- kernel-uek-5.4.17-2011.4.6.el7uek (oel7-uek6)
- 5.4.17-2136.350.3.2.el7uek
- 2026-01-20 14:32:00
- 2026-01-21 13:22:12
- K20260120_13
- CVE-2019-19054
- Description:
media: rc: prevent memory leak in cx23888_ir_probe
- CVE: https://access.redhat.com/security/cve/CVE-2019-19054
- Patch: 4.14.0/cve-2019-19054-media-rc-prevent-memory-leak.patch
- From: 4.14.35-1902.304.6
- CVE-2019-19462
- Description:
include/linux/relay.h: fix percpu annotation in struct rchan
- CVE: https://access.redhat.com/security/cve/CVE-2019-19462
- Patch: 5.4.0/CVE-2019-19462-kernel-relay.c-handle-alloc_percpu-returning-NULL-in-relay_open.patch
- From: kernel-5.4.0-42.46
- CVE-2020-10732
- Description:
fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info()
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-10732
- Patch: 4.19.0/CVE-2020-10732-fs-binfmt_elf.c-allocate-initialized-memory-in-fill_.patch
- From: 4.19.118-2+deb10u1
- CVE-2020-12888
- Description:
vfio: access to disabled MMIO space of some devices may lead to DoS scenario
- CVE: https://linux.oracle.com/cve/CVE-2020-12888.html
- Patch: 5.4.17/cve-2020-12888.patch
- From: 5.4.17-2011.5.0uek
- CVE-2020-12888
- Description:
vfio: access to disabled MMIO space of some devices may lead to DoS scenario
- CVE: https://linux.oracle.com/cve/CVE-2020-12888.html
- Patch: 5.4.17/cve-2020-12888-kpatch-1.patch
- From: 5.4.17-2011.5.0uek
- CVE-2020-16166
- Description:
random32: update the net random state on interrupt and activity
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-16166
- Patch: 5.4.17/CVE-2020-16166.patch
- From: 5.4.17-2011.6.2
- CVE-2020-24394
- Description:
nfsd: apply umask on fs without ACL support
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-24394
- Patch: 4.14.0/CVE-2020-24394-nfsd-apply-umask-on-fs-without-ACL-support.patch
- From: 4.14.35-2025.400.9
- CVE-2020-10751
- Description:
selinux: properly handle multiple messages in selinux_netlink_send()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-10751
- Patch: 5.4.17/CVE-2020-10751-selinux-properly-handle-multiple-messages-in-selinux_netlink_send.patch
- From: kernel-uek-5.4.17-2102.202.5.el7uek
- CVE-2020-12771
- Description:
bcache: fix potential deadlock problem in btree_gc_coalesce
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-12771
- Patch: 5.4.17/CVE-2020-12771-bcache-fix-potential-deadlock-problem-in-btree_gc_co.patch
- From: 5.4.17-2011.6.2
- CVE-2020-14331
- Description:
Fix for missing check in vgacon scrollback handling
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-14331
- Patch: 4.14.0/CVE-2020-14331.patch
- From: 4.14.35-2025.400.9
- CVE-2020-10781
- Description:
Revert "zram: convert remaining CLASS_ATTR() to CLASS_ATTR_RO()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-10781
- Patch: 4.14.0/CVE-2020-10781.patch
- From: 4.14.35-2025.400.9
- CVE-2020-10781
- Description:
Revert "zram: convert remaining CLASS_ATTR() to CLASS_ATTR_RO()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-10781
- Patch: 4.14.0/CVE-2020-10781-kpatch.patch
- From: 4.14.35-2025.400.9
- CVE-2020-25284
- Description:
rbd: require global CAP_SYS_ADMIN for mapping and unmapping
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-25284
- Patch: 4.19.0/cve-2020-25284-rbd-require-global-CAP_SYS_ADMIN.patch
- From: linux-4.19.146-1
- CVE-2020-14314
- Description:
ext4: fix potential negative array index in do_split()
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-14314
- Patch: 4.19.0/cve-2020-14314-ext4-fix-potential-negative-array-index.patch
- From: linux-4.19.146-1
- CVE-2020-14385
- Description:
xfs: fix boundary test in xfs_attr_shortform_verify
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-14385
- Patch: 4.19.0/cve-2020-14385-xfs-fix-boundary-test-in-xfs_attr_shortform_verify.patch
- From: linux-4.19.146-1
- CVE-2020-14386
- Description:
net/packet: fix overflow in tpacket_rcv
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-14386.html
- Patch: 4.15.0/CVE-2020-14386.patch
- From: 4.15.0-117.118
- CVE-2020-14356
- Description:
cgroup: fix cgroup_sk_alloc() for sk_clone_lock()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-14356
- Patch: 5.4.17/CVE-2020-14356-cgroup-fix-cgroup_sk_alloc-for-sk_clone_lock.patch
- From: kernel-5.4.0-42.46
- CVE-2020-14356
- Description:
cgroup: fix cgroup_sk_alloc() for sk_clone_lock()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-14356
- Patch: 5.4.0/CVE-2020-14356-cgroup-Fix-sock_cgroup_data-on-big-endian.patch
- From: kernel-5.4.0-42.46
- CVE-2020-25212
- Description:
nfs: Fix getxattr kernel panic and memory overflow
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-25212
- Patch: 5.4.0/CVE-2020-25212-nfs-Fix-getxattr-kernel-panic-and-memory-overflow.patch
- From: kernel-5.4.0-48.52
- CVE-2020-25285
- Description:
mm/hugetlb: fix a race between hugetlb sysctl handlers
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-25285
- Patch: 4.19.0/cve-2020-25285-hugetlb-fix-a-race-between-sysctl-handlers.patch
- From: linux-4.19.146-1
- CVE-2020-8694
- Description:
powercap: make attributes only readable by root
- CVE: https://access.redhat.com/security/cve/CVE-2020-8694
- Patch: 5.4.17/CVE-2020-8694-powercap-make-attributes-only-readable-by-root.patch
- From: kernel-uek-5.4.17-2036.100.6.1.el8uek
- CVE-2020-8694
- Description:
powercap: make attributes only readable by root (adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2020-8694
- Patch: 5.4.17/CVE-2020-8694-kpatch.patch
- From: kernel-uek-5.4.17-2036.100.6.1.el8uek
- CVE-2020-29369
- Description:
mm/mmap.c: close race between munmap() and expand_upwards()/downwards()
- CVE: https://ubuntu.com/security/CVE-2020-29369
- Patch: 5.4.0/881818-mm-mmap.c-close-race-between-munmap-and-expand_upw.patch
- From: kernel-5.4.0-43.47
- CVE-2020-12352 CVE-2020-25662
- Description:
[net] Bluetooth: A2MP: Fix not initializing all members
- CVE: https://access.redhat.com/security/cve/cve-2020-25662
- Patch: 4.18.0/CVE-2020-12352-Bluetooth-A2MP-Fix-not-initializing-all-members.patch
- From: 4.18.0-193.28.1.el8_2
- CVE-2020-25656
- Description:
vt: keyboard, simplify vt_kdgkbsent
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-25656
- Patch: 4.19.0/CVE-2020-25656-vt-keyboard-simplify-vt_kdgkbsent.patch
- From: 4.19.160-2~deb9u1
- CVE-2020-25656
- Description:
vt: keyboard, extend func_buf_lock to readers
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-25656
- Patch: 4.19.0/CVE-2020-25656-vt-keyboard-extend-func_buf_lock-to-readers.patch
- From: 4.19.160-2~deb9u1
- CVE-2020-25668
- Description:
tty: make FONTX ioctl use the tty pointer they were actually passed
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-25668
- Patch: 5.4.17/CVE-2020-25668-tty-make-FONTX-ioctl-use-the-tty-pointer-they-were-actually-passed.patch
- From: 5.4.17-2036.100.6.1.el8uek
- CVE-2020-25704
- Description:
perf/core: Fix a memory leak in perf_event_parse_addr_filter()
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-25704
- Patch: 4.19.0/CVE-2020-25704-perf-core-Fix-a-memory-leak-in-perf_event_parse_addr_filter.patch
- From: 4.19.160-2~deb9u1
- CVE-2020-28915
- Description:
fbcon: Fix global-out-of-bounds read in fbcon_get_font()
- CVE: https://ubuntu.com/security/CVE-2020-28915
- Patch: 5.4.0/CVE-2020-28915-fbcon-Fix-global-out-of-bounds-read-in-fbcon_get_fon.patch
- From: kernel-5.4.0-56.62
- CVE-2020-28915
- Description:
fbcon: Fix global-out-of-bounds read in fbcon_get_font()
- CVE: https://ubuntu.com/security/CVE-2020-28915
- Patch: 5.4.0/CVE-2020-28915-kpatch.patch
- From: kernel-5.4.0-56.62
- CVE-2020-28974
- Description:
vt: Disable KD_FONT_OP_COPY
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-28974
- Patch: 4.19.0/CVE-2020-28974-vt-Disable-KD_FONT_OP_COPY.patch
- From: 4.19.160-2~deb9u1
- CVE-2020-14351
- Description:
perf/core: Fix race in the perf_mmap_close() function
- CVE: https://access.redhat.com/security/cve/CVE-2020-14351
- Patch: 5.4.0/CVE-2020-14351-perf-core-Fix-race-in-the-perf_mmap_close-function.patch
- From: kernel-5.4.0-56.62
- CVE-2020-29569
- Description:
set ring->xenblkd to NULL explicitly
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-29569
- Patch: 5.4.0/cve-2020-29569-xen-set-to-NULL-ring-xenblkd.patch
- From: 5.4.17-2036.102.0.2uek
- CVE-2020-29568
- Description:
limit size of watch_events dom0 queue.
