03·CVSS 7.8
CVE-2024-26694 [HIGH] CVE-2024-26694 kernel: wifi: iwlwifi: fix double-free bug
CVE-2024-26694 kernel: wifi: iwlwifi: fix double-free bug
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: fix double-free bug
The Linux kernel CVE team has assigned CVE-2024-26694 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040337-CVE-2024-26694-b216@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273093]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is develop
Bugzilla
CVE-2024-26659 kernel: xhci: handle isoc Babble and Buffer Overrun events properly
bugzilla·2024-04-02·CVSS 5.5
CVE-2024-26659 [MEDIUM] CVE-2024-26659 kernel: xhci: handle isoc Babble and Buffer Overrun events properly
CVE-2024-26659 kernel: xhci: handle isoc Babble and Buffer Overrun events properly
In the Linux kernel, the following vulnerability has been resolved:
xhci: handle isoc Babble and Buffer Overrun events properly
The Linux kernel CVE team has assigned CVE-2024-26659 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040222-CVE-2024-26659-e4f6@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272781]
---
This was fixed for Fedora with the 6.7.5 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Bugzilla
CVE-2024-26664 kernel: hwmon: (coretemp) Fix out-of-bounds memory access
bugzilla·2024-04-02·CVSS 7.1
CVE-2024-26664 [HIGH] CVE-2024-26664 kernel: hwmon: (coretemp) Fix out-of-bounds memory access
CVE-2024-26664 kernel: hwmon: (coretemp) Fix out-of-bounds memory access
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (coretemp) Fix out-of-bounds memory access
The Linux kernel CVE team has assigned CVE-2024-26664 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040223-CVE-2024-26664-03db@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272792]
---
This was fixed for Fedora with the 6.7.5 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627
Bugzilla
CVE-2021-47171 kernel: net: usb: fix memory leak in smsc75xx_bind
bugzilla·2024-03-25·CVSS 5.5
CVE-2021-47171 [MEDIUM] CVE-2021-47171 kernel: net: usb: fix memory leak in smsc75xx_bind
CVE-2021-47171 kernel: net: usb: fix memory leak in smsc75xx_bind
In the Linux kernel, the following vulnerability has been resolved:
net: usb: fix memory leak in smsc75xx_bind
The Linux kernel CVE team has assigned CVE-2021-47171 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024032536-CVE-2021-47171-f223@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2021-47171 is: CHECK Maybe valid.
Bugzilla
CVE-2021-47153 kernel: i2c: i801: Don't generate an interrupt on bus reset
bugzilla·2024-03-25·CVSS 7.1
CVE-2021-47153 [HIGH] CVE-2021-47153 kernel: i2c: i801: Don't generate an interrupt on bus reset
CVE-2021-47153 kernel: i2c: i801: Don't generate an interrupt on bus reset
In the Linux kernel, the following vulnerability has been resolved:
i2c: i801: Don't generate an interrupt on bus reset
The Linux kernel CVE team has assigned CVE-2021-47153 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024032501-CVE-2021-47153-8c75@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2021-47153 is:
Bugzilla
CVE-2021-47118 kernel: pid: take a reference when initializing `cad_pid`
bugzilla·2024-03-16·CVSS 7.8
CVE-2021-47118 [HIGH] CVE-2021-47118 kernel: pid: take a reference when initializing `cad_pid`
CVE-2021-47118 kernel: pid: take a reference when initializing `cad_pid`
In the Linux kernel, the following vulnerability has been resolved:
pid: take a reference when initializing `cad_pid`
The Linux kernel CVE team has assigned CVE-2021-47118 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024031509-CVE-2021-47118-faf2@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2269858]
---
This was fixed for Fedora with the 5.12.10 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:
Bugzilla
CVE-2024-26610 kernel: wifi: iwlwifi: fix a memory corruption
bugzilla·2024-03-12·CVSS 7.8
CVE-2024-26610 [HIGH] CVE-2024-26610 kernel: wifi: iwlwifi: fix a memory corruption
CVE-2024-26610 kernel: wifi: iwlwifi: fix a memory corruption
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: fix a memory corruption
The Linux kernel CVE team has assigned CVE-2024-26610 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2269215]
---
This was fixed for Fedora with the 6.7.3 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redh
Bugzilla
CVE-2023-52595 kernel: wifi: rt2x00: restart beacon queue when hardware reset
bugzilla·2024-03-06·CVSS 5.5
CVE-2023-52595 [MEDIUM] CVE-2023-52595 kernel: wifi: rt2x00: restart beacon queue when hardware reset
CVE-2023-52595 kernel: wifi: rt2x00: restart beacon queue when hardware reset
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: restart beacon queue when hardware reset
