CVE-2024-9315
published 2024-09-28CVE-2024-9315: A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as critical. This issue affects some unknown…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.53%
41.2th percentile
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_department.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oretnom23 | employee_and_visitor_gate_pass_logging_system | — | — |
| sourcecodester | employee_and_visitor_gate_pass_logging_system | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-36974 kernel: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
bugzilla·2024-06-18·CVSS 7.8
CVE-2024-36974 [HIGH] CVE-2024-36974 kernel: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
CVE-2024-36974 kernel: net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
In the Linux kernel, the following vulnerability has been resolved:
net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
The Linux kernel CVE team has assigned CVE-2024-36974 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024061810-CVE-2024-36974-a482@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-36967 kernel: KEYS: trusted: Fix memory leak in tpm2_key_encode()
bugzilla·2024-06-14·CVSS 5.5
CVE-2024-36967 [MEDIUM] CVE-2024-36967 kernel: KEYS: trusted: Fix memory leak in tpm2_key_encode()
CVE-2024-36967 kernel: KEYS: trusted: Fix memory leak in tpm2_key_encode()
In the Linux kernel, the following vulnerability has been resolved:
KEYS: trusted: Fix memory leak in tpm2_key_encode()
The Linux kernel CVE team has assigned CVE-2024-36967 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024060804-CVE-2024-36967-b73d@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-36882 kernel: mm: use memalloc_nofs_save() in page_cache_ra_order()
bugzilla·2024-06-02·CVSS 5.5
CVE-2024-36882 [MEDIUM] CVE-2024-36882 kernel: mm: use memalloc_nofs_save() in page_cache_ra_order()
CVE-2024-36882 kernel: mm: use memalloc_nofs_save() in page_cache_ra_order()
In the Linux kernel, the following vulnerability has been resolved:
mm: use memalloc_nofs_save() in page_cache_ra_order()
The Linux kernel CVE team has assigned CVE-2024-36882 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024053032-CVE-2024-36882-79ff@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2284274]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2021-47428 kernel: powerpc/64s: fix program check interrupt emergency stack path
bugzilla·2024-05-22·CVSS 5.5
CVE-2021-47428 [MEDIUM] CVE-2021-47428 kernel: powerpc/64s: fix program check interrupt emergency stack path
CVE-2021-47428 kernel: powerpc/64s: fix program check interrupt emergency stack path
In the Linux kernel, the following vulnerability has been resolved:
powerpc/64s: fix program check interrupt emergency stack path
The Linux kernel CVE team has assigned CVE-2021-47428 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052157-CVE-2021-47428-f3c0@gregkh/T
Discussion:
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2021-47428 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built).
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2023-52869 kernel: pstore/platform: Add check for kstrdup
bugzilla·2024-05-22·CVSS 5.5
CVE-2023-52869 [MEDIUM] CVE-2023-52869 kernel: pstore/platform: Add check for kstrdup
CVE-2023-52869 kernel: pstore/platform: Add check for kstrdup
In the Linux kernel, the following vulnerability has been resolved:
pstore/platform: Add check for kstrdup
The Linux kernel CVE team has assigned CVE-2023-52869 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052120-CVE-2023-52869-6f57@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2023-52819 kernel: drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga
bugzilla·2024-05-22·CVSS 6.6
CVE-2023-52819 [MEDIUM] CVE-2023-52819 kernel: drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga
CVE-2023-52819 kernel: drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga
In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga
The Linux kernel CVE team has assigned CVE-2023-52819 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052105-CVE-2023-52819-98d5@gregkh/T
Discussion:
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52819 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built).
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-35918 kernel: randomize_kstack: Improve entropy diffusion
bugzilla·2024-05-20
CVE-2024-35918 CVE-2024-35918 kernel: randomize_kstack: Improve entropy diffusion
CVE-2024-35918 kernel: randomize_kstack: Improve entropy diffusion
In the Linux kernel, the following vulnerability has been resolved:
randomize_kstack: Improve entropy diffusion
The Linux kernel CVE team has assigned CVE-2024-35918 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051912-CVE-2024-35918-3fed@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281784]
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2024-35918 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built).
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.r
Bugzilla
CVE-2023-52664 kernel: net: atlantic: eliminate double free in error handling logic
bugzilla·2024-05-18·CVSS 7.8
CVE-2023-52664 [HIGH] CVE-2023-52664 kernel: net: atlantic: eliminate double free in error handling logic
CVE-2023-52664 kernel: net: atlantic: eliminate double free in error handling logic
In the Linux kernel, the following vulnerability has been resolved:
net: atlantic: eliminate double free in error handling logic
The Linux kernel CVE team has assigned CVE-2023-52664 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051756-CVE-2023-52664-dea1@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281357]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-35812 kernel: usb: cdc-wdm: close race between read and workqueue
bugzilla·2024-05-17
CVE-2024-35812 CVE-2024-35812 kernel: usb: cdc-wdm: close race between read and workqueue
CVE-2024-35812 kernel: usb: cdc-wdm: close race between read and workqueue
In the Linux kernel, the following vulnerability has been resolved:
usb: cdc-wdm: close race between read and workqueue
The Linux kernel CVE team has assigned CVE-2024-35812 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051741-CVE-2024-35812-c804@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281212]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2022-48703 kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR
bugzilla·2024-05-03·CVSS 5.5
CVE-2022-48703 [MEDIUM] CVE-2022-48703 kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR
CVE-2022-48703 kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR
In the Linux kernel, the following vulnerability has been resolved:
thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR
The Linux kernel CVE team has assigned CVE-2022-48703 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050351-CVE-2022-48703-3099@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26988 kernel: init/main.c: Fix potential static_command_line memory overflow
bugzilla·2024-05-01·CVSS 7.8
CVE-2024-26988 [HIGH] CVE-2024-26988 kernel: init/main.c: Fix potential static_command_line memory overflow
CVE-2024-26988 kernel: init/main.c: Fix potential static_command_line memory overflow
In the Linux kernel, the following vulnerability has been resolved:
init/main.c: Fix potential static_command_line memory overflow
The Linux kernel CVE team has assigned CVE-2024-26988 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050143-CVE-2024-26988-c304@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278325]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2023-52649 kernel: drm/vkms: Avoid reading beyond LUT array
bugzilla·2024-05-01·CVSS 7.8
CVE-2023-52649 [HIGH] CVE-2023-52649 kernel: drm/vkms: Avoid reading beyond LUT array
CVE-2023-52649 kernel: drm/vkms: Avoid reading beyond LUT array
In the Linux kernel, the following vulnerability has been resolved:
drm/vkms: Avoid reading beyond LUT array
The Linux kernel CVE team has assigned CVE-2023-52649 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050109-CVE-2023-52649-4614@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278525]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26937 kernel: drm/i915/gt: Reset queue_priority_hint on parking
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-26937 [MEDIUM] CVE-2024-26937 kernel: drm/i915/gt: Reset queue_priority_hint on parking
CVE-2024-26937 kernel: drm/i915/gt: Reset queue_priority_hint on parking
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gt: Reset queue_priority_hint on parking
The Linux kernel CVE team has assigned CVE-2024-26937 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050124-CVE-2024-26937-3d21@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278232]
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2024-26937 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built).
