RHSA-2024:8856

Vulnerability from csaf_opensuse - Published: 2024-11-05 01:22 - Updated: 2026-10-02 04:30
Summary
Red Hat Security Advisory: kernel security update
Severity
Moderate
Notes
Topic: An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Details: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: net/bluetooth: race condition in conn_info_{min,max}_age_set() (CVE-2024-24857) * kernel: dmaengine: fix NULL pointer in channel unregistration function (CVE-2023-52492) * kernel: netfilter: nf_conntrack_h323: Add protection for bmp length out of range (CVE-2024-26851) * kernel: netfilter: nft_set_pipapo: do not free live element (CVE-2024-26924) * kernel: netfilter: nft_set_pipapo: walk over current view on netlink dump (CVE-2024-27017) * kernel: KVM: Always flush async #PF workqueue when vCPU is being destroyed (CVE-2024-26976) * kernel: nouveau: lock the client object tree. (CVE-2024-27062) * kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info (CVE-2024-35839) * kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() (CVE-2024-35898) * kernel: dma-direct: Leak pages on dma_set_decrypted() failure (CVE-2024-35939) * kernel: net/mlx5e: Fix netif state handling (CVE-2024-38608) * kernel: r8169: Fix possible ring buffer corruption on fragmented Tx packets. (CVE-2024-38586) * kernel: of: module: add buffer overflow check in of_modalias() (CVE-2024-38541) * kernel: bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq (CVE-2024-38540) * kernel: netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type (CVE-2024-39503) * kernel: drm/i915/dpt: Make DPT object unshrinkable (CVE-2024-40924) * kernel: ipv6: prevent possible NULL deref in fib6_nh_init() (CVE-2024-40961) * kernel: tipc: force a dst refcount before doing decryption (CVE-2024-40983) * kernel: ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine." (CVE-2024-40984) * kernel: xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create (CVE-2022-48773) * kernel: bpf: Fix overrunning reservations in ringbuf (CVE-2024-41009) * kernel: netfilter: nf_tables: prefer nft_chain_validate (CVE-2024-41042) * kernel: ibmvnic: Add tx check to prevent skb leak (CVE-2024-41066) * kernel: drm/i915/gt: Fix potential UAF by revoke of fence registers (CVE-2024-41092) * kernel: drm/amdgpu: avoid using null object of framebuffer (CVE-2024-41093) * kernel: netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers (CVE-2024-42070) * kernel: gfs2: Fix NULL pointer dereference in gfs2_log_flush (CVE-2024-42079) * kernel: USB: serial: mos7840: fix crash on resume (CVE-2024-42244) * kernel: tipc: Return non-zero value from tipc_udp_addr2str() on error (CVE-2024-42284) * kernel: kobject_uevent: Fix OOB access within zap_modalias_env() (CVE-2024-42292) * kernel: dev/parport: fix the array out-of-bounds risk (CVE-2024-42301) * kernel: block: initialize integrity buffer to zero before writing it to media (CVE-2024-43854) * kernel: mlxsw: spectrum_acl_erp: Fix object nesting warning (CVE-2024-43880) * kernel: gso: do not skip outer ip header in case of ipip and net_failover (CVE-2022-48936) * kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper() (CVE-2024-43889) * kernel: memcg: protect concurrent access to mem_cgroup_idr (CVE-2024-43892) * kernel: sctp: Fix null-ptr-deref in reuseport_add_sock(). (CVE-2024-44935) * kernel: bonding: fix xfrm real_dev null pointer dereference (CVE-2024-44989) * kernel: bonding: fix null pointer deref in bond_ipsec_offload_ok (CVE-2024-44990) * kernel: netfilter: flowtable: initialise extack before use (CVE-2024-45018) * kernel: ELF: fix kernel.randomize_va_space double read (CVE-2024-46826) * kernel: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() (CVE-2024-47668) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Terms of Use: This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

A flaw was found in the Linux kernel in which a system crash can occur if there are certain errors establishing RPC-over-RDMA connections.

CWE-476 - NULL Pointer Dereference
Affected products
Product Identifier Version Remediation
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:bpftool-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:bpftool-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:bpftool-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:bpftool-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:bpftool-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:bpftool-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:bpftool-debuginfo-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:bpftool-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-0:4.18.0-553.27.1.el8_10.src —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-abi-stablelists-0:4.18.0-553.27.1.el8_10.noarch —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-core-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-core-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-core-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-core-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-core-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-core-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-core-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-core-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-debuginfo-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-devel-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-devel-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-devel-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-devel-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-modules-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-modules-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-modules-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-modules-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-modules-extra-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-modules-extra-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-modules-extra-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debug-modules-extra-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debuginfo-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debuginfo-common-aarch64-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debuginfo-common-ppc64le-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debuginfo-common-s390x-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-debuginfo-common-x86_64-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-devel-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-devel-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-devel-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-devel-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-doc-0:4.18.0-553.27.1.el8_10.noarch —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-modules-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-modules-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-modules-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-modules-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-modules-extra-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-modules-extra-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-modules-extra-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-modules-extra-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-debuginfo-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-libs-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-libs-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-tools-libs-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-zfcpdump-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-zfcpdump-core-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-zfcpdump-debuginfo-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-zfcpdump-devel-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-zfcpdump-modules-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:kernel-zfcpdump-modules-extra-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:perf-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:perf-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:perf-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:perf-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:perf-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:perf-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:perf-debuginfo-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:perf-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:python3-perf-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:python3-perf-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:python3-perf-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:python3-perf-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:python3-perf-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:python3-perf-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:python3-perf-debuginfo-0:4.18.0-553.27.1.el8_10.s390x —
Vendor Fix fix
Unresolved product id: BaseOS-8.10.0.Z.MAIN.EUS:python3-perf-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:bpftool-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:bpftool-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:bpftool-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-debug-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-debug-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-debug-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-debuginfo-common-aarch64-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-debuginfo-common-ppc64le-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-debuginfo-common-x86_64-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-tools-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-tools-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-tools-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-tools-libs-devel-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-tools-libs-devel-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:kernel-tools-libs-devel-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:perf-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:perf-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:perf-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:python3-perf-debuginfo-0:4.18.0-553.27.1.el8_10.aarch64 —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:python3-perf-debuginfo-0:4.18.0-553.27.1.el8_10.ppc64le —
Vendor Fix fix
Unresolved product id: CRB-8.10.0.Z.MAIN.EUS:python3-perf-debuginfo-0:4.18.0-553.27.1.el8_10.x86_64 —
Vendor Fix fix
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: gso: do not skip outer ip header in case of ipip and net_failover We encounter a tcp drop issue in our cloud environment. Packet GROed in host forwards to a VM virtio_net nic with net_failover enabled. VM acts as a IPVS LB with ipip encapsulation. The full path like: host gro -> vm virtio_net rx -> net_failover rx -> ipvs fullnat -> ipip encap -> net_failover tx -> virtio_net tx When net_failover transmits a ipip pkt (gso_type = 0x0103, which means SKB_GSO_TCPV4, SKB_GSO_DODGY and SKB_GSO_IPXIP4), there is no gso did because it supports TSO and GSO_IPXIP4. But network_header points to inner ip header.

Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

An out-of-bounds memory access vulnerability exists in the linux kernel, such that A stack-allocated buffer (backed by vmalloc) was passed into crypto code (scatterwalk_map_and_copy() → __memcpy) where a cross-page write occurred. This ended up hitting a read-only mapping, causing a page-level fault and kernel panic (Oops: 9600004f), potentially damaging system availability and stability.

CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: dmaengine: fix NULL pointer in channel unregistration function The Linux kernel CVE team has assigned CVE-2023-52492 to this issue. Upstream advisory: https://lore.kernel.org/linux-cve-announce/20240229155245.1571576-33-lee@kernel.org/T

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

In the Linux kernel, the following vulnerability has been resolved: memcontrol: ensure memcg acquired by id is properly set up In the eviction recency check, we attempt to retrieve the memcg to which the folio belonged when it was evicted, by the memcg id stored in the shadow entry. However, there is a chance that the retrieved memcg is not the original memcg that has been killed, but a new one which happens to have the same id. This is a somewhat unfortunate, but acceptable and rare inaccuracy in the heuristics. However, if we retrieve this new memcg between its allocation and when it is properly attached to the memcg hierarchy, we could run into the following NULL pointer exception during the memcg hierarchy traversal done in mem_cgroup_get_nr_swap_pages(): [ 155757.793456] BUG: kernel NULL pointer dereference, address: 00000000000000c0 [ 155757.807568] #PF: supervisor read access in kernel mode [ 155757.818024] #PF: error_code(0x0000) - not-present page [ 155757.828482] PGD 401f77067 P4D 401f77067 PUD 401f76067 PMD 0 [ 155757.839985] Oops: 0000 [#1] SMP [ 155757.887870] RIP: 0010:mem_cgroup_get_nr_swap_pages+0x3d/0xb0 [ 155757.899377] Code: 29 19 4a 02 48 39 f9 74 63 48 8b 97 c0 00 00 00 48 8b b7 58 02 00 00 48 2b b7 c0 01 00 00 48 39 f0 48 0f 4d c6 48 39 d1 74 42 <48> 8b b2 c0 00 00 00 48 8b ba 58 02 00 00 48 2b ba c0 01 00 00 48 [ 155757.937125] RSP: 0018:ffffc9002ecdfbc8 EFLAGS: 00010286 [ 155757.947755] RAX: 00000000003a3b1c RBX: 000007ffffffffff RCX: ffff888280183000 [ 155757.962202] RDX: 0000000000000000 RSI: 0007ffffffffffff RDI: ffff888bbc2d1000 [ 155757.976648] RBP: 0000000000000001 R08: 000000000000000b R09: ffff888ad9cedba0 [ 155757.991094] R10: ffffea0039c07900 R11: 0000000000000010 R12: ffff888b23a7b000 [ 155758.005540] R13: 0000000000000000 R14: ffff888bbc2d1000 R15: 000007ffffc71354 [ 155758.019991] FS: 00007f6234c68640(0000) GS:ffff88903f9c0000(0000) knlGS:0000000000000000 [ 155758.036356] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 155758.048023] CR2: 00000000000000c0 CR3: 0000000a83eb8004 CR4: 00000000007706e0 [ 155758.062473] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 155758.076924] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 155758.091376] PKRU: 55555554 [ 155758.096957] Call Trace: [ 155758.102016] <TASK> [ 155758.106502] ? __die+0x78/0xc0 [ 155758.112793] ? page_fault_oops+0x286/0x380 [ 155758.121175] ? exc_page_fault+0x5d/0x110 [ 155758.129209] ? asm_exc_page_fault+0x22/0x30 [ 155758.137763] ? mem_cgroup_get_nr_swap_pages+0x3d/0xb0 [ 155758.148060] workingset_test_recent+0xda/0x1b0 [ 155758.157133] workingset_refault+0xca/0x1e0 [ 155758.165508] filemap_add_folio+0x4d/0x70 [ 155758.173538] page_cache_ra_unbounded+0xed/0x190 [ 155758.182919] page_cache_sync_ra+0xd6/0x1e0 [ 155758.191738] filemap_read+0x68d/0xdf0 [ 155758.199495] ? mlx5e_napi_poll+0x123/0x940 [ 155758.207981] ? __napi_schedule+0x55/0x90 [ 155758.216095] __x64_sys_pread64+0x1d6/0x2c0 [ 155758.224601] do_syscall_64+0x3d/0x80 [ 155758.232058] entry_SYSCALL_64_after_hwframe+0x46/0xb0 [ 155758.242473] RIP: 0033:0x7f62c29153b5 [ 155758.249938] Code: e8 48 89 75 f0 89 7d f8 48 89 4d e0 e8 b4 e6 f7 ff 41 89 c0 4c 8b 55 e0 48 8b 55 e8 48 8b 75 f0 8b 7d f8 b8 11 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 33 44 89 c7 48 89 45 f8 e8 e7 e6 f7 ff 48 8b [ 155758.288005] RSP: 002b:00007f6234c5ffd0 EFLAGS: 00000293 ORIG_RAX: 0000000000000011 [ 155758.303474] RAX: ffffffffffffffda RBX: 00007f628c4e70c0 RCX: 00007f62c29153b5 [ 155758.318075] RDX: 000000000003c041 RSI: 00007f61d2986000 RDI: 0000000000000076 [ 155758.332678] RBP: 00007f6234c5fff0 R08: 0000000000000000 R09: 0000000064d5230c [ 155758.347452] R10: 000000000027d450 R11: 0000000000000293 R12: 000000000003c041 [ 155758.362044] R13: 00007f61d2986000 R14: 00007f629e11b060 R15: 000000000027d450 [ 155758.376661] </TASK> This patch fixes the issue by moving the memcg's id publication from the alloc stage to ---truncated---