- CVE: https://linux.oracle.com/cve/CVE-2020-29568.html
- Patch: debian10/4.19.171-2/CVE-2020-29568-xsa349-kpatch.patch
- From: kernel-4.19.171-2
- CVE-2020-29568
- Description:
handle xenwatch_thread patching.
- CVE: https://linux.oracle.com/cve/CVE-2020-29568.html
- Patch: 5.4.17/CVE-2020-29568-xsa349-handle-xenwatch-thread-kpatch.patch
- From: kernel-4.19.171-2
- CVE-2020-25705
- Description:
icmp: randomize the global rate limiter
- CVE: https://www.saddns.net/
- Patch: 5.4.0/icmp-randomize-the-global-rate-limiter.patch
- From: 5.4.73
- CVE-2020-29660
- Description:
tty: Fix ->pgrp locking in tiocspgrp()
- CVE: https://linux.oracle.com/cve/CVE-2020-29660.html
- Patch: 4.14.0/CVE-2020-29660-tty-Fix-pgrplocking-in-tiocspgrp.patch
- From: 4.14.35-2025.405.0
- CVE-2020-29660
- Description:
tty: Fix ->session locking
- CVE: https://linux.oracle.com/cve/CVE-2020-29660.html
- Patch: 4.14.0/CVE-2020-29660-tty-fix-session-locking.patch
- From: 4.14.35-2025.405.0
- CVE-2020-36158
- Description:
mwifiex: Fix possible buffer overflows in mwifiex_cmd_802_11_ad_hoc_start
- CVE: https://linux.oracle.com/cve/CVE-2020-36158.html
- Patch: 4.14.0/cve-2020-36158-mwifiex-possible-buffer-overflow.patch
- From: 4.14.35-2025.405.0
- CVE-2021-20177
- Description:
KCARE-12751: Removed this patch as it causes issue with new tcp connections
- CVE:
- Patch: skipped/CVE-2021-20177.patch
- From:
- CVE-2021-26932
- Description:
Xen/x86: don't bail early from clear_foreign_p2m_mapping()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-26932
- Patch: 5.4.17/884230-Xen-x86-don-t-bail-early-from-clear_foreign_p2m_ma.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2021-26932
- Description:
Xen/x86: also check kernel mapping in set_foreign_p2m_mapping()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-26932
- Patch: 5.4.17/884231-Xen-x86-also-check-kernel-mapping-in-set_foreign_p.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2021-26932
- Description:
Xen/gntdev: correct dev_bus_addr handling in gntdev_map_grant_pages()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-26932
- Patch: 5.4.17/884232-Xen-gntdev-correct-dev_bus_addr-handling-in-gntdev.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2021-26932
- Description:
Xen/gntdev: correct error checking in gntdev_map_grant_pages()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-26932
- Patch: 5.4.17/884233-Xen-gntdev-correct-error-checking-in-gntdev_map_gr.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2021-26931
- Description:
xen-blkback: don't "handle" error by BUG()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-26931
- Patch: 5.4.17/884234-xen-blkback-don-t-handle-error-by-BUG.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2021-26931
- Description:
xen-netback: don't "handle" error by BUG()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-26931
- Patch: 5.4.17/884235-xen-netback-don-t-handle-error-by-BUG.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2021-26931
- Description:
xen-scsiback: don't "handle" error by BUG()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-26931
- Patch: 5.4.17/884236-xen-scsiback-don-t-handle-error-by-BUG.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2021-26930
- Description:
xen-blkback: fix error handling in xen_blkbk_map()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-26930
- Patch: 5.4.17/884237-xen-blkback-fix-error-handling-in-xen_blkbk_map.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2020-0431
- Description:
HID: hid-input: fix stylus battery reporting.
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-0431
- Patch: 4.15.0/CVE-2020-0431-HID-hid-input-fix-stylus-battery-reporting.patch
- From: kernel-4.15.0-91.88
- CVE-2020-16120
- Description:
ovl: pass correct flags for opening real directory
- CVE: https://ubuntu.com/security/CVE-2020-16120
- Patch: 4.15.0/CVE-2020-16120-ovl-pass-correct-flags-for-opening-real-directory.patch
- From:
- CVE-2020-16120
- Description:
ovl: switch to mounter creds in readdir
- CVE: https://access.redhat.com/security/cve/CVE-2020-16120
- Patch: 5.4.17/CVE-2020-16120-ovl-switch-to-mounter-creds-in-readdir.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2020-16120
- Description:
ovl: verify permissions in ovl_path_open()
- CVE: https://access.redhat.com/security/cve/CVE-2020-16120
- Patch: 5.4.17/CVE-2020-16120-ovl-verify-permissions-in-ovl_path_open.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2020-16120
- Description:
ovl: check permission to open real file
- CVE: https://access.redhat.com/security/cve/CVE-2020-16120
- Patch: 5.4.17/CVE-2020-16120-ovl-check-permission-to-open-real-file-2011.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2021-3348
- Description:
nbd: freeze the queue while we're adding connections
- CVE: https://access.redhat.com/security/cve/CVE-2021-3348
- Patch: 5.4.17/CVE-2021-3348-nbd-freeze-the-queue-while-we-re-adding-connections-2011.patch
- From: 5.4.17-2036.103.3.1.el8uek
- CVE-2021-3347
- Description:
futex: Ensure the correct return value from futex_lock_pi()
- CVE: https://access.redhat.com/security/cve/cve-2021-3347
- Patch: 5.4.0/futex/CVE-2021-3347-futex-Ensure-the-correct-return-value-from-futex_lock_pi.patch
- From: >kernel-5.4.0-65.73
- CVE-2021-3347
- Description:
futex: Simplify fixup_pi_state_owner()
- CVE: https://access.redhat.com/security/cve/cve-2021-3347
- Patch: 5.4.0/futex/CVE-2021-3347-futex-Simplify-fixup_pi_state_owner.patch
- From: >kernel-5.4.0-65.73
- CVE-2021-3347
- Description:
futex: Handle faults correctly for PI futexes
- CVE: https://access.redhat.com/security/cve/cve-2021-3347
- Patch: 5.4.0/futex/CVE-2021-3347-futex-Handle-faults-correctly-for-PI-futexes.patch
- From: >kernel-5.4.0-65.73
- CVE-2021-27363
- Description:
scsi: iscsi: Restrict sessions and handles to admin
- CVE: https://access.redhat.com/security/cve/CVE-2021-27363
- Patch: 4.14.0/CVE-2021-27363-iscsi-Restrict-sessions-and-handles-to-admin-capabilities.patch
- From: 4.1.12-124.48.6.el6uek
- CVE-2021-27364
- Description:
scsi: iscsi: Verify lengths on passthrough PDUs
- CVE: https://access.redhat.com/security/cve/CVE-2021-27364
- Patch: 4.14.0/CVE-2021-27364-scsi-Verify-lengths-on-passthrough-PDUs.patch
- From: 4.1.12-124.48.6.el6uek
- CVE-2021-27365
- Description:
scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE
- CVE: https://access.redhat.com/security/cve/CVE-2021-27365
- Patch: 4.14.0/CVE-2021-27365-iscsi-Ensure-sysfs-attributes-are-limited-to-PAGE_SIZE.patch
- From: 4.1.12-124.48.6.el6uek
- CVE-2021-27365
- Description:
sysfs: Add sysfs_emit and sysfs_emit_at to format sysfs output
- CVE: https://people.canonical.com/~ubuntu-security/cve/2021/CVE-2021-27365
- Patch: 5.4.0/CVE-2021-27365-sysfs-Add-sysfs_emit-and-sysfs_emit_at-to-format-sysfs-output-pve6.patch
- From: >kernel-5.4.0-66.74
- CVE-2020-25639
- Description:
drm/nouveau: bail out of nouveau_channel_new if channel init
- CVE: https://access.redhat.com/security/cve/CVE-2020-25639
- Patch: 5.4.17/CVE-2020-25639-drm-nouveau-bail-out-of-nouveau_channel_new-if-channel-init.patch
- From: 5.4.17-2102.200.13.el8uek
- CVE-2020-28588
- Description:
lib/syscall: fix syscall registers retrieval on 32-bit platforms
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-28588
- Patch: ubuntu-focal/5.4.0-66.74/0004-CVE-2020-28588-lib-syscall-fix-syscall-registers-retrieval-on-32-bi.patch
- From: 5.4.0-66.74
- CVE-2020-27170
- Description:
bpf: Prohibit alu ops for pointer types not defining ptr_limit
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-27170
- Patch: 5.4.0/CVE-2020-27170-bpf-Prohibit-alu-ops-for-pointer-types-not-defining-ptr_limit.patch
- From: >kernel-5.4.0-67.75
- CVE-2020-27171
- Description:
bpf: Fix off-by-one for area size in creating mask to left
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-27171
- Patch: 5.4.0/CVE-2020-27171-bpf-Fix-off-by-one-for-area-size-in-creating-mask-to-left.patch
- From: >kernel-5.4.0-67.75
- CVE-2020-27171 CVE-2020-27170
- Description:
bpf: Simplify alu_limit masking for pointer arithmetic
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-27171
- Patch: 5.4.0/CVE-2020-27170-CVE-2020-27171-bpf-Simplify-alu_limit-masking-for-pointer-arithmetic.patch
- From: >kernel-5.4.0-67.75
- CVE-2020-27171 CVE-2020-27170
- Description:
bpf: Simplify alu_limit masking for pointer arithmetic
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-27171
- Patch: 5.4.0/CVE-2020-27170-CVE-2020-27171-bpf-Add-sanity-check-for-upper-ptr_limit.patch
- From: >kernel-5.4.0-67.75
- CVE-2021-3444
- Description:
bpf: Fix 32 bit src register truncation on div/mod
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-3444
- Patch: 5.4.0/CVE-2021-3444-bpf-Fix-32-bit-src-register-truncation-on-div-mod.patch
- From: >kernel-5.4.0-67.75
- CVE-2021-3444
- Description:
bpf: Fix truncation handling for mod32 dst reg wrt zero
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-3444
- Patch: 5.4.0/CVE-2021-3444-bpf-Fix-truncation-handling-for-mod32-dst-reg-wrt-zero.patch
- From: >kernel-5.4.0-67.75
- CVE-2021-28038
- Description:
Xen/gnttab: handle p2m update errors on a per-slot basis
- CVE: https://nvd.nist.gov/vuln/detail//CVE-2021-28038
- Patch: 4.14.0/CVE-2021-28038-Xen-gnttab-handle-p2m-update-errors-on-a-per-slot-basis.patch
- From: 4.14.225-121.357.amzn1
- CVE-2021-28950
- Description:
fuse: fix bad inode
- CVE: https://access.redhat.com/security/cve/CVE-2021-28950
- Patch: 5.4.17/CVE-2021-28950-fuse-fix-bad-inode.patch
- From: 5.4.17-2102.201.3.el8uek
- CVE-2021-28950
- Description:
fuse: fix live lock in fuse_iget()
- CVE: https://access.redhat.com/security/cve/CVE-2021-28950
- Patch: 5.4.17/CVE-2021-28950-fuse-fix-live-lock-in-fuse_iget.patch
- From: 5.4.17-2102.201.3.el8uek
- CVE-2021-28971
- Description:
perf/x86/intel: Fix a crash caused by zero PEBS status
- CVE: https://access.redhat.com/security/cve/CVE-2021-28971
- Patch: 5.4.17/CVE-2021-28971-perf-x86-intel-Fix-a-crash-caused-by-zero-PEBS-status.patch
- From: 5.4.17-2102.201.3.el8uek
- CVE-2021-28964
- Description:
btrfs: fix race when cloning extent buffer during rewind of an old
- CVE: https://access.redhat.com/security/cve/CVE-2021-28964
- Patch: 4.14.0/CVE-2021-28964-btrfs-fix-race-when-cloning-extent-buffer-during-rewind-of-an-old.patch
- From: 4.14.231-173.360.amzn2
- CVE-2021-28688
- Description:
xen-blkback: don't leak persistent grants from xen_blkbk_map()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-28688
- Patch: 4.14.0/CVE-2021-28688-xen-blkback-don-t-leak-persistent-grants-from-xen_blkbk_map.patch
- From: 4.14.231-173.360.amzn2
- CVE-2021-29650
- Description:
netfilter: x_tables: Use correct memory barriers
- CVE: https://people.canonical.com/~ubuntu-security/cve/2021/CVE-2021-29650
- Patch: ubuntu-focal/5.4.0-73.82/CVE-2021-29650-netfilter-x_tables-Use-correct-memory-barriers.patch
- From: 5.4.0-73.82
- CVE-2021-29154
- Description:
bpf, x86: Validate computation of branch displacements for x86-64
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-29154
- Patch: 5.4.0/CVE-2021-29154-bpf-x86-Validate-computation-of-branch-displacements-for-x86-64.patch
- From: >kernel-5.4.0-70.78
- CVE-2021-31916
- Description:
dm ioctl: fix out of bounds array access when no devices
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-31916
- Patch: 4.14.0/CVE-2021-31916-dm-ioctl-fix-out-of-bounds-array-access-when-no-devices.patch
- From: >kernel-4.14.231-173.360.amzn2
- CVE-2021-23133
- Description:
sctp: delay auto_asconf init until binding the first addr
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-23133
- Patch: 5.4.17/CVE-2021-23133-sctp-delay-auto_asconf-init-until-binding-the-first-addr.patch
- From: >kernel-4.14.231-173.360.amzn2
- CVE-2020-28374
- Description:
scsi: target: Fix XCOPY NAA identifier lookup
- CVE: https://access.redhat.com/security/cve/cve-2020-28374
- Patch: 4.18.0/CVE-2020-28374-scsi-target-Fix-XCOPY-NAA-identifier-lookup.patch
- From: 4.18.0-240.22.1.el8_3
- CVE-2020-28374
- Description:
scsi: target: Fix XCOPY NAA identifier lookup (kpatch adaptation)
- CVE: https://access.redhat.com/security/cve/cve-2020-28374
- Patch: 4.18.0/CVE-2020-28374-scsi-target-Fix-XCOPY-NAA-identifier-lookup-kpatch-1.patch
- From: 4.18.0-240.22.1.el8_3
- CVE-2020-36310
- Description:
KVM: SVM: avoid infinite loop on NPF from bad address
- CVE: https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-36310
- Patch: 5.4.17/CVE-2020-36310-KVM-SVM-avoid-infinite-loop-on-NPF-from-bad-address.patch
- From: kernel-uek-5.4.17-2102.202.5.el7uek
- CVE-2021-22555
- Description:
netfilter: x_tables: fix compat match/target pad out-of-bound write
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-22555
- Patch: 4.4.0/CVE-2021-22555-netfilter-x_tables-fix-compat-match-target-pad-out-of-bound-write.patch
- From: kernel-4.4.0-213.245
- CVE-2020-25670
- Description:
nfc: fix refcount leak in llcp_sock_bind()
- CVE: https://access.redhat.com/security/cve/CVE-2020-25670
- Patch: ubuntu-focal/5.4.0-74.83/CVE-2020-25670-nfc-fix-refcount-leak-in-llcp_sock_bind.patch
- From: 5.4.0-74.83
- CVE-2020-25671
- Description:
nfc: fix refcount leak in llcp_sock_connect()
- CVE: https://access.redhat.com/security/cve/CVE-2020-25671
- Patch: ubuntu-focal/5.4.0-74.83/CVE-2020-25671-nfc-fix-refcount-leak-in-llcp_sock_connect.patch
- From: 5.4.0-74.83
- CVE-2020-25672
- Description:
nfc: fix memory leak in llcp_sock_connect()
- CVE: https://access.redhat.com/security/cve/CVE-2020-25672
- Patch: ubuntu-focal/5.4.0-74.83/CVE-2020-25672-nfc-fix-memory-leak-in-llcp_sock_connect.patch
- From: 5.4.0-74.83
- CVE-2021-29155
- Description:
bpf: Move off_reg into sanitize_ptr_alu
- CVE: https://ubuntu.com/security/CVE-2021-29155
- Patch: 5.8.0/CVE-2021-29155-bpf-Move-off_reg-into-sanitize_ptr_alu.patch
- From: kernel-5.8.0-59.66
- CVE-2021-29155
- Description:
bpf: Ensure off_reg has no mixed signed bounds for all types
- CVE: https://ubuntu.com/security/CVE-2021-29155
- Patch: 5.4.17/CVE-2021-29155-bpf-Ensure-off_reg-has-no-mixed-signed-bounds-for-all-types.patch
- From: kernel-5.8.0-59.66
- CVE-2021-29155
- Description:
bpf: Rework ptr_limit into alu_limit and add common error path
- CVE: https://ubuntu.com/security/CVE-2021-29155
- Patch: 5.8.0/CVE-2021-29155-bpf-Rework-ptr_limit-into-alu_limit-and-add-common-error-path.patch
- From: kernel-5.8.0-59.66
- CVE-2021-29155
- Description:
bpf: Improve verifier error messages for users
- CVE: https://ubuntu.com/security/CVE-2021-29155
- Patch: 5.4.0/CVE-2021-29155-bpf-Improve-verifier-error-messages-for-user.patch
- From: kernel-5.4.0-77.86
- CVE-2021-29155
- Description:
bpf: Refactor and streamline bounds check into helper
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-29155
- Patch: 5.4.0/CVE-2021-29155-bpf-Refactor-and-streamline-bounds-check-into-helper.patch
- From: kernel-5.4.0-77.86
- CVE-2021-29155
- Description:
bpf: Move sanitize_val_alu out of op switch
- CVE: https://ubuntu.com/security/CVE-2021-29155
- Patch: 5.4.0/CVE-2020-29155-bpf-Move-sanitize_val_alu-out-of-op-switch.patch
- From: kernel-5.4.0-77.86
- CVE-2021-29155
- Description:
bpf: Tighten speculative pointer arithmetic mask
- CVE: https://ubuntu.com/security/CVE-2021-29155
- Patch: 5.4.0/CVE-2021-29155-bpf-Tighten-speculative-pointer-arithmetic-mask.patch
- From: kernel-5.4.0-77.86
- CVE-2021-23133
- Description:
The patch is reverted in the upstream by 01bfe5e8e4 as introducing a deadlock
- CVE:
- Patch: skipped/CVE-2021-23133.patch
- From:
- CVE-2021-31829
- Description:
bpf: Fix masking negation logic upon negative dst register
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-31829
- Patch: 4.14.0/CVE-2021-31829-bpf-Fix-masking-negation-logic-upon-negative-dst-register.patch
- From: >kernel-4.14.231-173.360.amzn2
- CVE-2021-32399
- Description:
bluetooth: eliminate the potential race condition when removing the HCI controller
- CVE: https://ubuntu.com/security/CVE-2021-32399
- Patch: 5.4.0/CVE-2021-32399-bluetooth-eliminate-the-potential-race-condition-when-removing-the-HCI-controller.patch
- From: kernel-5.4.0-77.86
- CVE-2021-33034
- Description:
Bluetooth: verify AMP hci_chan before amp_destroy
- CVE: https://access.redhat.com/security/cve/CVE-2021-33034
- Patch: 4.18.0/CVE-2021-33034.patch
- From: 4.18.0-305.7.1.el8_4
- CVE-2021-33034
- Description:
Bluetooth: verify AMP hci_chan before amp_destroy (kcare adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2021-33034
- Patch: 4.18.0/CVE-2021-33034-kpatch.patch
- From: 4.18.0-305.7.1.el8_4
- CVE-2021-33033
- Description:
cipso,calipso: resolve a number of problems with the DOI refcounts
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-33033
- Patch: 4.14.0/CVE-2021-33033-cipso-calipso-resolve-a-number-of-problems-with-the-DOI-refcounts.patch
- From: >kernel-4.14.231-173.360.amzn2
- CVE-2021-33033
- Description:
net: mac802154: Fix general protection fault
- CVE: https://linux.oracle.com/cve/CVE-2021-33033.html
- Patch: oel8-uek6/5.4.17-2102.203.5.el8uek/CVE-2021-33033-net-mac802154-fix-general-protection-fault.patch
- From: 5.4.17-2102.203.5.el8uek
- CVE-2021-33909
- Description:
seq_file: Disallow extremely large seq buffer allocations
- CVE: https://ubuntu.com/security/CVE-2021-33909
- Patch: 5.0.0/CVE-2021-33909-seq_file-Disallow-extremely-large-seq-buffer-allocations.patch
- From: >kernel-5.3.0-75.71
- CVE-2020-14304
- Description:
net/mlx4: Fix EEPROM dump support
- CVE: https://access.redhat.com/security/cve/CVE-2020-14304
- Patch: 5.4.17/CVE-2020-14304-net-mlx4-Fix-EEPROM-dump-support.patch
- From: 5.4.17-2102.203.6.el8uek
- CVE-2021-23134
- Description:
net/nfc: fix use-after-free llcp_sock_bind/connect
- CVE: https://ubuntu.com/security/CVE-2021-23134
- Patch: 5.4.0/CVE-2021-23134-net-nfc-fix-use-after-free-llcp_sock_bind-connect.patch
- From: kernel-5.4.0-77.86
- CVE-2020-26147
- Description:
mac80211: assure all fragments are encrypted
- CVE: https://ubuntu.com/security/CVE-2020-26147
- Patch: 5.4.0/CVE-2020-26147-mac80211-assure-all-fragments-are-encrypted.patch
- From: kernel-5.4.0-77.86
- CVE-2020-26145
- Description:
ath10k: add CCMP PN replay protection for fragmented frames
- CVE: https://access.redhat.com/security/cve/CVE-2020-26145
- Patch: 5.4.17/CVE-2020-26145-ath10k-add-CCMP-PN-replay-protection-for-fragmented-frames.patch
- From: 5.4.17-2102.203.6.el8uek
- CVE-2020-26145
- Description:
ath10k: drop fragments with multicast DA for PCIe
- CVE: https://access.redhat.com/security/cve/CVE-2020-26145
- Patch: 5.4.17/CVE-2020-26145-ath10k-drop-fragments-with-multicast-DA-for-PCIe.patch
- From: 5.4.17-2102.203.6.el8uek
- CVE-2020-26145
- Description:
ath10k: drop fragments with multicast DA for SDIO
- CVE: https://access.redhat.com/security/cve/CVE-2020-26145
- Patch: 5.4.17/CVE-2020-26145-ath10k-drop-fragments-with-multicast-DA-for-SDIO.patch
- From: 5.4.17-2102.203.6.el8uek
- CVE-2020-26141
- Description:
ath10k: Fix TKIP Michael MIC verification for PCIe
- CVE: https://access.redhat.com/security/cve/CVE-2020-26141
- Patch: 5.4.17/CVE-2020-26141-ath10k-Fix-TKIP-Michael-MIC-verification-for-PCIe.patch
- From: 5.4.17-2102.203.6.el8uek
- CVE-2020-24588
- Description:
ath10k: drop MPDU which has discard flag set by firmware for SDIO
- CVE: https://ubuntu.com/security/CVE-2020-24588
- Patch: 5.8.0/CVE-2020-24588-ath10k-drop-MPDU-which-has-discard-flag-set-by-firmware-for-SDIO.patch
- From: kernel-5.8.0-59.66
- CVE-2020-24588
- Description:
mac80211: drop A-MSDUs on old ciphers
- CVE: https://ubuntu.com/security/CVE-2020-24588
- Patch: 5.4.17/CVE-2020-24588-mac80211-drop-A-MSDUs-on-old-ciphers.patch
- From: kernel-5.8.0-59.66
- CVE-2020-24588
- Description:
cfg80211: mitigate A-MSDU aggregation attacks
- CVE: https://ubuntu.com/security/CVE-2020-24588
- Patch: 5.8.0/CVE-2020-24588-cfg80211-mitigate-A-MSDU-aggregation-attacks.patch
- From: kernel-5.8.0-59.66
- CVE-2020-24588
- Description:
mac80211: properly handle A-MSDUs that start with an RFC 1042 header
- CVE: https://ubuntu.com/security/CVE-2020-24588
- Patch: 5.8.0/CVE-2020-24588-mac80211-properly-handle-A-MSDUs-that-start-with-an-RFC-1042-header.patch
- From: kernel-5.8.0-59.66
- CVE-2020-24587 CVE-2020-24586
- Description:
mac80211: prevent mixed key and fragment cache attacks
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-24587
- Patch: 5.8.0/CVE-2020-24587-mac80211-prevent-mixed-key-and-fragment-cache-attacks.patch
- From: 5.8.0-59.66
- CVE-2020-24587 CVE-2020-24586
- Description:
mac80211: prevent mixed key and fragment cache attacks (adaptation)
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-24587
- Patch: 5.8.0/CVE-2020-24587-mac80211-prevent-mixed-key-and-fragment-cache-attacks-kpatch.patch
- From: 5.8.0-59.66
- CVE-2020-24587 CVE-2020-24586
- Description:
mac80211: prevent attacks on TKIP/WEP as well
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-24587
- Patch: 5.8.0/CVE-2020-24587-mac80211-prevent-attacks-on-TKIP-WEP-as-well.patch
- From: 5.8.0-59.66
- CVE-2020-24587 CVE-2020-24586
- Description:
mac80211: extend protection against mixed key and fragment cache attacks
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-24587
- Patch: 5.8.0/CVE-2020-24587-mac80211-extend-protection-against-mixed-key-and-fragment-cache-attacks.patch
- From: 5.8.0-59.66
- CVE-2020-24586
- Description:
mac80211: add fragment cache to sta_info
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-24586
- Patch: 5.8.0/CVE-2020-24586-mac80211-add-fragment-cache-to-sta_info-kpatch.patch
- From: kernel-5.8.0-59.66
- CVE-2021-3564
- Description:
Bluetooth: fix the erroneous flush_work() order
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2021-3564
- Patch: 4.19.0/CVE-2021-3564-Bluetooth-fix-the-erroneous-flush_work-order.patch
- From: 4.14.191-1
- n/a
- Description:
KVM: nSVM: do not change host intercepts while nested VM is running (CVE-2021-3656 dependency)
- CVE: n/a
- Patch: 5.4.17/KVM_nSVM-do-not-change-host-intercepts-while-nested-VM-is-running.patch
- From: 5.4.17-2033
- CVE-2021-3656
- Description:
KVM: nSVM: always intercept VMLOAD/VMSAVE when nested
- CVE: https://access.redhat.com/security/cve/CVE-2021-3656
- Patch: 5.4.17/CVE-2021-3656-KVM_nSVM-always-intercept-VMLOAD_VMSAVE-when-nested.patch
- From: 5.4.17-2102.204.4.3
- CVE-2021-3653
- Description:
KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl
- CVE: https://access.redhat.com/security/cve/CVE-2021-3653
- Patch: 5.4.17/CVE-2021-3653-KVM_nSVM-avoid-picking-up-unsupported-bits-from-L2-in-int_ctl.patch
- From: 5.4.17-2102.204.4.3
- CVE-2021-3653
- Description:
KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (adaptation)
- CVE: https://people.canonical.com/~ubuntu-security/cve/2021/CVE-2021-3653
- Patch: ubuntu-bionic/4.15.0-156.163/CVE-2021-3653-kpatch.patch
- From: 4.15.0-156.163
- CVE-2020-36311
- Description:
KVM: SVM: Periodically schedule when unregistering regions on destroy
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-36311
- Patch: ubuntu-focal/5.4.0-84.94/CVE-2020-36311-KVM-SVM-Periodically-schedule-when-unregistering-regions-on-destroy.patch
- From: 5.4.0-84.94
- CVE-2021-22543
- Description:
KVM: do not allow mapping valid but non-reference-counted pages
- CVE: https://ubuntu.com/security/CVE-2021-22543
- Patch: 4.18.0/CVE-2021-22543-17896-KVM-do-not-allow-mapping-valid-but-non-reference-co.patch
- From: kernel-4.18.0-305.12.1.el8
- CVE-2021-3573
- Description:
Bluetooth: use correct lock to prevent UAF of hdev object
- CVE: https://people.canonical.com/~ubuntu-security/cve/2021/CVE-2021-3573
- Patch: ubuntu-focal/5.4.0-81.91/0001-CVE-2021-3573-Bluetooth-use-correct-lock-to-prevent-UAF-of-hdev-ob.patch
- From: 5.4.0-81.91
- CVE-2021-3609
- Description:
UBUNTU: SAUCE: can: bcm: delay release of struct bcm_op after synchronize_rcu
- CVE: https://ubuntu.com/security/CVE-2021-3609
- Patch: 5.8.0/CVE-2021-3609-UBUNTU-SAUCE-can-bcm-delay-release-of-struct-bcm_op-after-synchronize_rcu.patch
- From: kernel-5.8.0-59.66
- CVE-2021-3656
- Description:
Already included in ELSA-2021-9420
- CVE:
- Patch: skipped/CVE-2021-3656.patch
- From:
- CVE-2021-3739
- Description:
btrfs: fix NULL pointer dereference when deleting device by invalid id
- CVE: https://linux.oracle.com/cve/CVE-2021-3739.html
- Patch: 5.4.17/CVE-2021-3739-btrfs-fix-null-pointer-dereference-when-deleting-device-by-invalid.patch
- From: 5.4.17-2102.205.7.3
- CVE-2021-37159
- Description:
hso: fix bailout in error case of probe
- CVE: https://access.redhat.com/security/cve/CVE-2021-37159
- Patch: 5.4.17/CVE-2021-37159-hso-fix-bailout-in-error-case-of-probe.patch
- From: 5.4.17-2102.206.1.el8uek
- CVE-2021-37159
- Description:
usb: hso: fix error handling code of hso_create_net_device
- CVE: https://access.redhat.com/security/cve/CVE-2021-37159
- Patch: 5.4.17/CVE-2021-37159-usb-hso-fix-error-handling-code-of-hso_create_net_device.patch
- From: 5.4.17-2102.206.1.el8uek
- CVE-2021-38198
- Description:
KVM: X86: MMU: Use the correct inherited permissions to get shadow page
- CVE: https://access.redhat.com/security/cve/CVE-2021-38198
- Patch: 5.4.17/CVE-2021-38198-KVM-X86-MMU-Use-the-correct-inherited-permissions-to-get.patch
- From: 5.4.17-2102.206.1.el8uek
- CVE-2021-38198
- Description:
KVM: X86: MMU: Use the correct inherited permissions to get shadow page (adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2021-38198
- Patch: 5.4.17/CVE-2021-38198-KVM-X86-MMU-Use-the-correct-inherited-permissions-to-get-kpatch-2011.patch
- From: 5.4.17-2102.206.1.el8uek
- CVE-2021-3743
- Description:
net: qrtr: fix another OOB Read in qrtr_endpoint_post
- CVE: https://access.redhat.com/security/cve/CVE-2021-3743
- Patch: 5.4.17/CVE-2021-3743-net-qrtr-fix-another-OOB-Read-in-qrtr_endpoint_post.patch
- From: 5.4.17-2102.206.1.el8uek
- CVE-2021-40490
- Description:
ext4: fix race writing to an inline_data file while its xattrs are changing
- CVE: https://security-tracker.debian.org/tracker/CVE-2021-40490
- Patch: debian11/CVE-2021-40490-ext4-fix-race-writing-to-an-inline_data-file-while-i.patch
- From: 5.10.46-5
- CVE-2017-6074
- Description:
Patch already exists in 5.4.y kernels.
- CVE:
- Patch: skipped/CVE-2017-6074.patch
- From:
- CVE-2020-16119
- Description:
dccp: don't duplicate ccid when cloning dccp sock
- CVE: https://security-tracker.debian.org/tracker/CVE-2020-16119
- Patch: debian11/CVE-2020-16119-dccp-don-t-duplicate-ccid-when-cloning-dccp-sock.patch
- From: 5.10.46-5
- CVE-2021-3744
- Description:
crypto: ccp - fix resource leaks in ccp_run_aes_gcm_cmd()
- CVE: https://access.redhat.com/security/cve/CVE-2021-3744
- Patch: 5.4.17/CVE-2021-3744-crypto-ccp-fix-resource-leaks-in-ccp_run_aes_gcm_cmd.patch
- From: 5.4.17-2136.301.1.2
- CVE-2021-41864
- Description:
bpf: Fix integer overflow in prealloc_elems_and_freelist()
- CVE: https://linux.oracle.com/cve/CVE-2021-41864.html
- Patch: 5.4.17/CVE-2021-41864-bpf-fix-integer-overflow-in-prealloc-elems-and-freelist.patch
- From: 5.4.17-2136.302.6.1.el8uek
- CVE-2021-0920
- Description:
af_unix: fix garbage collect vs MSG_PEEK
- CVE: https://access.redhat.com/security/cve/CVE-2021-0920
- Patch: 5.4.17/CVE-2021-0920-af_unix-fix-garbage-collect-vs-MSG_PEEK.patch
- From: 5.4.17-2136.302.7.2
- CVE-2021-0920
- Description:
af_unix: fix garbage collect vs MSG_PEEK (adaptation)
- CVE: https://security-tracker.debian.org/tracker/CVE-2021-0920
- Patch: 5.4.17/CVE-2021-0920-kpatch-uek6.patch
- From: 5.4.17-2136.302.7.2
- CVE-2021-0920
- Description:
fget: check that the fd still exists after getting a ref to it
- CVE: https://access.redhat.com/security/cve/CVE-2021-0920
- Patch: 5.4.17/CVE-2021-0920-fget-check-that-the-fd-still-exists-after-getting-a-ref-to-it.patch
- From: 5.4.17-2136.302.7.2
- CVE-2021-4155
- Description:
xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like
- CVE: https://access.redhat.com/security/cve/CVE-2021-4155
- Patch: 5.4.17/CVE-2021-4155-xfs-map-unwritten-blocks-in-XFS_IOC_ALLOC-FREESP-just-like.patch
- From: 5.4.17-2136.302.7.2
- CVE-2022-0185
- Description:
vfs: fs_context: fix up param length parsing in legacy_parse_param
- CVE: https://access.redhat.com/security/cve/CVE-2022-0185
- Patch: 4.18.0/CVE-2022-0185-vfs-fs_context-fix-up-param-length-parsing-in-legacy_parse_param.patch
- From: 4.18.0-348.12.2.el8_5
- CVE-2022-0185
- Description:
UBUNTU: SAUCE: vfs: test that one given mount param is not larger than PAGE_SIZE
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-0185
- Patch: 5.4.0/CVE-2022-0185-UBUNTU-SAUCE-vfs-test-that-one-given-mount-param-is-not-larger-than-PAGE_SIZE.patch
- From: 5.4.0-96.109
- CVE-2022-0492
- Description:
cgroup-v1: Require capabilities to set release_agent
- CVE: https://access.redhat.com/security/cve/CVE-2022-0492
- Patch: 5.4.17/CVE-2022-0492-cgroup-v1-Require-capabilities-to-set-release_agent.patch
- From: 5.4.17-2136.302.7.2.3
- CVE-2021-3640
- Description:
Bluetooth: sco: Fix lock_sock() blockage by memcpy_from_msg()
- CVE: https://ubuntu.com/security/CVE-2021-3640
- Patch: 5.11.0/CVE-2021-3640-Bluetooth-sco-Fix-lock_sock-blockage-by-memcpy_from_msg.patch
- From: 5.11.0-1028.31~20.04.1
- CVE-2021-44733
- Description:
- CVE: https://access.redhat.com/security/cve/CVE-2021-44733
- Patch: 5.4.17/CVE-2021-44733-tee-handle-lookup-of-shm-with-reference-count.patch
- From: kernel-uek-5.4.17-2136.304.4.1
- CVE-2021-44733
- Description:
- CVE: https://access.redhat.com/security/cve/CVE-2021-44733
- Patch: 5.4.17/CVE-2021-44733-kpatch.patch
- From: kernel-uek-5.4.17-2136.304.4.1
- CVE-2022-25636
- Description:
netfilter: nf_tables_offload: incorrect flow offload action array size
- CVE: https://access.redhat.com/security/cve/CVE-2022-25636
- Patch: 4.18.0/CVE-2022-25636.patch
- From: >4.18.0-348.12.2.el8_5
- CVE-2022-0847
- Description:
lib/iov_iter: initialize "flags" in new pipe_buffer
- CVE: https://access.redhat.com/security/cve/CVE-2022-0847
- Patch: 4.18.0/CVE-2022-0847-lib-iov_iter-initialize-flags-in-new-pipe_buffer.patch
- From: >kernel-4.18.0-348.12.2.el8_5
- CVE-2021-3656 CVE-2021-3653
- Description:
KVM: x86: nSVM: don't copy virt_ext from vmcb12
- CVE: https://security-tracker.debian.org/tracker/CVE-2021-3656
- Patch: 5.4.17/CVE-2021-3656-KVM-x86-nSVM-dont-copy-virt_ext-from-vmcb12-1.patch
- From: 5.4.17-2136.305.4
- CVE-2022-0330
- Description:
drm/i915: Flush TLBs before releasing backing store
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-0330
- Patch: ubuntu-focal/5.4.0-100.113/0010-CVE-2022-0330-drm-i915-Flush-TLBs-before-releasing-backing-store.patch
- From: 5.4.0-100.113
- CVE-2022-0330
- Description:
drm/i915: Flush TLBs before releasing backing store (adaptation)
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-0330
- Patch: ubuntu-focal/5.4.0-100.113/CVE-2022-0330-kpatch.patch
- From: 5.4.0-100.113
- CVE-2021-39685
- Description:
USB: gadget: zero allocate endpoint 0 buffers
- CVE: https://security-tracker.debian.org/tracker/CVE-2021-39685
- Patch: 5.4.17/CVE-2021-39685-USB-gadget-zero-allocate-endpoint-0-buffers.patch
- From: 5.4.17-2136.305.1
- CVE-2021-39685
- Description:
USB: gadget: detect too-big endpoint 0 requests
- CVE: https://security-tracker.debian.org/tracker/CVE-2021-39685
- Patch: 5.4.17/CVE-2021-39685-USB-gadget-detect-too-big-endpoint-0-requests.patch
- From: 5.4.17-2136.305.1
- CVE-2021-39685
- Description:
USB: gadget: bRequestType is a bitfield, not a enum
- CVE: https://security-tracker.debian.org/tracker/CVE-2021-39685
- Patch: 5.4.17/CVE-2021-39685-USB-gadget-bRequestType-is-a-bitfield-not-a-enum.patch
- From: 5.4.17-2136.305.1
- CVE-2022-0435
- Description:
tipc: improve size validations for received domain records
- CVE: https://access.redhat.com/security/cve/CVE-2022-0435
- Patch: 4.18.0/CVE-2022-0435-tipc-improve-size-validations-for-received-domain-records-193.patch
- From: 4.18.0-348.20.1.el8_5
- CVE-2022-23960
- Description:
Out of scope as the patch is aarch64 related
- CVE:
- Patch: skipped/CVE-2022-23960.patch
- From:
- CVE-2021-26401
- Description:
An introduction of required changes through KernelCare could cause unavoidable problems to applications which use unprivileged eBPF.
- CVE:
- Patch: skipped/CVE-2021-26401.patch
- From:
- CVE-2022-22942
- Description:
UBUNTU: SAUCE: drm/vmwgfx: Fix stale file descriptors on failed usercopy
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-22942
- Patch: ubuntu-focal/5.4.0-100.113/CVE-2022-22942-UBUNTU-SAUCE-drm-vmwgfx-Fix-stale-file-descriptors-on-failed-usercopy.patch
- From: 5.4.0-100.113
- CVE-2022-24448
- Description:
NFSv4: Handle case where the lookup of a directory fails
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-24448
- Patch: 5.10.0/CVE-2022-24448-NFSv4-Handle-case-where-the-lookup-of-a-directory-fails.patch
- From: 5.10.92-2
- CVE-2022-0617
- Description:
udf: Fix NULL ptr deref when converting from inline format
- CVE: https://access.redhat.com/security/cve/CVE-2022-0617
- Patch: 4.14.0/CVE-2022-0617-udf-Fix-NULL-ptr-deref-when-converting-from-inline-format.patch
- From: 4.14.268-205.500.amzn2
- CVE-2022-0617
- Description:
udf: Restore i_lenAlloc when inode expansion fails
- CVE: https://access.redhat.com/security/cve/CVE-2022-0617
- Patch: 4.14.0/CVE-2022-0617-udf-Restore-i_lenAlloc-when-inode-expansion-fails.patch
- From: 4.14.268-205.500.amzn2
- CVE-2020-36516
- Description:
ipv4: avoid using shared IP generator for connected sockets
- CVE: https://access.redhat.com/security/cve/CVE-2020-36516
- Patch: 5.4.17/CVE-2020-36516-ipv4-avoid-using-shared-IP-generator-for-connected-sockets.patch
- From: 5.4.17-2136.306.1.3
- CVE-2020-36516
- Description:
ipv4: tcp: send zero IPID in SYNACK messages
- CVE: https://access.redhat.com/security/cve/CVE-2020-36516
- Patch: 5.4.17/CVE-2020-36516-ipv4-tcp-send-zero-IPID-in-SYNACK-messages.patch
- From: 5.4.17-2136.306.1.3
- CVE-2022-26966
- Description:
sr9700: sanity check for packet length
- CVE: https://access.redhat.com/security/cve/CVE-2022-26966
- Patch: 5.4.17/CVE-2022-26966-sr9700-sanity-check-for-packet-length.patch
- From: 5.4.17-2136.306.1.3
- CVE-2021-26341
- Description:
An introduction of required changes through KernelCare could cause unavoidable problems to applications which use unprivileged eBPF.
- CVE:
- Patch: skipped/CVE-2021-26341.patch
- From:
- CVE-2022-1016
- Description:
netfilter: nf_tables: initialize registers in nft_do_chain()
- CVE: https://access.redhat.com/security/cve/CVE-2022-1016
- Patch: 5.4.17/CVE-2022-1016-netfilter-nf_tables-initialize-registers-in-nft_do_chain.patch
- From: 5.4.17-2136.306.1.3
- CVE-2022-1158
- Description:
KVM: x86/mmu: do compare-and-exchange of gPTE via the user
- CVE: https://access.redhat.com/security/cve/CVE-2022-1158
- Patch: 5.4.17/CVE-2022-1158-KVM-x86-mmu-do-compare-and-exchange-of-gPTE-via-the-user-2011.patch
- From: 5.4.17-2136.306.1.3
- CVE-2021-45095
- Description:
phonet: refcount leak in pep_sock_accep
- CVE: https://access.redhat.com/security/cve/CVE-2021-45095
- Patch: 5.10.0/CVE-2021-45095-phonet-refcount-leak-in-pep_sock_accep.patch
- From: kernel-5.10.92-1
- CVE-2022-1055
- Description:
net: sched: fix use-after-free in tc_new_tfilter()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-1055
- Patch: ubuntu-focal/5.4.0-107.121/0001-CVE-2022-1055-net-sched-fix-use-after-free-in-tc_new_tfilter.patch
- From: 5.4.0-107.121
- CVE-2022-27666
- Description:
esp: Fix possible buffer overflow in ESP transformation
- CVE: https://nvd.nist.gov/vuln/detail//CVE-2022-27666
- Patch: 5.4.17/CVE-2022-27666-esp-Fix-possible-buffer-overflow-in-ESP-transformation.patch
- From: 5.4.17-2136.307.3.1.el8uek
- CVE-2022-21499
- Description:
Not affected without certain conditions - Secure Boot, configured kgdb/kdb. Complex adaptation
- CVE:
- Patch: skipped/CVE-2022-21499.patch
- From:
- CVE-2022-1353
- Description:
af_key: add __GFP_ZERO flag for compose_sadb_supported in function pfkey_register
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-1353
- Patch: 5.10.0/CVE-2022-1353-af_key-add-__GFP_ZERO-flag-for-compose_sadb_supported-in-function-pfkey_register.patch
- From: 5.10.113-1
- CVE-2022-1048
- Description:
ALSA: pcm: Fix races among concurrent hw_params and hw_free calls
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-1048
- Patch: 5.4.17/CVE-2022-1048-ALSA-pcm-Fix-races-among-concurrent-hw_params-and-hw_free-calls.patch
- From: 5.4.17-2136.308.7
- CVE-2022-1048
- Description:
ALSA: pcm: Fix races among concurrent read/write and buffer changes
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-1048
- Patch: 5.4.17/CVE-2022-1048-ALSA-pcm-Fix-races-among-concurrent-read-write-and-buffer-changes.patch
- From: 5.10.113-1
- CVE-2022-1048
- Description:
ALSA: pcm: Fix races among concurrent prepare and hw_params/hw_free calls
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-1048
- Patch: 5.4.17/CVE-2022-1048-ALSA-pcm-Fix-races-among-concurrent-prepare-and-hw_params-hw_free-calls.patch
- From: 5.4.17-2136.308.7
- CVE-2022-1048
- Description:
ALSA: pcm: Fix races among concurrent prealloc proc writes
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-1048
- Patch: 5.4.17/CVE-2022-1048-ALSA-pcm-Fix-races-among-concurrent-prealloc-proc-writes.patch
- From: 5.4.17-2136.308.7
- CVE-2022-1048
- Description:
ALSA: pcm: Fix races among concurrent hw_params and hw_free calls (adaptation)
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-1048
- Patch: 5.4.17/CVE-2022-1048-kpatch.patch
- From: 5.4.17-2136.308.7
- CVE-2022-23040
- Description:
xen/xenbus: Fix granting of vmalloc'd memory
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23040
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23040-xen-xenbus-Fix-granting-of-vmallocd-memory.patch
- From: 4.15.0-177.186
- CVE-2022-23040
- Description:
xen/xenbus: don't let xenbus_grant_ring() remove grants in error case
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23040
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23040-xen-xenbus-dont-let-xenbus_grant_ring-remove-grants-in-error-case.patch
- From: 4.15.0-177.186
- CVE-2022-23036 CVE-2022-23038
- Description:
xen/grant-table: add gnttab_try_end_foreign_access()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23036
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23036-CVE-2022-23038-xen-grant-table-add-gnttab_try_end_foreign_access.patch
- From: 4.15.0-177.186
- CVE-2022-23037
- Description:
xen/netfront: don't use gnttab_query_foreign_access() for mapped status
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23037
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23037-xen-netfront-dont-use-gnttab_query_foreign_access-for-mapped-status-167.patch
- From: 4.15.0-177.186
- CVE-2022-23038
- Description:
xen/scsifront: don't use gnttab_query_foreign_access() for mapped status
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23038
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23038-xen-scsifront-dont-use-gnttab_query_foreign_access-for-mapped-status.patch
- From: 4.15.0-177.186
- CVE-2022-23039
- Description:
xen/gntalloc: don't use gnttab_query_foreign_access()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23039
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23039-xen-gntalloc-dont-use-gnttab_query_foreign_access.patch
- From: 4.15.0-177.186
- CVE-2022-23041
- Description:
xen: remove gnttab_query_foreign_access()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23041
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23041-xen-remove-gnttab_query_foreign_access.patch
- From: 4.15.0-177.186
- CVE-2022-23041
- Description:
xen/9p: use alloc/free_pages_exact()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23041
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23041-xen-9p-use-alloc-free_pages_exact.patch
- From: 4.15.0-177.186
- CVE-2022-23041
- Description:
xen/gnttab: fix gnttab_end_foreign_access() without page specified
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23041
- Patch: 5.4.17/CVE-2022-23041-xen-gnttab-fix-gnttab_end_foreign_access-without-page-specified.patch
- From: 5.4.17-2136.308.7
- CVE-2022-23042
- Description:
xen/netfront: react properly to failing gnttab_end_foreign_access_ref()
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23042
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23042-xen-netfront-react-properly-to-failing-gnttab_end_foreign_access_ref-167.patch
- From: 4.15.0-177.186
- CVE-2022-23041
- Description:
xen/gnttab: fix gnttab_end_foreign_access() without page specified (adaptation)
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23041
- Patch: 5.4.17/CVE-2022-23041-kpatch.patch
- From: 4.15.0-177.186
- CVE-2022-23042
- Description:
xen/netfront: react properly to failing gnttab_end_foreign_access_ref() (adaptation)
- CVE: https://people.canonical.com/~ubuntu-security/cve/2022/CVE-2022-23042
- Patch: ubuntu-bionic/4.15.0-177.186/CVE-2022-23042-kpatch.patch
- From: 4.15.0-177.186
- CVE-2021-4197
- Description:
cgroup: Use open-time credentials for process migraton perm checks
- CVE: https://access.redhat.com/security/cve/cve-2021-4197
- Patch: 5.4.17/CVE-2021-4197-cgroup-Use-open-time-credentials-for-process-migraton-perm-checks.patch
- From: 5.4.17-2136.308.7
- CVE-2022-21123 CVE-2022-21125 CVE-2022-21166 CVE-2022-21127
- Description:
x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data
- CVE: https://access.redhat.com/security/cve/cve-2022-21127
- Patch: mmio-enable.patch
- From: 5.18
- CVE-2022-21505
- Description:
Kernel lockdown bypass when UEFI secure boot is disabled / unavailable and IMA appraisal is enabled.