The Linux kernel CVE team has assigned CVE-2023-52595 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030645-CVE-2023-52595-d018@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268316]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-
Bugzilla
CVE-2023-52598 kernel: s390/ptrace: handle setting of fpc register correctly
bugzilla·2024-03-06·CVSS 7.1
CVE-2023-52598 [HIGH] CVE-2023-52598 kernel: s390/ptrace: handle setting of fpc register correctly
CVE-2023-52598 kernel: s390/ptrace: handle setting of fpc register correctly
In the Linux kernel, the following vulnerability has been resolved:
s390/ptrace: handle setting of fpc register correctly
The Linux kernel CVE team has assigned CVE-2023-52598 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030646-CVE-2023-52598-d0a2@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268310]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52598 is:
Bugzilla
CVE-2023-52594 kernel: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
bugzilla·2024-03-06·CVSS 7.8
CVE-2023-52594 [HIGH] CVE-2023-52594 kernel: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
CVE-2023-52594 kernel: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
The Linux kernel CVE team has assigned CVE-2023-52594 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030645-CVE-2023-52594-9b84@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268318]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the foll
Bugzilla
CVE-2023-52606 kernel: powerpc/lib: Validate size for vector operations
bugzilla·2024-03-06·CVSS 5.5
CVE-2023-52606 [MEDIUM] CVE-2023-52606 kernel: powerpc/lib: Validate size for vector operations
CVE-2023-52606 kernel: powerpc/lib: Validate size for vector operations
In the Linux kernel, the following vulnerability has been resolved:
powerpc/lib: Validate size for vector operations
The Linux kernel CVE team has assigned CVE-2023-52606 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030647-CVE-2023-52606-fdcc@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268294]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52606 is: CHECK May
Bugzilla
CVE-2023-52607 kernel: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
bugzilla·2024-03-06·CVSS 5.5
CVE-2023-52607 [MEDIUM] CVE-2023-52607 kernel: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
CVE-2023-52607 kernel: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
In the Linux kernel, the following vulnerability has been resolved:
powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
The Linux kernel CVE team has assigned CVE-2023-52607 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030647-CVE-2023-52607-75d1@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268292]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
The result of automatic check (that is developed by Alexander Larkin) for this CV
Bugzilla
CVE-2023-52528 kernel: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
bugzilla·2024-03-04·CVSS 5.5
CVE-2023-52528 [MEDIUM] CVE-2023-52528 kernel: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
CVE-2023-52528 kernel: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
In the Linux kernel, the following vulnerability has been resolved:
net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
The Linux kernel CVE team has assigned CVE-2023-52528 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030254-CVE-2023-52528-c33b@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Lar
Bugzilla
CVE-2023-52513 kernel: RDMA/siw: Fix connection failure handling
bugzilla·2024-03-04·CVSS 5.5
CVE-2023-52513 [MEDIUM] CVE-2023-52513 kernel: RDMA/siw: Fix connection failure handling
CVE-2023-52513 kernel: RDMA/siw: Fix connection failure handling
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Fix connection failure handling
The Linux kernel CVE team has assigned CVE-2023-52513 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030251-CVE-2023-52513-5224@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52513 is: CHECK Maybe valid
Bugzilla
CVE-2023-52520 kernel: platform/x86: think-lmi: Fix reference leak
bugzilla·2024-03-04·CVSS 5.5
CVE-2023-52520 [MEDIUM] CVE-2023-52520 kernel: platform/x86: think-lmi: Fix reference leak
CVE-2023-52520 kernel: platform/x86: think-lmi: Fix reference leak
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix reference leak
The Linux kernel CVE team has assigned CVE-2023-52520 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030252-CVE-2023-52520-0a4e@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52520 is: CHECK Maybe v
Bugzilla
CVE-2024-23307 kernel: Integer Overflow in raid5_cache_count
bugzilla·2024-03-04·CVSS 7.8
CVE-2024-23307 [HIGH] CVE-2024-23307 kernel: Integer Overflow in raid5_cache_count
CVE-2024-23307 kernel: Integer Overflow in raid5_cache_count
Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows Forced Integer Overflow.
Refer:
https://lore.kernel.org/linux-raid/[email protected]/#r
https://patchwork.kernel.org/project/linux-raid/patch/[email protected]/
https://bugzilla.openanolis.cn/show_bug.cgi?id=7975
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267706]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Bugzilla
CVE-2023-52565 kernel: media: uvcvideo: out-of-bounds read in uvc_query_v4l2_menu()
bugzilla·2024-03-04·CVSS 7.1
CVE-2023-52565 [HIGH] CVE-2023-52565 kernel: media: uvcvideo: out-of-bounds read in uvc_query_v4l2_menu()
CVE-2023-52565 kernel: media: uvcvideo: out-of-bounds read in uvc_query_v4l2_menu()
In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Fix OOB read
The Linux kernel CVE team has assigned CVE-2023-52565 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030254-CVE-2023-52565-07ce@gregkh/
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52565 is: CHECK Maybe va
Bugzilla
CVE-2022-48627 kernel: vt: fix memory overlapping when deleting chars in the buffer
bugzilla·2024-03-03·CVSS 5.5
CVE-2022-48627 [MEDIUM] CVE-2022-48627 kernel: vt: fix memory overlapping when deleting chars in the buffer
CVE-2022-48627 kernel: vt: fix memory overlapping when deleting chars in the buffer
In the Linux kernel, the following vulnerability has been resolved:
vt: fix memory overlapping when deleting chars in the buffer
The Linux kernel CVE team has assigned CVE-2022-48627 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030252-CVE-2022-48627-c7bf@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267510]
---
This was fixed for Fedora with the 5.18.13 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise L
Bugzilla
CVE-2024-26615 kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump
bugzilla·2024-03-01·CVSS 5.5
CVE-2024-26615 [MEDIUM] CVE-2024-26615 kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump
CVE-2024-26615 kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix illegal rmb_desc access in SMC-D connection dump
The Linux kernel CVE team has assigned CVE-2024-26615 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267356]
---
This was fixed for Fedora with the 6.7.3 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterpris
Bugzilla
CVE-2021-47055 kernel: mtd: require write permissions for locking and badblock ioctls
bugzilla·2024-03-01·CVSS 5.5
CVE-2021-47055 [MEDIUM] CVE-2021-47055 kernel: mtd: require write permissions for locking and badblock ioctls
CVE-2021-47055 kernel: mtd: require write permissions for locking and badblock ioctls
In the Linux kernel, the following vulnerability has been resolved:
mtd: require write permissions for locking and badblock ioctls
The Linux kernel CVE team has assigned CVE-2021-47055 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024022950-CVE-2021-47055-6927@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267186]
---
This was fixed for Fedora with the 5.12.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterpris
Bugzilla
CVE-2023-52477 kernel: usb: hub: Guard against accesses to uninitialized BOS descriptors
bugzilla·2024-02-29·CVSS 5.5
CVE-2023-52477 [MEDIUM] CVE-2023-52477 kernel: usb: hub: Guard against accesses to uninitialized BOS descriptors
CVE-2023-52477 kernel: usb: hub: Guard against accesses to uninitialized BOS descriptors
In the Linux kernel, the following vulnerability has been resolved:
usb: hub: Guard against accesses to uninitialized BOS descriptors
The Linux kernel CVE team has assigned CVE-2023-52477 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024022921-CVE-2023-52477-6f20@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267039]