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 http
Bugzilla
CVE-2024-26984 kernel: nouveau: fix instmem race condition around ptr stores
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-26984 [MEDIUM] CVE-2024-26984 kernel: nouveau: fix instmem race condition around ptr stores
CVE-2024-26984 kernel: nouveau: fix instmem race condition around ptr stores
In the Linux kernel, the following vulnerability has been resolved:
nouveau: fix instmem race condition around ptr stores
The Linux kernel CVE team has assigned CVE-2024-26984 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050142-CVE-2024-26984-3028@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278334]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.4 Extended Update Support
Via RHSA-2024:9546 https://access.redhat.com/errata/RHS
Bugzilla
CVE-2024-27004 kernel: clk: Get runtime PM before walking tree during disable_unused
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-27004 [MEDIUM] CVE-2024-27004 kernel: clk: Get runtime PM before walking tree during disable_unused
CVE-2024-27004 kernel: clk: Get runtime PM before walking tree during disable_unused
In the Linux kernel, the following vulnerability has been resolved:
clk: Get runtime PM before walking tree during disable_unused
The Linux kernel CVE team has assigned CVE-2024-27004 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050147-CVE-2024-27004-c429@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278292]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26922 kernel: drm/amdgpu: validate the parameters of bo mapping operations more clearly
bugzilla·2024-04-23·CVSS 5.5
CVE-2024-26922 [MEDIUM] CVE-2024-26922 kernel: drm/amdgpu: validate the parameters of bo mapping operations more clearly
CVE-2024-26922 kernel: drm/amdgpu: validate the parameters of bo mapping operations more clearly
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: validate the parameters of bo mapping operations more clearly
The Linux kernel CVE team has assigned CVE-2024-26922 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024042317-CVE-2024-26922-896d@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2276666]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26900 kernel: md: fix kmemleak of rdev->serial
bugzilla·2024-04-17·CVSS 5.5
CVE-2024-26900 [MEDIUM] CVE-2024-26900 kernel: md: fix kmemleak of rdev->serial
CVE-2024-26900 kernel: md: fix kmemleak of rdev->serial
In the Linux kernel, the following vulnerability has been resolved:
md: fix kmemleak of rdev->serial
The Linux kernel CVE team has assigned CVE-2024-26900 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041745-CVE-2024-26900-70a3@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275648]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26890 kernel: Bluetooth: btrtl: fix out of bounds memory access
bugzilla·2024-04-17·CVSS 6.5
CVE-2024-26890 [MEDIUM] CVE-2024-26890 kernel: Bluetooth: btrtl: fix out of bounds memory access
CVE-2024-26890 kernel: Bluetooth: btrtl: fix out of bounds memory access
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btrtl: fix out of bounds memory access
The Linux kernel CVE team has assigned CVE-2024-26890 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041742-CVE-2024-26890-4239@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275671]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26838 kernel: RDMA/irdma: Fix KASAN issue with tasklet
bugzilla·2024-04-17·CVSS 5.5
CVE-2024-26838 [MEDIUM] CVE-2024-26838 kernel: RDMA/irdma: Fix KASAN issue with tasklet
CVE-2024-26838 kernel: RDMA/irdma: Fix KASAN issue with tasklet
In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Fix KASAN issue with tasklet
The Linux kernel CVE team has assigned CVE-2024-26838 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041715-CVE-2024-26838-2fdb@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275579]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26857 kernel: geneve: make sure to pull inner header in geneve_rx()
bugzilla·2024-04-17·CVSS 5.5
CVE-2024-26857 [MEDIUM] CVE-2024-26857 kernel: geneve: make sure to pull inner header in geneve_rx()
CVE-2024-26857 kernel: geneve: make sure to pull inner header in geneve_rx()
In the Linux kernel, the following vulnerability has been resolved:
geneve: make sure to pull inner header in geneve_rx()
The Linux kernel CVE team has assigned CVE-2024-26857 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041724-CVE-2024-26857-75ac@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275738]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26846 kernel: nvme-fc: do not wait in vain when unloading module
bugzilla·2024-04-17·CVSS 4.4
CVE-2024-26846 [MEDIUM] CVE-2024-26846 kernel: nvme-fc: do not wait in vain when unloading module
CVE-2024-26846 kernel: nvme-fc: do not wait in vain when unloading module
In the Linux kernel, the following vulnerability has been resolved:
nvme-fc: do not wait in vain when unloading module
The Linux kernel CVE team has assigned CVE-2024-26846 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041717-CVE-2024-26846-9593@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275559]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
---
This issue has
Bugzilla
CVE-2024-26862 kernel: packet: annotate data-races around ignore_outgoing
bugzilla·2024-04-17·CVSS 4.7
CVE-2024-26862 [MEDIUM] CVE-2024-26862 kernel: packet: annotate data-races around ignore_outgoing
CVE-2024-26862 kernel: packet: annotate data-races around ignore_outgoing
In the Linux kernel, the following vulnerability has been resolved:
packet: annotate data-races around ignore_outgoing
The Linux kernel CVE team has assigned CVE-2024-26862 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041736-CVE-2024-26862-2605@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275728]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
---
Are there any updates on this issue? I have been accessing Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315 https://timecalcula
Bugzilla
CVE-2023-52643 kernel: iio: core: fix memleak in iio_device_register_sysfs
bugzilla·2024-04-17·CVSS 5.5
CVE-2023-52643 [MEDIUM] CVE-2023-52643 kernel: iio: core: fix memleak in iio_device_register_sysfs
CVE-2023-52643 kernel: iio: core: fix memleak in iio_device_register_sysfs
In the Linux kernel, the following vulnerability has been resolved:
iio: core: fix memleak in iio_device_register_sysfs
The Linux kernel CVE team has assigned CVE-2023-52643 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041701-CVE-2023-52643-8834@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275625]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26863 kernel: hsr: Fix uninit-value access in hsr_get_node()
bugzilla·2024-04-17·CVSS 5.5
CVE-2024-26863 [MEDIUM] CVE-2024-26863 kernel: hsr: Fix uninit-value access in hsr_get_node()
CVE-2024-26863 kernel: hsr: Fix uninit-value access in hsr_get_node()
In the Linux kernel, the following vulnerability has been resolved:
hsr: Fix uninit-value access in hsr_get_node()
The Linux kernel CVE team has assigned CVE-2024-26863 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041736-CVE-2024-26863-b742@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275726]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26782 kernel: mptcp: fix double-free on socket dismantle
bugzilla·2024-04-04·CVSS 7.8
CVE-2024-26782 [HIGH] CVE-2024-26782 kernel: mptcp: fix double-free on socket dismantle
CVE-2024-26782 kernel: mptcp: fix double-free on socket dismantle
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix double-free on socket dismantle
The Linux kernel CVE team has assigned CVE-2024-26782 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040458-CVE-2024-26782-71ca@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273469]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26707 kernel: net: hsr: remove WARN_ONCE() in send_hsr_supervision_frame()
bugzilla·2024-04-03·CVSS 5.5
CVE-2024-26707 [MEDIUM] CVE-2024-26707 kernel: net: hsr: remove WARN_ONCE() in send_hsr_supervision_frame()
CVE-2024-26707 kernel: net: hsr: remove WARN_ONCE() in send_hsr_supervision_frame()
In the Linux kernel, the following vulnerability has been resolved:
net: hsr: remove WARN_ONCE() in send_hsr_supervision_frame()
The Linux kernel CVE team has assigned CVE-2024-26707 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040341-CVE-2024-26707-1153@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273169]
---
Does not seems to have a security impact.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26679 kernel: inet: read sk->sk_family once in inet_recv_error()
bugzilla·2024-04-03·CVSS 5.5
CVE-2024-26679 [MEDIUM] CVE-2024-26679 kernel: inet: read sk->sk_family once in inet_recv_error()
CVE-2024-26679 kernel: inet: read sk->sk_family once in inet_recv_error()
In the Linux kernel, the following vulnerability has been resolved:
inet: read sk->sk_family once in inet_recv_error()
The Linux kernel CVE team has assigned CVE-2024-26679 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040253-CVE-2024-26679-d520@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272840]
---
This was fixed for Fedora with the 6.7.5 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26767 kernel: drm/amd/display: fixed integer types and null check locations
bugzilla·2024-04-03·CVSS 5.5
CVE-2024-26767 [MEDIUM] CVE-2024-26767 kernel: drm/amd/display: fixed integer types and null check locations
CVE-2024-26767 kernel: drm/amd/display: fixed integer types and null check locations
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: fixed integer types and null check locations
The Linux kernel CVE team has assigned CVE-2024-26767 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040306-CVE-2024-26767-bdac@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273186]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26700 kernel: drm/amd/display: Fix MST Null Ptr for RV
bugzilla·2024-04-03·CVSS 5.5
CVE-2024-26700 [MEDIUM] CVE-2024-26700 kernel: drm/amd/display: Fix MST Null Ptr for RV
CVE-2024-26700 kernel: drm/amd/display: Fix MST Null Ptr for RV
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix MST Null Ptr for RV
The Linux kernel CVE team has assigned CVE-2024-26700 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040339-CVE-2024-26700-a2b8@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273114]
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2024-26700 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built).
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.
Bugzilla
CVE-2024-26708 kernel: mptcp: really cope with fastopen race
bugzilla·2024-04-03·CVSS 5.5
CVE-2024-26708 [MEDIUM] CVE-2024-26708 kernel: mptcp: really cope with fastopen race
CVE-2024-26708 kernel: mptcp: really cope with fastopen race
In the Linux kernel, the following vulnerability has been resolved:
mptcp: really cope with fastopen race
The Linux kernel CVE team has assigned CVE-2024-26708 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040341-CVE-2024-26708-c98a@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273167]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26725 kernel: dpll: fix possible deadlock during netlink dump operation
bugzilla·2024-04-03·CVSS 5.5
CVE-2024-26725 [MEDIUM] CVE-2024-26725 kernel: dpll: fix possible deadlock during netlink dump operation
CVE-2024-26725 kernel: dpll: fix possible deadlock during netlink dump operation
In the Linux kernel, the following vulnerability has been resolved:
dpll: fix possible deadlock during netlink dump operation
The Linux kernel CVE team has assigned CVE-2024-26725 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040346-CVE-2024-26725-d16b@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273131]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26719 kernel: nouveau: offload fence uevents work to workqueue
bugzilla·2024-04-03·CVSS 5.5
CVE-2024-26719 [MEDIUM] CVE-2024-26719 kernel: nouveau: offload fence uevents work to workqueue
CVE-2024-26719 kernel: nouveau: offload fence uevents work to workqueue
In the Linux kernel, the following vulnerability has been resolved:
nouveau: offload fence uevents work to workqueue
The Linux kernel CVE team has assigned CVE-2024-26719 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040344-CVE-2024-26719-b66e@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273144]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26674 kernel: x86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups
bugzilla·2024-04-02·CVSS 7.1
CVE-2024-26674 [HIGH] CVE-2024-26674 kernel: x86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups
CVE-2024-26674 kernel: x86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups
In the Linux kernel, the following vulnerability has been resolved:
x86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups
The Linux kernel CVE team has assigned CVE-2024-26674 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040252-CVE-2024-26674-4ff9@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272819]
---
This was fixed for Fedora with the 6.7.5 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26663 kernel: tipc: Check the bearer type before calling tipc_udp_nl_bearer_add()
bugzilla·2024-04-02·CVSS 5.5
CVE-2024-26663 [MEDIUM] CVE-2024-26663 kernel: tipc: Check the bearer type before calling tipc_udp_nl_bearer_add()
CVE-2024-26663 kernel: tipc: Check the bearer type before calling tipc_udp_nl_bearer_add()
In the Linux kernel, the following vulnerability has been resolved:
tipc: Check the bearer type before calling tipc_udp_nl_bearer_add()
The Linux kernel CVE team has assigned CVE-2024-26663 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040223-CVE-2024-26663-9705@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272789]
---
This was fixed for Fedora with the 6.7.5 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2023-52634 kernel: drm/amd/display: Fix disable_otg_wa logic
bugzilla·2024-04-02·CVSS 5.5
CVE-2023-52634 [MEDIUM] CVE-2023-52634 kernel: drm/amd/display: Fix disable_otg_wa logic
CVE-2023-52634 kernel: drm/amd/display: Fix disable_otg_wa logic
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix disable_otg_wa logic
The Linux kernel CVE team has assigned CVE-2023-52634 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040219-CVE-2023-52634-27e0@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272807]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26672 kernel: drm/amdgpu: variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()'
bugzilla·2024-04-02·CVSS 7.1
CVE-2024-26672 [HIGH] CVE-2024-26672 kernel: drm/amdgpu: variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()'
CVE-2024-26672 kernel: drm/amdgpu: variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()'
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()'
The Linux kernel CVE team has assigned CVE-2024-26672 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040219-CVE-2024-26672-e96e@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272815]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26670 kernel: arm64: entry: fix ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD
bugzilla·2024-04-02·CVSS 5.5
CVE-2024-26670 [MEDIUM] CVE-2024-26670 kernel: arm64: entry: fix ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD
CVE-2024-26670 kernel: arm64: entry: fix ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD
In the Linux kernel, the following vulnerability has been resolved:
arm64: entry: fix ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD
The Linux kernel CVE team has assigned CVE-2024-26670 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040238-CVE-2024-26670-ecbd@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272801]
---
This was fixed for Fedora with the 6.7.3 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26661 kernel: drm/amd/display: Add NULL test for 'timing generator' in 'dcn21_set_pipe()'
bugzilla·2024-04-02·CVSS 5.5
CVE-2024-26661 [MEDIUM] CVE-2024-26661 kernel: drm/amd/display: Add NULL test for 'timing generator' in 'dcn21_set_pipe()'
CVE-2024-26661 kernel: drm/amd/display: Add NULL test for 'timing generator' in 'dcn21_set_pipe()'
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Add NULL test for 'timing generator' in 'dcn21_set_pipe()'
The Linux kernel CVE team has assigned CVE-2024-26661 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040223-CVE-2024-26661-bef6@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272785]
---
This was fixed for Fedora with the 6.7.5 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2023-52632 kernel: drm/amdkfd: lock dependency warning with srcu
bugzilla·2024-04-02·CVSS 5.5
CVE-2023-52632 [MEDIUM] CVE-2023-52632 kernel: drm/amdkfd: lock dependency warning with srcu
CVE-2023-52632 kernel: drm/amdkfd: lock dependency warning with srcu
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix lock dependency warning with srcu
The Linux kernel CVE team has assigned CVE-2023-52632 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040218-CVE-2023-52632-f7bb@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272805]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26662 kernel: drm/amd/display: 'panel_cntl' could be null in 'dcn21_set_backlight_level()'
bugzilla·2024-04-02·CVSS 5.5
CVE-2024-26662 [MEDIUM] CVE-2024-26662 kernel: drm/amd/display: 'panel_cntl' could be null in 'dcn21_set_backlight_level()'
CVE-2024-26662 kernel: drm/amd/display: 'panel_cntl' could be null in 'dcn21_set_backlight_level()'
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix 'panel_cntl' could be null in 'dcn21_set_backlight_level()'
The Linux kernel CVE team has assigned CVE-2024-26662 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040223-CVE-2024-26662-863c@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272787]
---
This was fixed for Fedora with the 6.7.5 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26678 kernel: x86/efistub: Use 1:1 file:memory mapping for PE/COFF .compat section
bugzilla·2024-04-02·CVSS 5.5
CVE-2024-26678 [MEDIUM] CVE-2024-26678 kernel: x86/efistub: Use 1:1 file:memory mapping for PE/COFF .compat section
CVE-2024-26678 kernel: x86/efistub: Use 1:1 file:memory mapping for PE/COFF .compat section
In the Linux kernel, the following vulnerability has been resolved:
x86/efistub: Use 1:1 file:memory mapping for PE/COFF .compat section
The Linux kernel CVE team has assigned CVE-2024-26678 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040253-CVE-2024-26678-2cf0@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2272837]
---
This was fixed for Fedora with the 6.7.5 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26646 kernel: thermal: intel: hfi: Add syscore callbacks for system-wide PM
bugzilla·2024-03-27·CVSS 5.5
CVE-2024-26646 [MEDIUM] CVE-2024-26646 kernel: thermal: intel: hfi: Add syscore callbacks for system-wide PM
CVE-2024-26646 kernel: thermal: intel: hfi: Add syscore callbacks for system-wide PM
In the Linux kernel, the following vulnerability has been resolved:
thermal: intel: hfi: Add syscore callbacks for system-wide PM
The Linux kernel CVE team has assigned CVE-2024-26646 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2271789]
---
This was fixed for Fedora with the 6.7.3 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2023-52625 kernel: drm/amd/display: Refactor DMCUB enter/exit idle interface
bugzilla·2024-03-26·CVSS 5.5
CVE-2023-52625 [MEDIUM] CVE-2023-52625 kernel: drm/amd/display: Refactor DMCUB enter/exit idle interface
CVE-2023-52625 kernel: drm/amd/display: Refactor DMCUB enter/exit idle interface
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Refactor DMCUB enter/exit idle interface