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A race condition was found in the Linux kernel's net/bluetooth device driver within the conn_info_{min,max}_age_set() function. This issue can lead to an integrity overflow issue, potentially disrupting Bluetooth connections or facilitating a denial of service attack.

CWE-190 - Integer Overflow or Wraparound
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A vulnerability was found in the netfilter subsystem of the Linux kernel, specifically in the `nf_conntrack_h323` module. This issue involves inadequate protection for BMP length values, potentially leading to out-of-range conditions.

CWE-20 - Improper Input Validation
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: do not free live element The Linux kernel CVE team has assigned CVE-2024-26924 to this issue. Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024042420-CVE-2024-26924-4d1e@gregkh/T

CWE-402 - Transmission of Private Resources into a New Sphere ('Resource Leak')
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

In the Linux kernel, the following vulnerability has been resolved: KVM: Always flush async #PF workqueue when vCPU is being destroyed Always flush the per-vCPU async #PF workqueue when a vCPU is clearing its completion queue, e.g. when a VM and all its vCPUs is being destroyed. KVM must ensure that none of its workqueue callbacks is running when the last reference to the KVM _module_ is put. Gifting a reference to the associated VM prevents the workqueue callback from dereferencing freed vCPU/VM memory, but does not prevent the KVM module from being unloaded before the callback completes. Drop the misguided VM refcount gifting, as calling kvm_put_kvm() from async_pf_execute() if kvm_put_kvm() flushes the async #PF workqueue will result in deadlock. async_pf_execute() can't return until kvm_put_kvm() finishes, and kvm_put_kvm() can't return until async_pf_execute() finishes: WARNING: CPU: 8 PID: 251 at virt/kvm/kvm_main.c:1435 kvm_put_kvm+0x2d/0x320 [kvm] Modules linked in: vhost_net vhost vhost_iotlb tap kvm_intel kvm irqbypass CPU: 8 PID: 251 Comm: kworker/8:1 Tainted: G W 6.6.0-rc1-e7af8d17224a-x86/gmem-vm #119 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 Workqueue: events async_pf_execute [kvm] RIP: 0010:kvm_put_kvm+0x2d/0x320 [kvm] Call Trace: <TASK> async_pf_execute+0x198/0x260 [kvm] process_one_work+0x145/0x2d0 worker_thread+0x27e/0x3a0 kthread+0xba/0xe0 ret_from_fork+0x2d/0x50 ret_from_fork_asm+0x11/0x20 </TASK> ---[ end trace 0000000000000000 ]--- INFO: task kworker/8:1:251 blocked for more than 120 seconds. Tainted: G W 6.6.0-rc1-e7af8d17224a-x86/gmem-vm #119 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/8:1 state:D stack:0 pid:251 ppid:2 flags:0x00004000 Workqueue: events async_pf_execute [kvm] Call Trace: <TASK> __schedule+0x33f/0xa40 schedule+0x53/0xc0 schedule_timeout+0x12a/0x140 __wait_for_common+0x8d/0x1d0 __flush_work.isra.0+0x19f/0x2c0 kvm_clear_async_pf_completion_queue+0x129/0x190 [kvm] kvm_arch_destroy_vm+0x78/0x1b0 [kvm] kvm_put_kvm+0x1c1/0x320 [kvm] async_pf_execute+0x198/0x260 [kvm] process_one_work+0x145/0x2d0 worker_thread+0x27e/0x3a0 kthread+0xba/0xe0 ret_from_fork+0x2d/0x50 ret_from_fork_asm+0x11/0x20 </TASK> If kvm_clear_async_pf_completion_queue() actually flushes the workqueue, then there's no need to gift async_pf_execute() a reference because all invocations of async_pf_execute() will be forced to complete before the vCPU and its VM are destroyed/freed. And that in turn fixes the module unloading bug as __fput() won't do module_put() on the last vCPU reference until the vCPU has been freed, e.g. if closing the vCPU file also puts the last reference to the KVM module. Note that kvm_check_async_pf_completion() may also take the work item off the completion queue and so also needs to flush the work queue, as the work will not be seen by kvm_clear_async_pf_completion_queue(). Waiting on the workqueue could theoretically delay a vCPU due to waiting for the work to complete, but that's a very, very small chance, and likely a very small delay. kvm_arch_async_page_present_queued() unconditionally makes a new request, i.e. will effectively delay entering the guest, so the remaining work is really just: trace_kvm_async_pf_completed(addr, cr2_or_gpa); __kvm_vcpu_wake_up(vcpu); mmput(mm); and mmput() can't drop the last reference to the page tables if the vCPU is still alive, i.e. the vCPU won't get stuck tearing down page tables. Add a helper to do the flushing, specifically to deal with "wakeup all" work items, as they aren't actually work items, i.e. are never placed in a workqueue. Trying to flush a bogus workqueue entry rightly makes __flush_work() complain (kudos to whoever added that sanity check). Note, commit 5f6de5cbebee ("KVM: Prevent module exit until al ---truncated---

Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk over current view on netlink dump The Linux kernel CVE team has assigned CVE-2024-27017 to this issue. Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024050150-CVE-2024-27017-d867@gregkh/T

CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

A flaw was found in the nouveau module in the Linux kernel. A missing resource lock can cause a race condition and trigger a general protection fault, resulting in a denial of service.

CWE-413 - Improper Resource Locking
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

CVE-2024-35839 is a flaw in the Linux kernel's Netfilter bridge functionality. It occurs when bridging certain packets, such as those involving destination NAT between virtual Ethernet interfaces. A mismatch between the network device associated with a packet and the neighbor's device can lead to incorrect handling, including references to freed memory. This issue could cause system crashes. The problem has been fixed by using safer methods to retrieve the network device during packet processing. Users should update their kernels to a patched version to avoid this vulnerability.

CWE-628 - Function Call with Incorrectly Specified Arguments
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() The Linux kernel CVE team has assigned CVE-2024-35898 to this issue. Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024051951-CVE-2024-35898-a10e@gregkh/T

CWE-366 - Race Condition within a Thread
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: dma-direct: Leak pages on dma_set_decrypted() failure The Linux kernel CVE team has assigned CVE-2024-35939 to this issue. Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024051919-CVE-2024-35939-f877@gregkh/T

CWE-772 - Missing Release of Resource after Effective Lifetime
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

in linux kernel, shift undefined behavior occurs in bnxt_qplib_alloc_init_hwq with hwq_attr->aux_depth of nonzero and hwq_attr->aux_stride of zero.

CWE-125 - Out-of-bounds Read
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A buffer overflow flaw was found in of_modalias() in the Linux kernel, occurring after the first snprintf() call. This issue could result in loss of availability of the system.

CWE-121 - Stack-based Buffer Overflow
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

in linux kernel r8169, when transmitting small fragmented packets, invalid entries were inserted into the transmit ring buffer, leading to calls to dma_unmap_single() with a null address.

CWE-457 - Use of Uninitialized Variable
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A vulnerability was found in the Linux kernel within the net/mlx5e component, where improper handling of network interface states could lead to a NULL pointer dereference or resource leaks if network registration fails during initialization. This condition could cause system instability, as resources may not be cleaned up correctly, although it presents a low risk due to limited overall impact.

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type Lion Ackermann reported that there is a race condition between namespace cleanup in ipset and the garbage collection of the list:set type. The namespace cleanup can destroy the list:set type of sets while the gc of the set type is waiting to run in rcu cleanup. The latter uses data from the destroyed set which thus leads use after free. The patch contains the following parts: - When destroying all sets, first remove the garbage collectors, then wait if needed and then destroy the sets. - Fix the badly ordered "wait then remove gc" for the destroy a single set case. - Fix the missing rcu locking in the list:set type in the userspace test case. - Use proper RCU list handlings in the list:set type. The patch depends on c1193d9bbbd3 (netfilter: ipset: Add list flush to cancel_gc).

CWE-416 - Use After Free
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: drm/i915/dpt: Make DPT object unshrinkable In some scenarios, the DPT object gets shrunk but the actual framebuffer did not and thus its still there on the DPT's vm->bound_list. Then it tries to rewrite the PTEs via a stale CPU mapping. This causes panic. [vsyrjala: Add TODO comment] (cherry picked from commit 51064d471c53dcc8eddd2333c3f1c1d9131ba36c)

CWE-99 - Improper Control of Resource Identifiers ('Resource Injection')
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

A vulnerability was found in the Linux kernel's IPv6 routing component, where a NULL dereference occurs in the fib6_nh_init() function, this issue arises when the function attempts to initialize a network interface without verifying its availability, potentially leading to a DoS.

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A vulnerability was found in the Linux kernel's TIPC module, where a reference count on the destination entry was not enforced before decryption. This issue arises due to potential asynchronous returns from crypto requests, which could lead to crash.

CWE-911 - Improper Update of Reference Count
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A vulnerability was found in the Linux kernel's ACPICA component, where improper handling of memory mappings can lead to a NULL pointer dereference. This issue arises when mapping requests exceed page boundaries, resulting in attempts to access unmapped memory.

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

An out-of-bounds memory access flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to crash the system.

CWE-121 - Stack-based Buffer Overflow
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: prefer nft_chain_validate nft_chain_validate already performs loop detection because a cycle will result in a call stack overflow (ctx->level >= NFT_JUMP_STACK_SIZE). It also follows maps via ->validate callback in nft_lookup, so there appears no reason to iterate the maps again. nf_tables_check_loops() and all its helper functions can be removed. This improves ruleset load time significantly, from 23s down to 12s. This also fixes a crash bug. Old loop detection code can result in unbounded recursion: BUG: TASK stack guard page was hit at .... Oops: stack guard page: 0000 [#1] PREEMPT SMP KASAN CPU: 4 PID: 1539 Comm: nft Not tainted 6.10.0-rc5+ #1 [..] with a suitable ruleset during validation of register stores. I can't see any actual reason to attempt to check for this from nft_validate_register_store(), at this point the transaction is still in progress, so we don't have a full picture of the rule graph. For nf-next it might make sense to either remove it or make this depend on table->validate_state in case we could catch an error earlier (for improved error reporting to userspace).

CWE-121 - Stack-based Buffer Overflow
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Add tx check to prevent skb leak Below is a summary of how the driver stores a reference to an skb during transmit: tx_buff[free_map[consumer_index]]->skb = new_skb; free_map[consumer_index] = IBMVNIC_INVALID_MAP; consumer_index ++; Where variable data looks like this: free_map == [4, IBMVNIC_INVALID_MAP, IBMVNIC_INVALID_MAP, 0, 3] consumer_index^ tx_buff == [skb=null, skb=<ptr>, skb=<ptr>, skb=null, skb=null] The driver has checks to ensure that free_map[consumer_index] pointed to a valid index but there was no check to ensure that this index pointed to an unused/null skb address. So, if, by some chance, our free_map and tx_buff lists become out of sync then we were previously risking an skb memory leak. This could then cause tcp congestion control to stop sending packets, eventually leading to ETIMEDOUT. Therefore, add a conditional to ensure that the skb address is null. If not then warn the user (because this is still a bug that should be patched) and free the old pointer to prevent memleak/tcp problems.

CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

A use-after-free was found in drivers/gpu/drm/i915/gt/intel_ggtt_fencing.c in the Linux kernel. This issue can be caused by a race among revocation of fence registers on one side and sequential execution of signal callbacks invoked on completion of a request that was using them on the other, processed in parallel to revocation of those fence registers.

CWE-416 - Use After Free
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid using null object of framebuffer Instead of using state->fb->obj[0] directly, get object from framebuffer by calling drm_gem_fb_get_obj() and return error code when object is null to avoid using null object of framebuffer.

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers register store validation for NFT_DATA_VALUE is conditional, however, the datatype is always either NFT_DATA_VALUE or NFT_DATA_VERDICT. This only requires a new helper function to infer the register type from the set datatype so this conditional check can be removed. Otherwise, pointer to chain object can be leaked through the registers.

CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix NULL pointer dereference in gfs2_log_flush In gfs2_jindex_free(), set sdp->sd_jdesc to NULL under the log flush lock to provide exclusion against gfs2_log_flush(). In gfs2_log_flush(), check if sdp->sd_jdesc is non-NULL before dereferencing it. Otherwise, we could run into a NULL pointer dereference when outstanding glock work races with an unmount (glock_work_func -> run_queue -> do_xmote -> inode_go_sync -> gfs2_log_flush).

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mos7840: fix crash on resume Since commit c49cfa917025 ("USB: serial: use generic method if no alternative is provided in usb serial layer"), USB serial core calls the generic resume implementation when the driver has not provided one. This can trigger a crash on resume with mos7840 since support for multiple read URBs was added back in 2011. Specifically, both port read URBs are now submitted on resume for open ports, but the context pointer of the second URB is left set to the core rather than mos7840 port structure. Fix this by implementing dedicated suspend and resume functions for mos7840. Tested with Delock 87414 USB 2.0 to 4x serial adapter. [ johan: analyse crash and rewrite commit message; set busy flag on resume; drop bulk-in check; drop unnecessary usb_kill_urb() ]

CWE-99 - Improper Control of Resource Identifiers ('Resource Injection')
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Low

A flaw was found in Linux kernel tipc. tipc_udp_addr2str() does not return a nonzero value when UDP media address is invalid, which can result in a buffer overflow in tipc_media_addr_printf().

CWE-393 - Return of Wrong Status Code
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

in linux kernel's kobject_uevent, zap_modalias_env incorrectly calculates the size of the memory block to move, which may cause out of bounds memory access.

CWE-125 - Out-of-bounds Read
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

An array out-of-bounds flaw was found in dev/parport in the Linux kernel. This issue may result in a crash.

Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A flaw was found in the Linux kernel, where it initialized the integrity buffer to zero before writing it to media. Metadata added by bio_integrity_prep uses plain kmalloc, which leads to random kernel memory being written. Protection Information (PI) metadata is limited to the app tag not used by kernel-generated metadata, but for non-PI metadata, the entire buffer leaks kernel memory, potentially exposing sensitive internal kernel data.

CWE-401 - Missing Release of Memory after Effective Lifetime
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A flaw incorrect memory access in the Linux kernel Mellanox network (Ethernet or RDMA) device driver was found. A local user could use this flaw to crash the system.

CWE-284 - Improper Access Control
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A denial of service vulnerability exists in the Linux kernel. A possible divide-by-0 is in the padata_mt_helper() function when the ps->chunk_size is 0. This vulnerability could result in a loss of system availability.

CWE-369 - Divide By Zero
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

memcg in linux kernel permit concurrent access to mem_cgroup_idr which can lead to kernel crashes.

CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A flaw was found in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. A local attacker with low privileges could exploit improper synchronization during concurrent socket operations involving SO_REUSEPORT. This vulnerability, a null-pointer dereference, can lead to a system crash, resulting in a Denial of Service (DoS).

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A flaw was found in the Linux kernel's bonding module. A local attacker with low privileges could exploit a null pointer dereference by manipulating network operations. This vulnerability can cause the system to crash, leading to a Denial of Service (DoS).

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A flaw was found in the Linux kernel's bonding module. A local attacker could exploit a null pointer dereference in the bond_ipsec_offload_ok function. This occurs because the system does not verify the presence of an active slave before attempting to dereference a pointer, which can lead to a system crash and result in a Denial of Service (DoS).

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A flaw was found in the Linux kernel's netfilter flowtable feature. A local attacker could exploit a missing initialization of the `extack` structure, leading to a denial of service. This vulnerability could allow an attacker with local access to crash the system.

CWE-457 - Use of Uninitialized Variable
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A flaw was found in ethtool in the Linux kernel, where sysfs reader getting link settings can attempt to read the device state on a device that is not present, leading to a crash.

