Debian Acpica-Unix vulnerabilities
4 known vulnerabilities affecting debian/acpica-unix.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
LOW4
Vulnerabilities
Page 1 of 1
CVE-2017-13693P4LOWCVSS 5.5fixed in acpica-unix 20180209-1 (bookworm)2017
CVE-2017-13693 [MEDIUM] CVE-2017-13693: acpica-unix - The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the L...
The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
Scope: local
bookw
debian
CVE-2017-13695P4LOWCVSS 5.5fixed in acpica-unix 20180209-1 (bookworm)2017
CVE-2017-13695 [MEDIUM] CVE-2017-13695: acpica-unix - The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux ker...
The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
Scope: local
bookworm: res
debian
CVE-2017-13694P4LOWCVSS 5.5fixed in acpica-unix 20180209-1 (bookworm)2017
CVE-2017-13694 [MEDIUM] CVE-2017-13694: acpica-unix - The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in th...
The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
Scop
debian
CVE-2024-24856P4LOWCVSS 5.3fixed in acpica-unix 20240827-2 (forky)2024
CVE-2024-24856 [MEDIUM] CVE-2024-24856: acpica-unix - The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a success...
The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer that receives it, which may lead to null pointer dereference. To fix this issue, a null pointer check should be added. If it is null, return exception code AE_NO_MEMORY.
Scope: local
bookworm: open
bullseye:
debian