Search

Found 5,162 results in 1545ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-49270 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: dm: fix use-after-free in dm_cleanup_zoned_dev() dm_cleanup_zoned_dev() uses queue, so it must be called before blk_cleanup_disk(…
CVE-2022-49268 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: Fix NULL ptr dereference when ENOMEM Do not call snd_dma_free_pages() when snd_dma_alloc_pages() returns -ENOME…
CVE-2022-49265 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: PM: domains: Fix sleep-in-atomic bug caused by genpd_debug_remove() When a genpd with GENPD_FLAG_IRQ_SAFE gets removed, the follo…
CVE-2022-49264 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: exec: Force single empty string when argv is empty Quoting[1] Ariadne Conill: "In several other operating systems, it is a hard …
CVE-2022-49263 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: brcmfmac: pcie: Release firmwares in the brcmf_pcie_setup error path This avoids leaking memory if brcmf_chip_get_raminfo fails. …
CVE-2022-49259 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: block: don't delete queue kobject before its children kobjects aren't supposed to be deleted before their child kobjects are dele…
CVE-2022-49253 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: media: usb: go7007: s2250-board: fix leak in probe() Call i2c_unregister_device(audio) on this error path.
CVE-2022-49247 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: media: stk1160: If start stream fails, return buffers with VB2_BUF_STATE_QUEUED If the callback 'start_streaming' fails, then all…
CVE-2022-49238 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ath11k: free peer for station when disconnect from AP for QCA6390/WCN6855 Commit b4a0f54156ac ("ath11k: move peer delete after vd…
CVE-2022-49235 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix uninit value bugs Syzbot reported 2 KMSAN bugs in ath9k. All of them are caused by missing field initialization. …
CVE-2022-49229 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ptp: unregister virtual clocks when unregistering physical clock. When unregistering a physical clock which has some virtual cloc…
CVE-2022-49228 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a btf decl_tag bug when tagging a function syzbot reported a btf decl_tag bug with stack trace below: general protect…
CVE-2022-49215 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: xsk: Fix race at socket teardown Fix a race in the xsk socket teardown code that can lead to a NULL pointer dereference splat. Th…
CVE-2022-49199 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: Prevent underflow in nldev_stat_set_counter_dynamic_doit() This code checks "index" for an upper bound but it does no…
CVE-2022-49188 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_q6v5_mss: Fix some leaks in q6v5_alloc_memory_region The device_node pointer is returned by of_parse_phandle() o…
CVE-2022-49179 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: block, bfq: don't move oom_bfqq Our test report a UAF: [ 2073.019181] ==========================================================…
CVE-2022-49175 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: PM: core: keep irq flags in device_pm_check_callbacks() The function device_pm_check_callbacks() can be called under the spin loc…
CVE-2022-49160 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash during module load unload test During purex packet handling the driver was incorrectly freeing a pre-all…
CVE-2022-49158 medium 5.5 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix warning message due to adisc being flushed Fix warning message due to adisc being flushed. Linux kernel trigg…
CVE-2022-49156 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix scheduling while atomic The driver makes a call into midlayer (fc_remote_port_delete) which can put the thread…
CVE-2022-49153 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: wireguard: socket: free skb in send6 when ipv6 is disabled I got a memory leak report: unreferenced object 0xffff8881191fc040 (s…
CVE-2022-49152 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: XArray: Fix xas_create_range() when multi-order entry present If there is already an entry present that is of order >= XA_CHUNK_S…
CVE-2022-49147 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: block: Fix the maximum minor value is blk_alloc_ext_minor() ida_alloc_range(..., min, max, ...) returns values from min to max, i…
CVE-2022-49145 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data If the NumEntries field in the _CPC return package is less than 2, …
CVE-2022-49142 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: net: preserve skb_end_offset() in skb_unclone_keeptruesize() syzbot found another way to trigger the infamous WARN_ON_ONCE(delta …
CVE-2022-49130 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ath11k: mhi: use mhi_sync_power_up() If amss.bin was missing ath11k would crash during 'rmmod ath11k_pci'. The reason for that wa…
CVE-2022-49129 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: fix crash when startup fails. If the nic fails to start, it is possible that the reset_work has already been schedu…
CVE-2022-49123 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ath11k: Fix frames flush failure caused by deadlock We are seeing below warnings: kernel: [25393.301506] ath11k_pci 0000:01:00.0…
CVE-2022-49122 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: dm ioctl: prevent potential spectre v1 gadget It appears like cmd could be a Spectre v1 gadget as it's supplied by a user and use…
CVE-2022-49109 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ceph: fix inode reference leakage in ceph_get_snapdir() The ceph_get_inode() will search for or insert a new inode into the hash …
CVE-2022-49107 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ceph: fix memory leak in ceph_readdir when note_last_dentry returns error Reset the last_readdir at the same time, and add a comm…
CVE-2022-49098 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Fix potential crash on module unload The vmbus driver relies on the panic notifier infrastructure to perform …
CVE-2022-49093 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: skbuff: fix coalescing for page_pool fragment recycling Fix a use-after-free when using page_pool with page fragments. We encount…
CVE-2022-49090 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: arch/arm64: Fix topology initialization for core scheduling Arm64 systems rely on store_cpu_topology() to call update_siblings_ma…
CVE-2022-49086 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix leak of nested actions While parsing user-provided actions, openvswitch module may dynamically allocate mem…
CVE-2022-49066 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: veth: Ensure eth header is in skb's linear part After feeding a decapsulated packet to a veth device with act_mirred, skb_headlen…
CVE-2022-49060 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix NULL pointer dereference in smc_pnet_find_ib() dev_name() was called with dev.parent as argument but without to NULL…
CVE-2022-48936 medium 5.5 rhel rocky sles 4y ago RHSA-2024:8870: kernel-rt security update (Moderate)
CVE-2022-48921 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix fault in reweight_entity Syzbot found a GPF in reweight_entity. This has been bisected to commit 4ef0c5c6b5ba ("k…
CVE-2022-48918 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: iwlwifi: mvm: check debugfs_dir ptr before use When "debugfs=off" is used on the kernel command line, iwiwifi's mvm module uses a…
CVE-2022-48912 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: fix use-after-free in __nf_register_net_hook() We must not dereference @new_hooks after nf_hook_mutex has been release…
CVE-2022-48905 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ibmvnic: free reset-work-item when flushing Fix a tiny memory leak when flushing the reset work queue.
CVE-2022-48786 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: vsock: remove vsock from connected table when connect is interrupted by a signal vsock_connect() expects that the socket could al…
CVE-2022-48765 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: KVM: LAPIC: Also cancel preemption timer during SET_LAPIC The below warning is splatting during guest reboot. ------------[ cu…
CVE-2022-48738 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Reject out of bounds values in snd_soc_put_volsw() We don't currently validate that the values being set are within th…
CVE-2022-48735 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix UAF of leds class devs at unbinding The LED class devices that are created by HD-audio codec drivers are registere…
CVE-2022-42432 medium 5.5 FIX rhel slesdebian debian 4y ago This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged…
CVE-2022-39190 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-36946 medium 5.5 FIX arch arch rhelalmalinux almalinux 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-3500 medium 5.5 FIX rhel sles rocky 4y ago Moderate: keylime security update
CVE-2022-32990 medium 5.5 FIX rhel slesdebian debian 4y ago Moderate: gimp security and enhancement update
CVE-2022-32891 medium 5.5 FIX arch arch rhel sles 4y ago The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
CVE-2022-32816 medium 5.5 FIX arch arch rhel sles 4y ago The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may l…
CVE-2022-32792 medium 5.5 FIX arch arch rhel sles 4y ago An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing malici…
CVE-2022-32746 medium 5.5 FIX rhelarch arch rocky 4y ago RHSA-2022:7730: libldb security, bug fix, and enhancement update (Moderate)
CVE-2022-32742 medium 5.5 FIX rhelarch arch sles 4y ago RHSA-2022:7111: samba security and bug fix update (Moderate)
CVE-2022-32189 medium 5.5 FIX rocky rhel sles 4y ago RHSA-2023:2802: container-tools:4.0 security and bug fix update (Moderate)