CWE-99 - Improper Control of Resource Identifiers ('Resource Injection')
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

In the Linux kernel, the following vulnerability has been resolved: ELF: fix kernel.randomize_va_space double read ELF loader uses "randomize_va_space" twice. It is sysctl and can change at any moment, so 2 loads could see 2 different values in theory with unpredictable consequences. Issue exactly one load for consistent value across one exec.

CWE-20 - Improper Input Validation
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate

A flaw was found in the Linux kernel. A race condition in the `__genradix_ptr_alloc()` function, responsible for allocating nodes in the generic radix tree, can occur when increasing the tree depth. This race can lead to a preallocated node retaining a pointer to an old root instead of being properly zeroed. An attacker could potentially exploit this to cause system instability or a denial of service.

CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Affected products
Fixed 120 products, the same list as for CVE-2022-48773
Threats
Impact Moderate
References
URL Category
https://access.redhat.com/errata/RHSA-2024:8856 self
https://access.redhat.com/security/updates/classi… external
https://bugzilla.redhat.com/show_bug.cgi?id=2266247 external
https://bugzilla.redhat.com/show_bug.cgi?id=2269183 external
https://bugzilla.redhat.com/show_bug.cgi?id=2275750 external
https://bugzilla.redhat.com/show_bug.cgi?id=2277168 external
https://bugzilla.redhat.com/show_bug.cgi?id=2278262 external
https://bugzilla.redhat.com/show_bug.cgi?id=2278350 external
https://bugzilla.redhat.com/show_bug.cgi?id=2278387 external
https://bugzilla.redhat.com/show_bug.cgi?id=2281284 external
https://bugzilla.redhat.com/show_bug.cgi?id=2281669 external
https://bugzilla.redhat.com/show_bug.cgi?id=2281817 external
https://bugzilla.redhat.com/show_bug.cgi?id=2293356 external
https://bugzilla.redhat.com/show_bug.cgi?id=2293402 external
https://bugzilla.redhat.com/show_bug.cgi?id=2293458 external
https://bugzilla.redhat.com/show_bug.cgi?id=2293459 external
https://bugzilla.redhat.com/show_bug.cgi?id=2297475 external
https://bugzilla.redhat.com/show_bug.cgi?id=2297508 external
https://bugzilla.redhat.com/show_bug.cgi?id=2297545 external
https://bugzilla.redhat.com/show_bug.cgi?id=2297567 external
https://bugzilla.redhat.com/show_bug.cgi?id=2297568 external
https://bugzilla.redhat.com/show_bug.cgi?id=2298109 external
https://bugzilla.redhat.com/show_bug.cgi?id=2298412 external
https://bugzilla.redhat.com/show_bug.cgi?id=2300412 external
https://bugzilla.redhat.com/show_bug.cgi?id=2300442 external
https://bugzilla.redhat.com/show_bug.cgi?id=2300487 external
https://bugzilla.redhat.com/show_bug.cgi?id=2300488 external
https://bugzilla.redhat.com/show_bug.cgi?id=2300508 external
https://bugzilla.redhat.com/show_bug.cgi?id=2300517 external
https://bugzilla.redhat.com/show_bug.cgi?id=2305446 external
https://bugzilla.redhat.com/show_bug.cgi?id=2307862 external
https://bugzilla.redhat.com/show_bug.cgi?id=2307865 external
https://bugzilla.redhat.com/show_bug.cgi?id=2307892 external
https://bugzilla.redhat.com/show_bug.cgi?id=2309852 external
https://bugzilla.redhat.com/show_bug.cgi?id=2309853 external
https://bugzilla.redhat.com/show_bug.cgi?id=2311715 external
https://bugzilla.redhat.com/show_bug.cgi?id=2315178 external
https://bugzilla.redhat.com/show_bug.cgi?id=2317601 external
https://security.access.redhat.com/data/csaf/v2/a… self
https://access.redhat.com/security/cve/CVE-2022-48773 self
https://bugzilla.redhat.com/show_bug.cgi?id=2298109 external
https://www.cve.org/CVERecord?id=CVE-2022-48773 external
https://nvd.nist.gov/vuln/detail/CVE-2022-48773 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2022-48936 self
https://bugzilla.redhat.com/show_bug.cgi?id=2307192 external
https://www.cve.org/CVERecord?id=CVE-2022-48936 external
https://nvd.nist.gov/vuln/detail/CVE-2022-48936 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2022-50341 self
https://bugzilla.redhat.com/show_bug.cgi?id=2395879 external
https://www.cve.org/CVERecord?id=CVE-2022-50341 external
https://nvd.nist.gov/vuln/detail/CVE-2022-50341 external
https://lore.kernel.org/linux-cve-announce/202509… external
https://access.redhat.com/security/cve/CVE-2023-52492 self
https://bugzilla.redhat.com/show_bug.cgi?id=2269183 external
https://www.cve.org/CVERecord?id=CVE-2023-52492 external
https://nvd.nist.gov/vuln/detail/CVE-2023-52492 external
https://lore.kernel.org/linux-cve-announce/202402… external
https://access.redhat.com/security/cve/CVE-2023-53621 self
https://bugzilla.redhat.com/show_bug.cgi?id=2402239 external
https://www.cve.org/CVERecord?id=CVE-2023-53621 external
https://nvd.nist.gov/vuln/detail/CVE-2023-53621 external
https://lore.kernel.org/linux-cve-announce/202510… external
https://access.redhat.com/security/cve/CVE-2024-24857 self
https://bugzilla.redhat.com/show_bug.cgi?id=2266247 external
https://www.cve.org/CVERecord?id=CVE-2024-24857 external
https://nvd.nist.gov/vuln/detail/CVE-2024-24857 external
https://access.redhat.com/security/cve/CVE-2024-26851 self
https://bugzilla.redhat.com/show_bug.cgi?id=2275750 external
https://www.cve.org/CVERecord?id=CVE-2024-26851 external
https://nvd.nist.gov/vuln/detail/CVE-2024-26851 external
https://lore.kernel.org/linux-cve-announce/202404… external
https://access.redhat.com/security/cve/CVE-2024-26924 self
https://bugzilla.redhat.com/show_bug.cgi?id=2277168 external
https://www.cve.org/CVERecord?id=CVE-2024-26924 external
https://nvd.nist.gov/vuln/detail/CVE-2024-26924 external
https://lore.kernel.org/linux-cve-announce/202404… external
https://access.redhat.com/security/cve/CVE-2024-26976 self
https://bugzilla.redhat.com/show_bug.cgi?id=2278350 external
https://www.cve.org/CVERecord?id=CVE-2024-26976 external
https://nvd.nist.gov/vuln/detail/CVE-2024-26976 external
https://lore.kernel.org/linux-cve-announce/202405… external
https://access.redhat.com/security/cve/CVE-2024-27017 self
https://bugzilla.redhat.com/show_bug.cgi?id=2278262 external
https://www.cve.org/CVERecord?id=CVE-2024-27017 external
https://nvd.nist.gov/vuln/detail/CVE-2024-27017 external
https://lore.kernel.org/linux-cve-announce/202405… external
https://access.redhat.com/security/cve/CVE-2024-27062 self
https://bugzilla.redhat.com/show_bug.cgi?id=2278387 external
https://www.cve.org/CVERecord?id=CVE-2024-27062 external
https://nvd.nist.gov/vuln/detail/CVE-2024-27062 external
https://lore.kernel.org/linux-cve-announce/202405… external
https://access.redhat.com/security/cve/CVE-2024-35839 self
https://bugzilla.redhat.com/show_bug.cgi?id=2281284 external
https://www.cve.org/CVERecord?id=CVE-2024-35839 external
https://nvd.nist.gov/vuln/detail/CVE-2024-35839 external
https://lore.kernel.org/linux-cve-announce/202405… external
https://access.redhat.com/security/cve/CVE-2024-35898 self
https://bugzilla.redhat.com/show_bug.cgi?id=2281669 external
https://www.cve.org/CVERecord?id=CVE-2024-35898 external
https://nvd.nist.gov/vuln/detail/CVE-2024-35898 external
https://lore.kernel.org/linux-cve-announce/202405… external
https://access.redhat.com/security/cve/CVE-2024-35939 self
https://bugzilla.redhat.com/show_bug.cgi?id=2281817 external
https://www.cve.org/CVERecord?id=CVE-2024-35939 external
https://nvd.nist.gov/vuln/detail/CVE-2024-35939 external
https://lore.kernel.org/linux-cve-announce/202405… external
https://access.redhat.com/security/cve/CVE-2024-38540 self
https://bugzilla.redhat.com/show_bug.cgi?id=2293459 external
https://www.cve.org/CVERecord?id=CVE-2024-38540 external
https://nvd.nist.gov/vuln/detail/CVE-2024-38540 external
https://lore.kernel.org/linux-cve-announce/202406… external
https://access.redhat.com/security/cve/CVE-2024-38541 self
https://bugzilla.redhat.com/show_bug.cgi?id=2293458 external
https://www.cve.org/CVERecord?id=CVE-2024-38541 external
https://nvd.nist.gov/vuln/detail/CVE-2024-38541 external
https://lore.kernel.org/linux-cve-announce/202406… external
https://access.redhat.com/security/cve/CVE-2024-38586 self
https://bugzilla.redhat.com/show_bug.cgi?id=2293402 external
https://www.cve.org/CVERecord?id=CVE-2024-38586 external
https://nvd.nist.gov/vuln/detail/CVE-2024-38586 external
https://lore.kernel.org/linux-cve-announce/202406… external
https://access.redhat.com/security/cve/CVE-2024-38608 self
https://bugzilla.redhat.com/show_bug.cgi?id=2293356 external
https://www.cve.org/CVERecord?id=CVE-2024-38608 external
https://nvd.nist.gov/vuln/detail/CVE-2024-38608 external
https://lore.kernel.org/linux-cve-announce/202406… external
https://access.redhat.com/security/cve/CVE-2024-39503 self
https://bugzilla.redhat.com/show_bug.cgi?id=2297475 external
https://www.cve.org/CVERecord?id=CVE-2024-39503 external
https://nvd.nist.gov/vuln/detail/CVE-2024-39503 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-40924 self
https://bugzilla.redhat.com/show_bug.cgi?id=2297508 external
https://www.cve.org/CVERecord?id=CVE-2024-40924 external
https://nvd.nist.gov/vuln/detail/CVE-2024-40924 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-40961 self
https://bugzilla.redhat.com/show_bug.cgi?id=2297545 external
https://www.cve.org/CVERecord?id=CVE-2024-40961 external
https://nvd.nist.gov/vuln/detail/CVE-2024-40961 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-40983 self
https://bugzilla.redhat.com/show_bug.cgi?id=2297567 external
https://www.cve.org/CVERecord?id=CVE-2024-40983 external
https://nvd.nist.gov/vuln/detail/CVE-2024-40983 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-40984 self
https://bugzilla.redhat.com/show_bug.cgi?id=2297568 external
https://www.cve.org/CVERecord?id=CVE-2024-40984 external
https://nvd.nist.gov/vuln/detail/CVE-2024-40984 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-41009 self
https://bugzilla.redhat.com/show_bug.cgi?id=2298412 external
https://www.cve.org/CVERecord?id=CVE-2024-41009 external
https://nvd.nist.gov/vuln/detail/CVE-2024-41009 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-41042 self
https://bugzilla.redhat.com/show_bug.cgi?id=2300412 external
https://www.cve.org/CVERecord?id=CVE-2024-41042 external
https://nvd.nist.gov/vuln/detail/CVE-2024-41042 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-41066 self
https://bugzilla.redhat.com/show_bug.cgi?id=2300442 external
https://www.cve.org/CVERecord?id=CVE-2024-41066 external
https://nvd.nist.gov/vuln/detail/CVE-2024-41066 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-41092 self
https://bugzilla.redhat.com/show_bug.cgi?id=2300487 external
https://www.cve.org/CVERecord?id=CVE-2024-41092 external
https://nvd.nist.gov/vuln/detail/CVE-2024-41092 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-41093 self
https://bugzilla.redhat.com/show_bug.cgi?id=2300488 external
https://www.cve.org/CVERecord?id=CVE-2024-41093 external
https://nvd.nist.gov/vuln/detail/CVE-2024-41093 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-42070 self
https://bugzilla.redhat.com/show_bug.cgi?id=2300508 external
https://www.cve.org/CVERecord?id=CVE-2024-42070 external
https://nvd.nist.gov/vuln/detail/CVE-2024-42070 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-42079 self
https://bugzilla.redhat.com/show_bug.cgi?id=2300517 external
https://www.cve.org/CVERecord?id=CVE-2024-42079 external
https://nvd.nist.gov/vuln/detail/CVE-2024-42079 external
https://lore.kernel.org/linux-cve-announce/202407… external
https://access.redhat.com/security/cve/CVE-2024-42244 self
https://bugzilla.redhat.com/show_bug.cgi?id=2303512 external
https://www.cve.org/CVERecord?id=CVE-2024-42244 external
https://nvd.nist.gov/vuln/detail/CVE-2024-42244 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2024-42284 self
https://bugzilla.redhat.com/show_bug.cgi?id=2305429 external
https://www.cve.org/CVERecord?id=CVE-2024-42284 external
https://nvd.nist.gov/vuln/detail/CVE-2024-42284 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2024-42292 self
https://bugzilla.redhat.com/show_bug.cgi?id=2305437 external
https://www.cve.org/CVERecord?id=CVE-2024-42292 external
https://nvd.nist.gov/vuln/detail/CVE-2024-42292 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2024-42301 self
https://bugzilla.redhat.com/show_bug.cgi?id=2305446 external
https://www.cve.org/CVERecord?id=CVE-2024-42301 external
https://nvd.nist.gov/vuln/detail/CVE-2024-42301 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2024-43854 self
https://bugzilla.redhat.com/show_bug.cgi?id=2305512 external
https://www.cve.org/CVERecord?id=CVE-2024-43854 external
https://nvd.nist.gov/vuln/detail/CVE-2024-43854 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2024-43880 self
https://bugzilla.redhat.com/show_bug.cgi?id=2306374 external
https://www.cve.org/CVERecord?id=CVE-2024-43880 external
https://nvd.nist.gov/vuln/detail/CVE-2024-43880 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2024-43889 self
https://bugzilla.redhat.com/show_bug.cgi?id=2307862 external
https://www.cve.org/CVERecord?id=CVE-2024-43889 external
https://nvd.nist.gov/vuln/detail/CVE-2024-43889 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2024-43892 self
https://bugzilla.redhat.com/show_bug.cgi?id=2307865 external
https://www.cve.org/CVERecord?id=CVE-2024-43892 external
https://nvd.nist.gov/vuln/detail/CVE-2024-43892 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2024-44935 self
https://bugzilla.redhat.com/show_bug.cgi?id=2307892 external
https://www.cve.org/CVERecord?id=CVE-2024-44935 external
https://nvd.nist.gov/vuln/detail/CVE-2024-44935 external
https://lore.kernel.org/linux-cve-announce/202408… external
https://access.redhat.com/security/cve/CVE-2024-44989 self
https://bugzilla.redhat.com/show_bug.cgi?id=2309852 external
https://www.cve.org/CVERecord?id=CVE-2024-44989 external
https://nvd.nist.gov/vuln/detail/CVE-2024-44989 external
https://lore.kernel.org/linux-cve-announce/202409… external
https://access.redhat.com/security/cve/CVE-2024-44990 self
https://bugzilla.redhat.com/show_bug.cgi?id=2309853 external
https://www.cve.org/CVERecord?id=CVE-2024-44990 external
https://nvd.nist.gov/vuln/detail/CVE-2024-44990 external
https://lore.kernel.org/linux-cve-announce/202409… external
https://access.redhat.com/security/cve/CVE-2024-45018 self
https://bugzilla.redhat.com/show_bug.cgi?id=2311715 external
https://www.cve.org/CVERecord?id=CVE-2024-45018 external
https://nvd.nist.gov/vuln/detail/CVE-2024-45018 external
https://lore.kernel.org/linux-cve-announce/202409… external
https://access.redhat.com/security/cve/CVE-2024-46679 self
https://bugzilla.redhat.com/show_bug.cgi?id=2312067 external
https://www.cve.org/CVERecord?id=CVE-2024-46679 external
https://nvd.nist.gov/vuln/detail/CVE-2024-46679 external
https://lore.kernel.org/linux-cve-announce/202409… external
https://access.redhat.com/security/cve/CVE-2024-46826 self
https://bugzilla.redhat.com/show_bug.cgi?id=2315178 external
https://www.cve.org/CVERecord?id=CVE-2024-46826 external
https://nvd.nist.gov/vuln/detail/CVE-2024-46826 external
https://lore.kernel.org/linux-cve-announce/202409… external
https://access.redhat.com/security/cve/CVE-2024-47668 self
https://bugzilla.redhat.com/show_bug.cgi?id=2317601 external
https://www.cve.org/CVERecord?id=CVE-2024-47668 external
https://nvd.nist.gov/vuln/detail/CVE-2024-47668 external
https://lore.kernel.org/linux-cve-announce/202410… external

Loading 1.9 MB of JSON…



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…