---
This was fixed for Fedora with the 6.5.8 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Ente
Bugzilla
CVE-2020-36777 kernel: media: dvbdev: Fix memory leak in dvb_media_device_free()
bugzilla·2024-02-28·CVSS 5.5
CVE-2020-36777 [MEDIUM] CVE-2020-36777 kernel: media: dvbdev: Fix memory leak in dvb_media_device_free()
CVE-2020-36777 kernel: media: dvbdev: Fix memory leak in dvb_media_device_free()
In the Linux kernel, the following vulnerability has been resolved:
media: dvbdev: Fix memory leak in dvb_media_device_free()
The Linux kernel CVE team has assigned CVE-2020-36777 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2266747]
---
This was fixed for Fedora with the 5.11.20 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Ente
Bugzilla
CVE-2021-46934 kernel: i2c: validate user data in compat ioctl
bugzilla·2024-02-27·CVSS 3.3
CVE-2021-46934 [LOW] CVE-2021-46934 kernel: i2c: validate user data in compat ioctl
CVE-2021-46934 kernel: i2c: validate user data in compat ioctl
In the Linux kernel, the following vulnerability has been resolved:
i2c: validate user data in compat ioctl
The Linux kernel CVE team has assigned CVE-2021-46934 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024022750-CVE-2021-46934-79c8@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2266447]
---
This was fixed for Fedora with the 5.15.13 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.
Bugzilla
CVE-2024-26603 kernel: x86/fpu: Stop relying on userspace for info to fault in xsave buffer that cause loop forever
bugzilla·2024-02-24·CVSS 5.5
CVE-2024-26603 [MEDIUM] CVE-2024-26603 kernel: x86/fpu: Stop relying on userspace for info to fault in xsave buffer that cause loop forever
CVE-2024-26603 kernel: x86/fpu: Stop relying on userspace for info to fault in xsave buffer that cause loop forever
In the Linux kernel, the following vulnerability has been resolved:
x86/fpu: Stop relying on userspace for info to fault in xsave buffer
The Linux kernel CVE team has assigned CVE-2024-26603 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024022415-CVE-2024-26603-42c2@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2265834]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https
Bugzilla
CVE-2023-52445 kernel: pvrusb2: fix use after free on context disconnection
bugzilla·2024-02-23·CVSS 7.8
CVE-2023-52445 [HIGH] CVE-2023-52445 kernel: pvrusb2: fix use after free on context disconnection
CVE-2023-52445 kernel: pvrusb2: fix use after free on context disconnection
media: pvrusb2: fix use after free on context disconnection
Upon module load, a kthread is created targeting the
pvr2_context_thread_func function, which may call pvr2_context_destroy
and thus call kfree() on the context object. However, that might happen
before the usb hub_event handler is able to notify the driver. This
patch adds a sanity check before the invalid read reported by syzbot,
within the context disconnection call stack.
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267102]
---
This was fixed for Fedora with the 6.6.14 stable kernel update.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://
https://github.com/zyairelai/CVE-submissions/blob/main/kortex-activate_case-sqli.mdhttps://vuldb.com/?ctiid.260274https://vuldb.com/?id.260274https://vuldb.com/?submit.312807https://github.com/zyairelai/CVE-submissions/blob/main/kortex-activate_case-sqli.mdhttps://vuldb.com/?ctiid.260274https://vuldb.com/?id.260274https://vuldb.com/?submit.312807
2024-04-11
Published