The Linux kernel CVE team has assigned CVE-2023-52625 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2271683]
---
This was fixed for Fedora with the 6.7.3 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26638 kernel: nbd: always initialize struct msghdr completely
bugzilla·2024-03-18·CVSS 4.4
CVE-2024-26638 [MEDIUM] CVE-2024-26638 kernel: nbd: always initialize struct msghdr completely
CVE-2024-26638 kernel: nbd: always initialize struct msghdr completely
In the Linux kernel, the following vulnerability has been resolved:
nbd: always initialize struct msghdr completely
The Linux kernel CVE team has assigned CVE-2024-26638 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2270104]
---
This was fixed for Fedora with the 6.7.3 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 h
Bugzilla
CVE-2024-26631 kernel: ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work
bugzilla·2024-03-18·CVSS 4.7
CVE-2024-26631 [MEDIUM] CVE-2024-26631 kernel: ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work
CVE-2024-26631 kernel: ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work
In the Linux kernel, the following vulnerability has been resolved:
ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work
The Linux kernel CVE team has assigned CVE-2024-26631 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2270134]
---
This was fixed for Fedora with the 6.6.14 stable kernel update.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-26611 kernel: xsk: fix usage of multi-buffer BPF helpers for ZC XDP
bugzilla·2024-03-12·CVSS 5.5
CVE-2024-26611 [MEDIUM] CVE-2024-26611 kernel: xsk: fix usage of multi-buffer BPF helpers for ZC XDP
CVE-2024-26611 kernel: xsk: fix usage of multi-buffer BPF helpers for ZC XDP
In the Linux kernel, the following vulnerability has been resolved:
xsk: fix usage of multi-buffer BPF helpers for ZC XDP
The Linux kernel CVE team has assigned CVE-2024-26611 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2269204]
---
This was fixed for Fedora with the 6.7.3 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2023-52490 kernel: mm: migrate: fix getting incorrect page mapping during page migration
bugzilla·2024-03-12·CVSS 5.5
CVE-2023-52490 [MEDIUM] CVE-2023-52490 kernel: mm: migrate: fix getting incorrect page mapping during page migration
CVE-2023-52490 kernel: mm: migrate: fix getting incorrect page mapping during page migration
In the Linux kernel, the following vulnerability has been resolved:
mm: migrate: fix getting incorrect page mapping during page migration
The Linux kernel CVE team has assigned CVE-2023-52490 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2269188]
---
This was fixed for Fedora with the 6.7.3 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
---
This issue has been addressed in the following products:
Red
Bugzilla
CVE-2021-47101 kernel: asix: fix uninit-value in asix_mdio_read()
bugzilla·2024-03-05·CVSS 7.1
CVE-2021-47101 [HIGH] CVE-2021-47101 kernel: asix: fix uninit-value in asix_mdio_read()
CVE-2021-47101 kernel: asix: fix uninit-value in asix_mdio_read()
In the Linux kernel, the following vulnerability has been resolved:
asix: fix uninit-value in asix_mdio_read()
The Linux kernel CVE team has assigned CVE-2021-47101 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030415-CVE-2021-47101-f3fa@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://acc
Bugzilla
CVE-2024-22099 kernel: NULL Pointer dereference bluetooth allows Overflow Buffers
bugzilla·2024-03-04·CVSS 5.5
CVE-2024-22099 [MEDIUM] CVE-2024-22099 kernel: NULL Pointer dereference bluetooth allows Overflow Buffers
CVE-2024-22099 kernel: NULL Pointer dereference bluetooth allows Overflow Buffers
NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C.
Refer:
https://bugzilla.openanolis.cn/show_bug.cgi?id=7956
https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=6ec00b0737fe
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267702]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
Bugzilla
CVE-2024-24858 kernel: net/bluetooth: race condition in {conn,adv}_{min,max}_interval_set() function
bugzilla·2024-02-27·CVSS 5.3
CVE-2024-24858 [MEDIUM] CVE-2024-24858 kernel: net/bluetooth: race condition in {conn,adv}_{min,max}_interval_set() function
CVE-2024-24858 kernel: net/bluetooth: race condition in {conn,adv}_{min,max}_interval_set() function
A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.
https://bugzilla.openanolis.cn/show_bug.cgi?id=8154
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2298820]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315
2024-09-28
Published