CVE-2022-31813 medium 5.5 FIX debian debian rhelarch arch 4y ago Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based auth…
CVE-2022-31625 medium 5.5 FIX arch arch rhel rocky 4y ago RHSA-2022:7624: php:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-3107 medium 5.5 FIX rhel slesdebian debian 4y ago An issue was discovered in the Linux kernel through 5.16-rc6. netvsc_get_ethtool_stats in drivers/net/hyperv/netvsc_drv.c lacks check of the return value of kvmalloc_array() and will cause the null p…
CVE-2022-30699 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7622: unbound security, bug fix, and enhancement update (Moderate)
CVE-2022-30698 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7622: unbound security, bug fix, and enhancement update (Moderate)
CVE-2022-30556 medium 5.5 FIX debian debian rhelarch arch 4y ago Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
CVE-2022-30550 medium 5.5 FIX arch arch rheldebian debian 4y ago An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and m…
CVE-2022-30522 medium 5.5 FIX debian debian rhelarch arch 4y ago If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigg…
CVE-2022-30293 medium 5.5 FIX rhelarch arch rocky 4y ago In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
CVE-2022-30067 medium 5.5 FIX rhel slesdebian debian 4y ago Moderate: gimp security and enhancement update
CVE-2022-29901 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-29900 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-2989 medium 5.5 FIX rocky rhel sles 4y ago RHSA-2023:2802: container-tools:4.0 security and bug fix update (Moderate)
CVE-2022-29581 medium 5.5 FIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-29404 medium 5.5 FIX debian debian rhelarch arch 4y ago In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.
CVE-2022-29162 medium 5.5 FIX rhelarch arch sles 4y ago RHSA-2022:7469: container-tools:4.0 security and bug fix update (Moderate)
CVE-2022-28893 medium 5.5 FIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-28615 medium 5.5 FIX debian debian rhelarch arch 4y ago Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed …
CVE-2022-28614 medium 5.5 FIX debian debian rhelarch arch 4y ago The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as w…
CVE-2022-2850 medium 5.5 FIX debian debian rhel sles 4y ago RHSA-2022:7133: 389-ds:1.4 security update (Moderate)
CVE-2022-28390 medium 5.5 FIX rhelalmalinux almalinuxarch arch 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-27406 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7745: freetype security update (Moderate)
CVE-2022-27405 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7745: freetype security update (Moderate)
CVE-2022-27404 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7745: freetype security update (Moderate)
CVE-2022-27337 medium 5.5 FIX arch arch rhel rocky 4y ago A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2022-27191 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago RHSA-2022:7469: container-tools:4.0 security and bug fix update (Moderate)
CVE-2022-26719 medium 5.5 FIX rhelarch arch rocky 4y ago A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing malicious…
CVE-2022-26717 medium 5.5 FIX rhelarch arch rocky 4y ago A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Win…
CVE-2022-26716 medium 5.5 FIX rhelarch arch rocky 4y ago A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing malicious…
CVE-2022-26710 medium 5.5 FIX arch arch rhel rocky 4y ago A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, tvOS 15.5, watchOS 8.6. Processing maliciously crafted web …
CVE-2022-26709 medium 5.5 FIX rhelarch arch rocky 4y ago A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously…
CVE-2022-26700 medium 5.5 FIX rhelarch arch rocky 4y ago A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5. Processing malicious…
CVE-2022-2639 medium 5.5 FIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-26377 medium 5.5 FIX debian debian rhelarch arch 4y ago Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards reque…
CVE-2022-26373 medium 5.5 FIX almalinux almalinux rhel rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-26125 medium 5.5 FIX rhel slesdebian debian 4y ago Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
CVE-2022-2586 medium 7.0 KEVFIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-25310 medium 5.5 FIX rhel sles rocky 4y ago RHSA-2022:7514: fribidi security update (Moderate)
CVE-2022-25309 medium 5.5 FIX rhel sles rocky 4y ago RHSA-2022:7514: fribidi security update (Moderate)
CVE-2022-25308 medium 5.5 FIX rhel sles rocky 4y ago RHSA-2022:7514: fribidi security update (Moderate)
CVE-2022-25255 medium 5.5 FIX rhel sles rocky 4y ago In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
CVE-2022-2503 medium 5.5 FIX arch arch rhel sles 4y ago Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads c…
CVE-2022-24448 medium 5.5 FIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update