- kernel-4.14.336-256.557.amzn2 (amazon2)
- 4.14.348-265.565.amzn2
- 2024-07-18 21:31:44
- 2024-07-29 08:52:50
- K20240718_03
- CVE-2024-1086
- Description:
netfilter: nf_tables: reject QUEUE/DROP verdict parameters
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-1086.html
- Patch: amazon2/4.14.336-256.559.amzn2/CVE-2024-1086-netfilter-nf_tables-reject-QUEUE-DROP-verdict-parameters.patch
- From: kernel-4.14.336-256.559.amzn2
- CVE-2024-23849
- Description:
net/rds: Fix UBSAN: array-index-out-of-bounds in rds_cmsg_recv
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-23849.html
- Patch: amazon2/4.14.336-257.562.amzn2/CVE-2024-23849-patch-net-rds-fix-ubsan-array-index-out-of-bounds-in.patch
- From: 4.14.336-257.562.amzn2
- CVE-2023-52429
- Description:
dm: limit the number of targets and parameter size area
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52429.html
- Patch: amazon2/4.14.336-257.562.amzn2/CVE-2023-52429-patch-dm-limit-the-number-of-targets-and-parameter-size-area.patch
- From: 4.14.336-257.562.amzn2
- CVE-2023-6270
- Description:
Complex adaptation is required, vendor retired ATA over Ethernet driver.
- CVE:
- Patch: skipped/CVE-2023-6270.patch
- From:
- CVE-2024-2193 CVE-2024-26602
- Description:
sched/membarrier: reduce the ability to hammer on
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-26602.html
- Patch: amazon2/4.14.336-257.568.amzn2/CVE-2024-2193-CVE-2024-26602-sched-membarrier-reduce-the-ability-to-hammer-on.patch
- From: 4.14.336-257.568.amzn2
- CVE-2024-26625
- Description:
llc: call sock_orphan() at release time
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-26625.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2024-26625-llc-call-sock-orphan-at-release-time.patch
- From: 4.14.343-259.562.amzn2
- CVE-2024-26898
- Description:
aoe: fix the potential use-after-free problem in
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-26898.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2024-26898-aoe-fix-the-potential-use-after-free-problem-in.patch
- From: 4.14.343-259.562.amzn2
- CVE-2023-52464
- Description:
EDAC/thunderx: Fix possible out-of-bounds string access
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52464.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2023-52464.patch
- From: 4.14.343-259.562.amzn
- CVE-2023-52486
- Description:
drm: Don't unref the same fb many times by mistake due to deadlock
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52486.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2023-52486.patch
- From: 4.14.343-259.562.amzn
- CVE-2023-52698
- Description:
calipso: fix memory leak in netlbl_calipso_add_pass()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52698.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2023-52698.patch
- From: 4.14.343-259.562.amzn
- CVE-2024-0607
- Description:
netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-0607.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2024-0607.patch
- From: 4.14.343-259.562.amzn
- CVE-2023-46838
- Description:
xen-netback: don't produce zero-size SKB frags
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-46838.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2023-46838-xen-netback-don-t-produce-zero-size-skb-frags-304-226.patch
- From: 4.14.343-259.562.amzn
- CVE-2023-52628
- Description:
netfilter: nftables: exthdr: fix 4-byte stack OOB write
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52628.html
- Patch: amazon2/4.14.343-261.564.amzn2/CVE-2023-52628-netfilter-nftables-exthdr-fix-4-byte-stack-oob-write.patch
- From: 4.14.343-261.564.amzn2
- CVE-2023-1077
- Description:
sched/rt: pick_next_rt_entity(): check list_entry
- CVE: https://ubuntu.com/security/CVE-2023-1077
- Patch: amazon2/4.14.344-262.563.amzn2/CVE-2023-1077-sched-rt-pick_next_rt_entity-check-list_entry.patch
- From: 4.14.344-262.563
- CVE-2021-47110
- Description:
x86/kvm: Disable kvmclock on all CPUs on shutdown
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2021-47110.html
- Patch: amazon2/4.14.348-265.562.amzn2/CVE-2021-47110-x86-kvm-Disable-kvmclock-on-all-CPUs-on-shutdown.patch
- From: 4.14.348-265.562.amzn2
- CVE-2023-30456
- Description:
KVM: nVMX: add missing consistency checks for CR0 and CR4
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-30456.html
- Patch: amazon2/4.14.348-265.562.amzn2/CVE-2023-30456-KVM-nVMX-add-missing-consistency-checks-for-CR0-and-CR4.patch
- From: 4.14.348-265.562.amzn2
- n/a
- Description:
x86/xen: Add xenpv_restore_regs_and_return_to_usermode()
- CVE: n/a
- Patch: 4.14.0/x86-xen-Add-xenpv_restore_regs_and_return_to_usermode.patch
- From: v5.16
- N/A
- Description:
N/A
- CVE: N/A
- Patch: 4.14.0/kpatch-pti-add-KernelCare-mapping-into-shadow-PGD.patch
- From: N/A
- N/A
- Description:
N/A
- CVE: N/A
- Patch: 4.14.0/kpatch-add-asm-definitions.patch
- From: N/A
- N/A
- Description:
Restrict access to pagemap/kpageflags/kpagecount
- CVE: http://googleprojectzero.blogspot.ru/2015/03/exploiting-dram-rowhammer-bug-to-gain.html
- Patch: 4.15.0/proc-restrict-pagemap-access.patch
- From: N/A
- N/A
- Description:
vmx_vcpu_run wrapper
- CVE:
- Patch: 4.14.0/x86-kvm-vmx_vcpu_run-wrapper.patch
- From: