- kernel-4.14.276-211.499.amzn2 (amazon2)
- 4.14.348-265.565.amzn2
- 2024-07-18 21:31:32
- 2024-07-29 08:52:50
- K20240718_03
- CVE-2022-0812
- Description:
xprtrdma: fix incorrect header size calculations
- CVE: https://access.redhat.com/security/cve/CVE-2022-0812
- Patch: 4.14.0/CVE-2022-0812-xprtrdma-fix-incorrect-header-size-calculations.patch
- From: 4.14.285-215.501.amzn2
- CVE-2022-0494
- Description:
block-map: add __GFP_ZERO flag for alloc_page in function
- CVE: https://access.redhat.com/security/cve/CVE-2022-0494
- Patch: 5.4.0/CVE-2022-0494-block-map-add-__GFP_ZERO-for-alloc_page-in-bio_copy_kern.patch
- From: kernel-5.4.196-108.356.amzn2
- CVE-2022-1184
- Description:
ext4: verify dir block before splitting it
- CVE: https://access.redhat.com/security/cve/CVE-2022-1184
- Patch: 4.14.0/CVE-2022-1184-ext4-verify-dir-block-before-splitting-it.patch
- From: 4.14.285-215.501.amzn2
- CVE-2022-1184
- Description:
ext4: make variable "count" signed
- CVE: https://access.redhat.com/security/cve/CVE-2022-1184
- Patch: 4.14.0/CVE-2022-1184-ext4-make-variable-count-signed.patch
- From: 4.14.285-215.501.amzn2
- CVE-2022-1184
- Description:
ext4: avoid cycles in directory h-tree
- CVE: https://access.redhat.com/security/cve/CVE-2022-1184
- Patch: 4.14.0/CVE-2022-1184-ext4-avoid-cycles-in-directory-h-tree.patch
- From: 4.14.285-215.501.amzn2
- CVE-2022-32296
- Description:
perturb functionality missing in kernels earlier than 4.14.285-215.501.amzn2
- CVE:
- Patch: skipped/CVE-2022-32296.patch
- From:
- CVE-2022-1012
- Description:
secure_seq: use the 64 bits of the siphash for port offset
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-1012
- Patch: 4.14.0/CVE-2022-1012-secure_seq-use-the-64-bits-of-the-siphash-for-port-offset-211.patch
- From: 4.14.285-215.501.amzn2
- CVE-2022-32981
- Description:
Out of scope - related to PowerPC 32-bit.
- CVE:
- Patch: skipped/CVE-2022-32981.patch
- From:
- CVE-2022-1966
- Description:
Duplicate of CVE-2022-32250
- CVE:
- Patch: skipped/CVE-2022-1966.patch
- From:
- CVE-2022-32250
- Description:
netfilter: nf_tables: disallow non-stateful expression in
- CVE: https://access.redhat.com/security/cve/CVE-2022-32250
- Patch: 4.14.0/CVE-2022-32250-netfilter-nf_tables-disallow-non-stateful-expression-in.patch
- From: 4.14.285-215.501.amzn2
- CVE-2022-26365
- Description:
xen/blkfront: fix leaking data in shared pages
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-26365
- Patch: 4.14.0/CVE-2022-26365.patch
- From: v5.19
- CVE-2022-33740
- Description:
net: Rename and export copy_skb_header
- CVE: https://ubuntu.com/security/CVE-2022-33740
- Patch: 4.4.0/CVE-2022-33740-net-Rename-and-export-copy_skb_header.patch
- From: kernel-4.4.0-233.267
- CVE-2022-33740
- Description:
xen/netfront: fix leaking data in shared pages
- CVE: https://ubuntu.com/security/CVE-2022-33740
- Patch: 4.4.0/CVE-2022-33740-xen-netfront-fix-leaking-data-in-shared-pages.patch
- From: kernel-4.4.0-233.267
- CVE-2022-33741
- Description:
xen/netfront: force data bouncing when backend is untrusted
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-33741
- Patch: 4.14.0/CVE-2022-33741-285.patch
- From: v5.19
- CVE-2022-33741
- Description:
xen/netfront: force data bouncing when backend is untrusted (adaptation)
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-33741
- Patch: 4.14.0/CVE-2022-33741-kpatch-285.patch
- From: v5.19
- CVE-2022-33742
- Description:
xen/blkfront: force data bouncing when backend is untrusted
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-33742
- Patch: 4.14.0/CVE-2022-33742-285.patch
- From: v5.19
- CVE-2022-33742
- Description:
xen/blkfront: force data bouncing when backend is untrusted (adaptation)
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-33742
- Patch: 4.14.0/CVE-2022-33742-kpatch-285.patch
- From: v5.19
- CVE-2022-33744
- Description:
Out of scope - ARM architecture.
- CVE:
- Patch: skipped/CVE-2022-33744.patch
- From:
- CVE-2022-2318
- Description:
net: rose: fix UAF bugs caused by timer handler
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-2318
- Patch: 4.14.0/CVE-2022-2318-net-rose-fix-UAF-bugs-caused-by-timer-handler.patch
- From: 4.14.287-148.504
- CVE-2022-2318
- Description:
net: rose: fix UAF bugs caused by timer handler (adaptation)
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-2318
- Patch: 5.15.0/CVE-2022-2318-net-rose-fix-UAF-bugs-caused-by-timer-handler-kpatch.patch
- From: 5.15.0-48.54
- CVE-2021-33655
- Description:
fbcon: Disallow setting font bigger than screen size
- CVE: https://security-tracker.debian.org/tracker/CVE-2021-33655
- Patch: 4.14.0/CVE-2021-33655-fbcon-Disallow-setting-font-bigger-than-screen-size.patch
- From: 4.14.290-217.505
- CVE-2022-36879
- Description:
xfrm: xfrm_policy: fix a possible double xfrm_pols_put() in
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-36879
- Patch: 5.10.0/CVE-2022-36879-xfrm-xfrm_policy-fix-a-possible-double-xfrm_pols_put-in.patch
- From: 5.10.136-1
- CVE-2022-36123
- Description:
x86: Clear .brk area at early boot
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-36123
- Patch: 4.14.0/CVE-2022-36123-x86-Clear-brk-area-at-early-boot.patch
- From: 4.14.290-217.505
- N/A
- Description:
N/A
- CVE: N/A
- Patch: 4.14.0/kpatch-fense_swapgs_entry.patch
- From: N/A
- CVE-2022-1679
- Description:
[PATCH v4 1/2] ath9k: fix use-after-free in ath9k_hif_usb_rx_cb
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-1679
- Patch: ubuntu-bionic/4.15.0-191.202/0010-CVE-2022-1679-UBUNTU-SAUCE-ath9k-fix-use-after-free-in-ath9k_hif_u.patch
- From: 4.15.0-191.202
- CVE-2022-2153
- Description:
KVM: x86: Check lapic_in_kernel() before attempting to set a SynIC irq
- CVE: https://ubuntu.com/security/CVE-2022-2153
- Patch: 5.15.0/CVE-2022-2153-KVM-x86-Check-lapic_in_kernel-before-attempting-to-set-a-SynIC-irq.patch
- From: 5.15.35-36
- CVE-2022-2153
- Description:
KVM: x86: Avoid theoretical NULL pointer dereference in kvm_irq_delivery_to_apic_fast()
- CVE: https://ubuntu.com/security/CVE-2022-2153
- Patch: 5.15.0/CVE-2022-2153-KVM-x86-Avoid-theoretical-NULL-pointer-dereference-in-kvm_irq_delivery_to_apic_fast.patch
- From: 5.15.35-36
- CVE-2022-2153
- Description:
KVM: Add infrastructure and macro to mark VM as bugged
- CVE: https://ubuntu.com/security/CVE-2022-2153
- Patch: 4.14.0/CVE-2022-2153-KVM-Add-infrastructure-and-macro-to-mark-VM-as-bugged.patch
- From: 4.14.291
- CVE-2022-2153
- Description:
KVM: x86: Check lapic_in_kernel() before attempting to set a SynIC irq (adaptation)
- CVE: https://ubuntu.com/security/CVE-2022-2153
- Patch: 4.14.0/CVE-2022-2153-KVM-x86-Check-lapic_in_kernel-before-attempting-to-set-a-SynIC-irq-kpatch.patch
- From: 4.14.291
- CVE-2022-2588
- Description:
UBUNTU: SAUCE: net_sched: cls_route: remove from list when handle is 0
- CVE: https://access.redhat.com/security/cve/cve-2022-2588
- Patch: ubuntu-bionic/4.15.0-191.202/CVE-2022-2588-UBUNTU-SAUCE-net_sched-cls_route-remove-from-list-when-handle-is-0.patch
- From: kernel-4.15.0-191.202
- CVE-2022-26373
- Description:
Livepatching Retbleed may decrease the stability and performance of the kernel, while vulnerability has a medium security impact and only for a certain hardware environment.
- CVE:
- Patch: skipped/CVE-2022-26373.patch
- From:
- CVE-2022-29901
- Description:
Livepatching Retbleed may decrease the stability and performance of the kernel, while vulnerability has a medium security impact and only for a certain hardware environment.
- CVE:
- Patch: skipped/CVE-2022-29901.patch
- From:
- CVE-2022-36946
- Description:
netfilter: nf_queue: do not allow packet truncation below transport header offset
- CVE: https://ubuntu.com/security/CVE-2022-36946
- Patch: 4.4.0/CVE-2022-36946-netfilter-nf_queue-do-not-allow-packet-truncation-below-transport-header-offset.patch
- From: 4.15.0-192.203~16.04.1
- CVE-2022-3594
- Description:
r8152: Rate limit overflow messages
- CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3594
- Patch: 4.14.0/CVE-2022-3594-r8152-rate-limit-overflow-messages.patch
- From: 4.14.296-222.539
- CVE-2022-3621
- Description:
nilfs2: fix NULL pointer dereference at nilfs_bmap_lookup_at_level()
- CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3621
- Patch: 4.14.0/CVE-2022-3621-nilfs2-fix-NULL-pointer-dereference-at-nilfs_bmap_lookup_at_level.patch
- From: 4.14.296-222.539
- CVE-2022-3646
- Description:
nilfs2: fix leak of nilfs_root in case of writer thread creation failure
- CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3646
- Patch: 4.14.0/CVE-2022-3646-nilfs2-fix-leak-of-nilfs_root-in-case-of-writer-thread-creation-failure.patch
- From: 4.14.296-222.539
- CVE-2022-3649
- Description:
nilfs2: fix leak of nilfs_root in case of writer thread creation failure
- CVE: https://access.redhat.com/security/cve/cve-2022-3649
- Patch: 4.14.0/CVE-2022-3649-nilfs2-fix-use-after-free-bug-of-struct-nilfs_root.patch
- From: 4.14.296
- CVE-2022-39842
- Description:
video: fbdev: pxa3xx-gcu: Fix integer overflow in pxa3xx_gcu_write
- CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39842
- Patch: 4.14.0/CVE-2022-39842-video-fbdev-pxa3xx-gcu-fix-integer-overflow-in-pxa3xx_gcu_write.patch
- From: 4.14.296-222.539
- CVE-2022-40768
- Description:
scsi: stex: Properly zero out the passthrough command structure
- CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40768
- Patch: 4.14.0/CVE-2022-40768-scsi-stex-properly-zero-out-the-passthrough-command-structure.patch
- From: 4.14.296-222.539
- CVE-2022-20369
- Description:
media: v4l2-mem2mem: Apply DST_QUEUE_OFF_BASE on MMAP buffers across
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2022-20369.html
- Patch: 4.14.0/CVE-2022-20369-media-v4l2-mem2mem-apply-dst-queue-off-base-on-mmap-buffers-across.patch
- From: 4.14.299-223.520
- CVE-2022-3564
- Description:
Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu
- CVE: https://ubuntu.com/security/CVE-2022-3564
- Patch: ubuntu-bionic/4.15.0-200.211/0010-CVE-2022-3564-Bluetooth-L2CAP-Fix-use-after-free-caused-by-l2cap_r.patch
- From: 4.15.0-200.211
- CVE-2022-3643
- Description:
xen/netback: Ensure protocol headers don't fall in the non-linear area
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2022-3643.html
- Patch: 4.14.0/CVE-2022-3643-xen-netback-Ensure-protocol-headers-dont-fall-in-the-non-linear-area.patch
- From: kernel-4.14.304-226.531.amzn2
- CVE-2022-45934
- Description:
Bluetooth: L2CAP: Fix u8 overflow
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2022-45934.html
- Patch: 4.14.0/CVE-2022-45934-Bluetoot-L2CAP-Fix-u8-overflow.patch
- From: kernel-4.14.304-226.531.amzn2
- CVE-2022-47929
- Description:
net: sched: disallow noqueue for qdisc classes
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2022-47929.html
- Patch: 4.14.0/CVE-2022-47929-net-sched-disallow-noqueue-for-qdisc-classes.patch
- From: kernel-4.14.304-226.531.amzn2
- CVE-2023-0394
- Description:
ipv6: raw: Deduct extension header length in rawv6_push_pending_frames
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-0394.html
- Patch: 4.14.0/CVE-2023-0394-ipv6-raw-Deduct-extension-header-length-in-rawv6_push_pending_frames.patch
- From: kernel-4.14.304-226.531.amzn2
- CVE-2023-23455
- Description:
net: sched: atm: dont intepret cls results when asked to drop
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-23455.html
- Patch: 4.14.0/CVE-2023-23455-net-sched-atm-dont-intepret-cls-results-when-asked-to-drop.patch
- From: kernel-4.14.304-226.531.amzn2
- CVE-2023-1073
- Description:
HID: check empty report_list in hid_validate_values()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-1073.html
- Patch: amazon2/4.14.305-227.531.amzn2/CVE-2023-1073-patch-hid-check-empty-report-list-in-hid-validate-values.patch
- From: 4.14.305-227.531.amzn2
- CVE-2022-0854
- Description:
Reinstate some of "swiotlb: rework "fix info leak with DMA_FROM_DEVICE""
- CVE: https://access.redhat.com/security/cve/CVE-2022-0854
- Patch: 4.14.0/CVE-2022-0854.patch
- From: v4.14
- CVE-2022-1729
- Description:
perf: Fix sys_perf_event_open() race against self
- CVE: https://access.redhat.com/security/cve/CVE-2022-1729
- Patch: 4.14.0/CVE-2022-1729.patch
- From: >kernel-4.14.281-212.502.amzn2
- CVE-2022-29581
- Description:
net/sched: cls_u32: fix netns refcount changes in u32_change()
- CVE: https://access.redhat.com/security/cve/CVE-2022-29581
- Patch: 4.14.0/CVE-2022-29581.patch
- From: >kernel-4.14.281-212.502.amzn2
- CVE-2022-1462
- Description:
tty: extract tty_flip_buffer_commit() from tty_flip_buffer_push()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-1462
- Patch: 5.4.0/CVE-2022-1462-tty-extract-tty_flip_buffer_commit-from-tty_flip_buffer_push.patch
- From: v5.4
- CVE-2022-1462
- Description:
tty: use new tty_insert_flip_string_and_push_buffer() in pty_write()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-1462
- Patch: 5.4.0/CVE-2022-1462-tty-use-new-tty_insert_flip_string_and_push_buffer-in-pty_write.patch
- From: v5.4
- CVE-2022-2663
- Description:
netfilter: nf_conntrack_irc: Fix forged IP logic
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-2663
- Patch: 4.14.0/CVE-2022-2663-netfilter-nf_conntrack_irc-Fix-forged-IP-logic.patch
- From: 4.14.293
- CVE-2022-40307
- Description:
efi: capsule-loader: Fix use-after-free in efi_capsule_write
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-40307
- Patch: 4.14.0/CVE-2022-40307-efi-capsule-loader-Fix-use-after-free-in-efi_capsule_write.patch
- From: 4.14.293
- CVE-2022-40307
- Description:
efi: capsule-loader: Fix use-after-free in efi_capsule_write (adaptation)
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-40307
- Patch: 4.14.0/CVE-2022-40307-efi-capsule-loader-Fix-use-after-free-in-efi_capsule_write-kpatch.patch
- From: 4.14.293
- CVE-2022-3028
- Description:
af_key: Do not call xfrm_probe_algs in parallel
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-3028
- Patch: 5.10.0/CVE-2022-3028-af_key-Do-not-call-xfrm_probe_algs-in-parallel.patch
- From: 5.10.140-1
- CVE-2023-26545
- Description:
net: mpls: fix stale pointer if allocation fails during device rename
- CVE: https://access.redhat.com/security/cve/CVE-2023-26545
- Patch: 4.14.0/CVE-2023-26545-net-mpls-fix-stale-pointer-if-allocation-fails-during-device-rename.patch
- From: kernel-4.14.309-231.529.amzn2
- CVE-2023-1829
- Description:
Complex adaptation is required, mainline retired tcindex.
- CVE:
- Patch: skipped/CVE-2023-1829.patch
- From:
- CVE-2023-0458
- Description:
prlimit: do_prlimit needs to have a speculation check
- CVE: https://access.redhat.com/security/cve/CVE-2023-0458
- Patch: 4.14.0/CVE-2023-0458-prlimit-do_prlimit-needs-to-have-a-speculation-check.patch
- From: kernel-4.14.309-231.529.amzn2
- CVE-2023-2162
- Description:
scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress
- CVE: https://access.redhat.com/security/cve/CVE-2023-2162
- Patch: 4.14.0/CVE-2023-2162-scsi-iscsi_tcp-Fix-UAF-during-login-when-accessing-the-shost-ipaddress.patch
- From: kernel-4.14.309-231.529.amzn2
- CVE-2023-45862
- Description:
USB: ene_usb6250: Allocate enough memory for full object
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-45862.html
- Patch: 4.14.0/CVE-2023-45862-USB-ene_usb6250-Allocate-enough-memory-for-full-object.patch
- From: kernel-4.14.309-231.529.amzn2
- CVE-2023-1838
- Description:
Fix double fget() in vhost_net_set_backend()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-1838.html
- Patch: 4.14.0/CVE-2023-1838-Fix-double-fget-in-vhost_net_set_backend.patch
- From: kernel-4.14.313-235.533.amzn2
- CVE-2023-2002
- Description:
bluetooth: Perform careful capability checks in hci_sock_ioctl()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-2002.html
- Patch: 4.14.0/CVE-2023-2002-01-bluetooth-Perform-careful-capability-checks-in-hci_sock_ioctl.patch
- From: kernel-4.14.313-235.533.amzn2
- CVE-2023-2002
- Description:
bluetooth: Add cmd validity checks at the start of hci_sock_ioctl()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-2002.html
- Patch: 4.14.0/CVE-2023-2002-02-bluetooth-Add-cmd-validity-checks-at-the-start-of-hci_sock_ioctl.patch
- From: kernel-4.14.313-235.533.amzn2
- CVE-2023-2124
- Description:
xfs: verify buffer contents when we skip log replay
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-2124.html
- Patch: 4.14.0/CVE-2023-2124-xfs-verify-buffer-contents-when-we-skip-log-replay.patch
- From: kernel-4.14.313-235.533.amzn2
- CVE-2023-23454
- Description:
net: sched: cbq: dont intepret cls results when asked to drop
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-23454.html
- Patch: 4.14.0/CVE-2023-23454-net-sched-cbq-dont-intepret-cls-results-when-asked-to-drop.patch
- From: kernel-4.14.313-235.533.amzn2
- CVE-2023-33203
- Description:
net: qcom/emac: Fix use after free bug in emac_remove due to race condition
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-33203.html
- Patch: 4.14.0/CVE-2023-33203-net-qcom-emac-Fix-use-after-free-bug-in-emac_remove-due-to-race-condition.patch
- From: kernel-4.14.313-235.533.amzn2
- CVE-2023-2194
- Description:
i2c: xgene-slimpro: Fix out-of-bounds bug in xgene_slimpro_i2c_xfer()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-2194.html
- Patch: 4.14.0/CVE-2023-2194-i2c-xgene-slimpro-Fix-out-of-bounds-bug-in-xgene_slimpro_i2c_xfer.patch
- From: kernel-4.14.313-235.533.amzn2
- CVE-2023-2513
- Description:
ext4: add EXT4_INODE_HAS_XATTR_SPACE macro in xattr.h
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-2513.html
- Patch: 4.14.0/CVE-2023-2513-01-ext4-add-EXT4_INODE_HAS_XATTR_SPACE-macro-in-xattr.patch
- From: kernel-4.14.314-237.533.amzn2
- CVE-2023-2513
- Description:
ext4: fix use-after-free in ext4_xattr_set_entry
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-2513.html
- Patch: 4.14.0/CVE-2023-2513-02-ext4-fix-use-after-free-in-ext4_xattr_set_entry.patch
- From: kernel-4.14.314-237.533.amzn2
- CVE-2023-31436
- Description:
net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-31436.html
- Patch: 4.14.0/CVE-2023-31436-net-sched-sch_qfq-prevent-slab-out-of-bounds-in-qfq_activate_agg.patch
- From: kernel-4.14.314-237.533.amzn2
- CVE-2023-32233
- Description:
netfilter: nf_tables: split set destruction in deactivate and destroy phase
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-32233.html
- Patch: amazon2/4.14.314-238.539.amzn2/CVE-2023-32233-netfilter-nf_tables-split-set-destruction-in-deactivate-and-destroy-phase.patch
- From: 4.14.314-238.539
- CVE-2023-32233
- Description:
netfilter: nft_hash: fix nft_hash_deactivate
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-32233.html
- Patch: amazon2/4.14.314-238.539.amzn2/CVE-2023-32233-netfilter-nft_hash-fix-nft_hash_deactivate.patch
- From: 4.14.314-238.539
- CVE-2023-32233
- Description:
netfilter: nf_tables: bogus EBUSY when deleting set after flush
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-32233.html
- Patch: amazon2/4.14.314-238.539.amzn2/CVE-2023-32233-netfilter-nf_tables-bogus-EBUSY-when-deleting-set-after-flush.patch
- From: 4.14.314-238.539
- CVE-2023-32233
- Description:
netfilter: nf_tables: deactivate anonymous set from preparation phase
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-32233.html
- Patch: amazon2/4.14.314-238.539.amzn2/CVE-2023-32233-netfilter-nf_tables-deactivate-anonymous-set-from-preparation-phase.patch
- From: 4.14.314-238.539
- CVE-2023-32233
- Description:
netfilter: nf_tables: split set destruction in deactivate and destroy phase (adaptation)
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-32233.html
- Patch: amazon2/4.14.314-238.539.amzn2/CVE-2023-32233-netfilter-nf_tables-split-set-destruction-in-deactivate-and-destroy-phase-kpatch.patch
- From: 4.14.314-238.539
- CVE-2023-32233
- Description:
netfilter: nf_tables: bogus EBUSY when deleting set after flush (Revert)
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-32233.html
- Patch: amazon2/4.14.314-238.539.amzn2/CVE-2023-32233-netfilter-nf_tables-bogus-EBUSY-when-deleting-set-after-flush-kpatch.patch
- From: 4.14.314-238.539
- CVE-2023-32233
- Description:
netfilter: nf_tables: split set destruction in deactivate and destroy phase
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-32233.html
- Patch: amazon2/4.14.314-238.539.amzn2/CVE-2023-32233-netfilter-nf_tables-unbind-kpatch.patch
- From: 4.14.314-238.539
- CVE-2023-32233
- Description:
netfilter: nf_tables: split set destruction in deactivate and destroy phase
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-32233.html
- Patch: amazon2/4.14.314-238.539.amzn2/CVE-2023-32233-netfilter-kpatch.patch
- From: 4.14.314-238.539
- CVE-2023-28466
- Description:
net: tls: fix possible race condition between
- CVE: https://alas.aws.amazon.com/
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2023-28466-patch-net-tls-fix-possible-race-condition-between.patch
- From: 4.14.318-240.529.amzn2
- CVE-2023-3090
- Description:
ipvlan:Fix out-of-bounds caused by unclear skb->cb
- CVE: https://alas.aws.amazon.com/
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2023-3090-patch-ipvlan-fix-out-of-bounds-caused-by-unclear-skb-cb.patch
- From: 4.14.318-240.529.amzn2
- CVE-2023-34256
- Description:
ext4: avoid a potential slab-out-of-bounds in ext4_group_desc_csum
- CVE: https://alas.aws.amazon.com/
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2023-34256-patch-ext4-avoid-a-potential-slab-out-of-bounds-in.patch
- From: 4.14.318-240.529.amzn2
- CVE-2023-2269
- Description:
Re: Possible deadlock detected in Linux 6.2.0 in
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-2269.html
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2023-2269-re-possible-deadlock-detected-in-linux-6-2-0-in.patch
- From: 4.14.318-240.529.amzn2
- CVE-2022-2586
- Description:
netfilter: nf_tables: do not allow RULE_ID to refer to another chain
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2022-2586.html
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2022-2586-netfilter-nf-tables-do-not-allow-rule-id-to-refer-to-another-chain.patch
- From: 4.14.318-240.529.amzn2
- CVE-2022-2586
- Description:
netfilter: nf_tables: do not allow RULE_ID to refer to another chain
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2022-2586.html
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2022-2586-netfilter-nf-tables-do-not-allow-set-id-to-refer-to-another-table-pre-318.patch
- From: 4.14.318-240.529.amzn2
- CVE-2022-2586
- Description:
netfilter: nf_tables: do not allow RULE_ID to refer to another chain
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2022-2586.html
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2022-2586-netfilter-nf-tables-do-not-allow-set-id-to-refer-to-another-table-pre-318-kpatch.patch
- From: 4.14.318-240.529.amzn2
- CVE-2022-34918
- Description:
netfilter: nf_tables: stricter validation of element data
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2022-34918.html
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2022-34918-netfilter-nf_tables-stricter-validation-of-element-d.patch
- From: 4.14.318-240.529.amzn2
- CVE-2023-3111
- Description:
btrfs: unset reloc control if transaction commit fails in prepare_to_relocate()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3111.htm
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2023-3111-1-btrfs-check-return-value-of-btrfs_commit_transaction.patch
- From: 4.14.318-240.529.amzn2
- CVE-2023-3111
- Description:
btrfs: unset reloc control if transaction commit fails in prepare_to_relocate()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3111.htm
- Patch: amazon2/4.14.318-240.529.amzn2/CVE-2023-3111-btrfs-unset-reloc-control-if-transaction-commit-fail.patch
- From: 4.14.318-240.529.amzn2
- CVE-2023-3117
- Description:
netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3117.html
- Patch: 4.14.0/CVE-2023-3117-netfilter-nf_tables-incorrect-error-path-handling-with-NFT_MSG_NEWRULE.patch
- From: kernel-4.14.320-242.534.amzn2
- CVE-2023-35001
- Description:
netfilter: nf_tables: prevent OOB access in nft_byteorder_eval
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-35001.html
- Patch: 4.14.0/CVE-2023-35001-netfilter-nf_tables-prevent-OOB-access-in-nft_byteorder_eval.patch
- From: kernel-4.14.320-242.534.amzn2
- CVE-2023-3609
- Description:
net/sched: cls_u32: Fix reference counter leak leading to overflow
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3609.html
- Patch: 4.14.0/CVE-2023-3609-net-sched-cls_u32-Fix-reference-counter-leak-leading-to-overflow.patch
- From: kernel-4.14.320-243.544.amzn2
- CVE-2023-3611
- Description:
net/sched: sch_qfq: account for stab overhead in qfq_enqueue
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3611.html
- Patch: 4.14.0/CVE-2023-3611-net-sched-sch_qfq-account-for-stab-overhead-in-qfq_enqueue.patch
- From: kernel-4.14.320-243.544.amzn2
- CVE-2023-3776
- Description:
net/sched: cls_fw: Fix improper refcount update leads to use-after-free
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3776.html
- Patch: 4.14.0/CVE-2023-3776-net-sched-cls_fw-Fix-improper-refcount-update-leads-to-use-after-free.patch
- From: kernel-4.14.320-243.544.amzn2
- CVE-2023-20569
- Description:
A low priority AMD Inception vulnerability that affects Zen3/Zen4 & relates to RetBleed fixes requiring microcode updates, we can't do much about it in KCare Infra.
- CVE:
- Patch: skipped/CVE-2023-20569.patch
- From:
- CVE-2023-3212
- Description:
gfs2: Don't deref jdesc in evict
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3212.html
- Patch: amazon2/4.14.322-244.536.amzn2/CVE-2023-3212-patch-gfs2-don-t-deref-jdesc-in-evict.patch
- From: 4.14.322-244.536.amzn2
- CVE-2023-1206
- Description:
This is a low priority CVE & the patch impacts many critical components of the networking subsystem & it requires multiple complex adaptations in those components to avoid losing existing connections on patch/unpatch.
- CVE:
- Patch: skipped/CVE-2023-1206.patch
- From:
- CVE-2023-4128
- Description:
net/sched: cls_route: No longer copy tcf_result on update to avoid
- CVE: https://alas.aws.amazon.com/
- Patch: amazon2/4.14.322-244.536.amzn2/CVE-2023-4128-patch-net-sched-cls-route-no-longer-copy-tcf-result-on-update-to.patch
- From: 4.14.322-244.536.amzn2
- CVE-2023-4128
- Description:
net/sched: cls_u32: No longer copy tcf_result on update to avoid
- CVE: https://alas.aws.amazon.com/
- Patch: amazon2/4.14.322-244.536.amzn2/CVE-2023-4128-patch-net-sched-cls-u32-no-longer-copy-tcf-result-on-update-to.patch
- From: 4.14.322-244.536.amzn2
- CVE-2023-3772
- Description:
xfrm: add NULL check in xfrm_update_ae_params
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3772.html
- Patch: 4.14.0/CVE-2023-3772-xfrm-add-NULL-check-in-xfrm_update_ae_params.patch
- From: kernel-4.14.326-245.539.amzn2
- CVE-2023-4622
- Description:
af_unix: Fix null-ptr-deref in unix_stream_sendpage().
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-4622.html
- Patch: 4.14.0/CVE-2023-4622-af_unix-Fix-null-ptr-deref-in-unix_stream_sendpage.patch
- From: kernel-4.14.326-245.539.amzn2
- CVE-2023-4623
- Description:
net/sched: sch_hfsc: Ensure inner classes have fsc curve
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-4623.html
- Patch: 4.14.0/CVE-2023-4623-net-sched-sch_hfsc-Ensure-inner-classes-have-fsc-curve.patch
- From: kernel-4.14.326-245.539.amzn2
- CVE-2023-4921
- Description:
net: sched: sch_qfq: Fix UAF in qfq_dequeue()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-4921.html
- Patch: 4.14.0/CVE-2023-4921-net-sched-sch_qfq-Fix-UAF-in-qfq_dequeue.patch
- From: kernel-4.14.326-245.539.amzn2
- CVE-2023-4921
- Description:
net: sched: sch_qfq: Fix UAF in qfq_dequeue() (adaptation)
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-4921.html
- Patch: 4.14.0/CVE-2023-4921-net-sched-sch_qfq-Fix-UAF-in-qfq_dequeue-kpatch.patch
- From: kernel-4.14.326-245.539.amzn2
- CVE-2023-42755
- Description:
The patch removes functionality.
- CVE:
- Patch: skipped/CVE-2023-42755.patch
- From:
- CVE-2023-4244
- Description:
An introduction of required changes through KernelCare could cause unavoidable problems to applications which use netfilter functionality.
- CVE:
- Patch: skipped/CVE-2023-4244.patch
- From:
- CVE-2023-42753
- Description:
netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-42753.html
- Patch: 4.14.0/CVE-2023-42753-netfilter-ipset-add-the-missing-IP_SET_HASH_WITH_NET0.patch
- From: 4.14.326-245.539.amzn2
- CVE-2023-34324
- Description:
xen/events: replace evtchn_rwlock with RCU
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-34324.html
- Patch: amazon2/4.14.327-246.539.amzn2/CVE-2023-34324-xen-events-replace-evtchn_rwlock-with-RCU.patch
- From: 4.14.327-246.539.amzn2
- CVE-2023-34324
- Description:
xen/events: replace evtchn_rwlock with RCU (adaptation)
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-34324.html
- Patch: amazon2/4.14.327-246.539.amzn2/CVE-2023-34324-xen-events-replace-evtchn_rwlock-with-RCU-kpatch.patch
- From: 4.14.327-246.539.amzn2
- CVE-2023-3397
- Description:
fs/jfs: Add a mutex named txEnd_lmLogClose_mutex to prevent a race condition between txEnd and lmLogClose functions
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3397.html
- Patch: amazon2/4.14.328-248.540.amzn2/CVE-2023-3397-fs_jfs-Add-a-mutex-named-txEnd_lmLogClose_mutex-to-prevent-a-race-condition-between-txEnd-and-lmLogClose-functions.patch
- From: 4.14.328-248.540.amzn2
- CVE-2023-5717
- Description:
perf: Disallow mis-matched inherited group reads (adaptation)
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-5717.html
- Patch: amazon2/4.14.328-248.540.amzn2/CVE-2023-5717-perf-disallow-mis-matched-inherited-group-reads.patch
- From: 4.14.328-248.540.amzn2
- CVE-2023-5717
- Description:
perf: Disallow mis-matched inherited group reads (adaptation)
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-5717.html
- Patch: amazon2/4.14.328-248.540.amzn2/CVE-2023-5717-perf-disallow-mis-matched-inherited-group-reads-kpatch.patch
- From: 4.14.328-248.540.amzn2
- CVE-2023-3567
- Description:
vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-3567.html
- Patch: amazon2/4.14.330-250.540.amzn2/CVE-2023-3567-patch-vc-screen-move-load-of-struct-vc-data-pointer-in-vcs-read.patch
- From: 4.14.330-250.540.amzn2
- CVE-2023-39198
- Description:
drm/qxl: fix UAF on handle creation
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-39198.html
- Patch: amazon2/4.14.334-252.552.amzn2/CVE-2023-39198-1.patch
- From: 4.14.334-252.552.amzn2
- CVE-2023-6932
- Description:
ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-6932.html
- Patch: amazon2/4.14.334-252.552.amzn2/CVE-2023-6932.patch
- From: 4.14.334-252.552.amzn2
- CVE-2023-6606
- Description:
smb: client: fix OOB in smbCalcSize()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-6606.html
- Patch: amazon2/4.14.336-253.554.amzn2/CVE-2023-6606-patch-smb-client-fix-oob-in-smbcalcsize.patch
- From: 4.14.336-253.554.amzn2
- CVE-2023-6040
- Description:
netfilter: nf_tables: Reject tables of unsupported family
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-6040.html
- Patch: amazon2/4.14.336-255.557.amzn2/CVE-2023-6040-netfilter-nf_tables-Reject-tables-of-unsupported-family.patch
- From: 4.14.336-255.557.amzn2
- CVE-2023-6546
- Description:
tty: n_gsm: fix the UAF caused by race condition in gsm_cleanup_mux
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-6546.html
- Patch: amazon2/4.14.336-255.557.amzn2/CVE-2023-6546-tty-n_gsm-fix-the-UAF-caused-by-race-condition-in-gsm_cleanup_mux-pre281.patch
- From: 4.14.336-255.557.amzn2
- CVE-2023-6931
- Description:
perf: Fix perf_event_validate_size()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-6931.html
- Patch: amazon2/4.14.336-255.557.amzn2/CVE-2023-6931-patch-perf-fix-perf-event-validate-size.patch
- From: 4.14.336-255.557.amzn2
- CVE-2024-1086
- Description:
netfilter: nf_tables: reject QUEUE/DROP verdict parameters
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-1086.html
- Patch: amazon2/4.14.336-256.559.amzn2/CVE-2024-1086-netfilter-nf_tables-reject-QUEUE-DROP-verdict-parameters-pre-246.539.patch
- From: kernel-4.14.336-256.559.amzn2
- CVE-2024-23849
- Description:
net/rds: Fix UBSAN: array-index-out-of-bounds in rds_cmsg_recv
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-23849.html
- Patch: amazon2/4.14.336-257.562.amzn2/CVE-2024-23849-patch-net-rds-fix-ubsan-array-index-out-of-bounds-in.patch
- From: 4.14.336-257.562.amzn2
- CVE-2023-52429
- Description:
dm: limit the number of targets and parameter size area
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52429.html
- Patch: amazon2/4.14.336-257.562.amzn2/CVE-2023-52429-patch-dm-limit-the-number-of-targets-and-parameter-size-area.patch
- From: 4.14.336-257.562.amzn2
- CVE-2023-6270
- Description:
Complex adaptation is required, vendor retired ATA over Ethernet driver.
- CVE:
- Patch: skipped/CVE-2023-6270.patch
- From:
- CVE-2024-2193 CVE-2024-26602
- Description:
sched/membarrier: reduce the ability to hammer on
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-26602.html
- Patch: amazon2/4.14.336-257.568.amzn2/CVE-2024-2193-CVE-2024-26602-sched-membarrier-reduce-the-ability-to-hammer-on.patch
- From: 4.14.336-257.568.amzn2
- CVE-2024-26625
- Description:
llc: call sock_orphan() at release time
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-26625.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2024-26625-llc-call-sock-orphan-at-release-time.patch
- From: 4.14.343-259.562.amzn2
- CVE-2024-26898
- Description:
aoe: fix the potential use-after-free problem in
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-26898.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2024-26898-aoe-fix-the-potential-use-after-free-problem-in.patch
- From: 4.14.343-259.562.amzn2
- CVE-2023-52464
- Description:
EDAC/thunderx: Fix possible out-of-bounds string access
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52464.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2023-52464.patch
- From: 4.14.343-259.562.amzn
- CVE-2023-52486
- Description:
drm: Don't unref the same fb many times by mistake due to deadlock
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52486.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2023-52486.patch
- From: 4.14.343-259.562.amzn
- CVE-2023-52698
- Description:
calipso: fix memory leak in netlbl_calipso_add_pass()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52698.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2023-52698.patch
- From: 4.14.343-259.562.amzn
- CVE-2024-0607
- Description:
netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2024-0607.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2024-0607.patch
- From: 4.14.343-259.562.amzn
- CVE-2023-46838
- Description:
xen-netback: don't produce zero-size SKB frags
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-46838.html
- Patch: amazon2/4.14.343-259.562.amzn2/CVE-2023-46838-xen-netback-don-t-produce-zero-size-skb-frags-301-225.patch
- From: 4.14.343-259.562.amzn
- CVE-2023-52628
- Description:
netfilter: nftables: exthdr: fix 4-byte stack OOB write
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-52628.html
- Patch: amazon2/4.14.343-261.564.amzn2/CVE-2023-52628-netfilter-nftables-exthdr-fix-4-byte-stack-oob-write.patch
- From: 4.14.343-261.564.amzn2
- CVE-2023-1077
- Description:
sched/rt: pick_next_rt_entity(): check list_entry
- CVE: https://ubuntu.com/security/CVE-2023-1077
- Patch: amazon2/4.14.344-262.563.amzn2/CVE-2023-1077-sched-rt-pick_next_rt_entity-check-list_entry.patch
- From: 4.14.344-262.563
- CVE-2021-47110
- Description:
x86/kvm: Disable kvmclock on all CPUs on shutdown
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2021-47110.html
- Patch: amazon2/4.14.348-265.562.amzn2/CVE-2021-47110-x86-kvm-Disable-kvmclock-on-all-CPUs-on-shutdown-326.patch
- From: 4.14.348-265.562.amzn2
- CVE-2023-30456
- Description:
KVM: nVMX: add missing consistency checks for CR0 and CR4
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-30456.html
- Patch: amazon2/4.14.348-265.562.amzn2/CVE-2023-30456-KVM-nVMX-add-missing-consistency-checks-for-CR0-and-CR4.patch
- From: 4.14.348-265.562.amzn2
- n/a
- Description:
x86/xen: Add xenpv_restore_regs_and_return_to_usermode()
- CVE: n/a
- Patch: 4.14.0/x86-xen-Add-xenpv_restore_regs_and_return_to_usermode.patch
- From: v5.16
- N/A
- Description:
N/A
- CVE: N/A
- Patch: 4.14.0/kpatch-pti-add-KernelCare-mapping-into-shadow-PGD.patch
- From: N/A
- N/A
- Description:
N/A
- CVE: N/A
- Patch: 4.14.0/kpatch-add-asm-definitions.patch
- From: N/A
- N/A
- Description:
Restrict access to pagemap/kpageflags/kpagecount
- CVE: http://googleprojectzero.blogspot.ru/2015/03/exploiting-dram-rowhammer-bug-to-gain.html
- Patch: 4.15.0/proc-restrict-pagemap-access.patch
- From: N/A
- N/A
- Description:
vmx_vcpu_run wrapper
- CVE:
- Patch: 4.14.0/x86-kvm-vmx_vcpu_run-wrapper.patch
- From:
- CVE-2023-20588
- Description:
x86/CPU/AMD: Do not leak quotient data after a division by 0
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-20588.html
- Patch: 4.14.0/CVE-2023-20588-x86-CPU-AMD-Do-not-leak-quotient-data-after-a-division-by-0.patch
- From: kernel-4.14.322-244.539.amzn2
- CVE-2022-3524
- Description:
tcp/udp: Fix memory leak in ipv6_renew_options()
- CVE: https://access.redhat.com/security/cve/CVE-2022-3524
- Patch: 4.14.0/CVE-2022-3524-tcp-udp-Fix-memory-leak-in-ipv6_renew_options.patch
- From: 4.14.301-224.520.amzn2
- CVE-2022-42896
- Description:
Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM
- CVE: https://access.redhat.com/security/cve/CVE-2022-42896
- Patch: 4.14.0/CVE-2022-42896-Bluetooth-L2CAP-Fix-accepting-connection-request-for-invalid-SPSM.patch
- From: 4.14.301-224.520.amzn2
- CVE-2022-42896
- Description:
Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-42896
- Patch: 4.14.0/CVE-2022-42896-Bluetooth-L2CAP-Fix-l2cap_global_chan_by_psm.patch
- From: 4.14.301-224.520.amzn2