- CVE: https://linux.oracle.com/cve/CVE-2022-21505.html
- Patch: 5.4.17/CVE-2022-21505.patch
- From: 5.4.17-2136.309.5
- CVE-2022-2588
- Description:
net_sched: cls_route: remove from list when handle is 0
- CVE: https://access.redhat.com/security/cve/CVE-2022-2588
- Patch: 5.4.17/CVE-2022-2588.patch
- From: kernel-uek-5.4.17-2136.309.5.1.el8uek
- CVE-2022-2153
- Description:
KVM: Add infrastructure and macro to mark VM as bugged
- CVE: https://linux.oracle.com/cve//CVE-2022-2153.html
- Patch: 5.4.17/CVE-2022-2153-KVM-Add-infrastructure-and-macro-to-mark-VM-as-bugged-200.patch
- From: 5.4.17-2136.310.7
- CVE-2022-2153
- Description:
KVM: Add infrastructure and macro to mark VM as bugged (adaptation)
- CVE: https://linux.oracle.com/cve//CVE-2022-2153.html
- Patch: 5.4.17/CVE-2022-2153-KVM-Add-infrastructure-and-macro-to-mark-VM-as-bugged-kpatch-206.patch
- From: 5.4.17-2136.310.7
- CVE-2022-2153
- Description:
KVM: Add infrastructure and macro to mark VM as bugged
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-2153
- Patch: 5.4.17/CVE-2022-2153-KVM-x86-Forbid-VMM-to-set-SYNIC-STIMER-MSRs-when-SynIC-wasnt-activated.patch
- From: 5.4.17-2136.310.7
- CVE-2022-2153
- Description:
KVM: x86: Check lapic_in_kernel() before attempting to set a SynIC irq
- CVE: https://ubuntu.com/security/CVE-2022-2153
- Patch: 5.15.0/CVE-2022-2153-KVM-x86-Check-lapic_in_kernel-before-attempting-to-set-a-SynIC-irq.patch
- From: 5.15.35-36
- CVE-2022-2153
- Description:
KVM: x86: Avoid theoretical NULL pointer dereference in kvm_irq_delivery_to_apic_fast()
- CVE: https://ubuntu.com/security/CVE-2022-2153
- Patch: 5.15.0/CVE-2022-2153-KVM-x86-Avoid-theoretical-NULL-pointer-dereference-in-kvm_irq_delivery_to_apic_fast.patch
- From: 5.15.35-36
- CVE-2022-23816
- Description:
Livepatching Retbleed may decrease kernel stability and performance. This vulnerability has medium security impact and applies to certain hardware environments only.
- CVE:
- Patch: skipped/CVE-2022-23816.patch
- From:
- CVE-2022-23825
- Description:
Livepatching Retbleed may decrease kernel stability and performance. This vulnerability has medium security impact and applies to certain hardware environments only.
- CVE:
- Patch: skipped/CVE-2022-23825.patch
- From:
- CVE-2022-29900
- Description:
Livepatching Retbleed may decrease kernel stability and performance. This vulnerability has medium security impact and applies to certain hardware environments only.
- CVE:
- Patch: skipped/CVE-2022-29900.patch
- From:
- CVE-2021-3669
- Description:
ipc: replace costly bailout check in sysvipc_find_ipc()
- CVE: https://linux.oracle.com/cve/CVE-2021-3669.html
- Patch: 5.4.17/CVE-2021-3669-ipc-replace-costly-bailout-check-in-sysvipc_find_ipc-2.patch
- From: 5.4.17-2136.311.6.el8uek
- n/a
- Description:
drm/lease: fix WARNING in idr_destroy
- CVE: n/a
- Patch: 5.4.17/drm-lease-fix-WARNING-in-idr_destroy.patch
- From: n/a
- CVE-2022-1280
- Description:
drm: add a locked version of drm_is_current_master
- CVE: https://linux.oracle.com/cve/CVE-2022-1280.html
- Patch: 5.4.17/CVE-2022-1280-0001-drm-add-a-locked-version-of-drm_is_current_master.patch
- From: 5.4.17-2136.311.6.el8uek
- CVE-2022-1280
- Description:
drm: add a locked version of drm_is_current_master
- CVE: https://linux.oracle.com/cve/CVE-2022-1280.html
- Patch: 5.4.17/CVE-2022-1280-0002-drm-serialize-drm_file.master-with-a-new-spinlock.patch
- From: 5.4.17-2136.311.6.el8uek
- CVE-2022-1280
- Description:
drm: add a locked version of drm_is_current_master
- CVE: https://linux.oracle.com/cve/CVE-2022-1280.html
- Patch: 5.4.17/CVE-2022-1280-0003-drm-protect-drm_master-pointers-in-drm_lease.c.patch
- From: 5.4.17-2136.311.6.el8uek
- CVE-2022-1280
- Description:
drm: add a locked version of drm_is_current_master (adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2022-1280
- Patch: 5.4.17/CVE-2022-1280-kpatch.patch
- From: 5.4.17-2136.311.6.el8uek
- CVE-2022-2586
- Description:
netfilter: nf_tables: do not allow SET_ID to refer to another
- CVE: https://linux.oracle.com/cve/CVE-2022-2586.html
- Patch: 5.4.17/CVE-2022-2586-0001-netfilter-nf_tables-do-not-allow-SET_ID-to-refer-to.patch
- From: 5.4.17-2136.311.6.el8uek
- CVE-2022-2586
- Description:
netfilter: nf_tables: do not allow SET_ID to refer to another
- CVE: https://linux.oracle.com/cve/CVE-2022-2586.html
- Patch: 5.4.17/CVE-2022-2586-0002-netfilter-nf_tables-do-not-allow-RULE_ID-to-refer-to.patch
- From: 5.4.17-2136.311.6.el8uek
- CVE-2022-21546 (dependency)
- Description:
scsi: target: Fix protect handling in WRITE SAME(32)
- CVE: n/a
- Patch: 5.4.17/CVE-2022-21546-scsi-target-Fix-protect-handling-in-WRITE_SAME.patch
- From: 5.4.17-2102.205.3
- CVE-2022-21546
- Description:
scsi: target: Fix WRITE_SAME No Data Buffer crash
- CVE: n/a
- Patch: 4.14.35/CVE-2022-21546-scsi-target-Fix-WRITE_SAME-No-Data-Buffer-crash.patch
- From: kernel-uek-4.14.35-2047.517.3.el7uek
- CVE-2022-21499
- Description:
lockdown: also lock down previous kgdb use
- CVE: https://linux.oracle.com/cve/CVE-2022-21499.html
- Patch: 5.4.17/CVE-2022-21499-lockdown-also-lock-down-previous-kgdb-use.patch
- From: 5.4.17-2136.312.3.4.el8uek
- CVE-2022-3028
- Description:
af_key: Do not call xfrm_probe_algs in parallel
- CVE: https://security-tracker.debian.org/tracker/CVE-2022-3028
- Patch: 5.10.0/CVE-2022-3028-af_key-Do-not-call-xfrm_probe_algs-in-parallel.patch
- From: 5.10.140-1
- CVE-2022-3565
- Description:
mISDN: fix use-after-free bugs in l1oip timer handlers
- CVE: https://ubuntu.com/security/CVE-2022-3565
- Patch: ubuntu-focal/5.4.0-135.152/0001-mISDN-fix-use-after-free-bugs-in-l1oip-timer-handler.patch
- From: 5.4.0-135.152
- CVE-2022-3565
- Description:
mISDN: fix use-after-free bugs in l1oip timer handlers (adaptation)
- CVE: https://ubuntu.com/security/CVE-2022-3565
- Patch: 5.4.17/CVE-2022-3565-kpatch.patch
- From: 5.4.17-2136.314.6.2
- CVE-2022-2602
- Description:
io_uring/af_unix: defer registered files gc to io_uring release
- CVE: https://access.redhat.com/security/cve/CVE-2022-2602
- Patch: 5.4.17/CVE-2022-2602-0001-io_uring-af_unix-defer-registered-files-gc-to-io_uri.patch
- From: 5.4.17-2136.314.6.2
- CVE-2022-2602
- Description:
io_uring/af_unix: defer registered files gc to io_uring release (adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2022-2602
- Patch: 5.4.17/CVE-2022-2602-kpatch.patch
- From: 5.4.17-2136.314.6.2
- CVE-2022-4378
- Description:
proc: avoid integer type confusion in get_proc_long
- CVE: https://access.redhat.com/security/cve/CVE-2022-4378
- Patch: 5.4.17/CVE-2022-4378-0001-proc-avoid-integer-type-confusion-in-get_proc_long.patch
- From: 5.4.17-2136.314.6.2
- CVE-2022-4378
- Description:
proc: proc_skip_spaces() shouldn't think it is working on C strings
- CVE: https://access.redhat.com/security/cve/CVE-2022-4378
- Patch: 5.4.17/CVE-2022-4378-0002-proc-proc_skip_spaces-shouldn-t-think-it-is-working-.patch
- From: 5.4.17-2136.314.6.2
- CVE-2022-42895
- Description:
Bluetooth: L2CAP: Fix attempting to access uninitialized memory
- CVE: https://linux.oracle.com/cve//CVE-2022-4378.html
- Patch: 5.4.17/CVE-2022-42895-Bluetooth-L2CAP-Fix-attempting-to-access-uninitialized-memory.patch
- From: 5.4.17-2136.315.5
- CVE-2022-4139
- Description:
drm/i915/gt: Serialize TLB invalidates with GT resets
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-4139
- Patch: 5.4.17/CVE-2022-4139-1-lt-2136.312.3.patch
- From: 5.4.17-2136.312.3
- CVE-2022-4139
- Description:
drm/i915: fix TLB invalidation for Gen12 video and compute engines
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-4139
- Patch: 5.4.17/CVE-2022-4139-2.patch
- From: 5.4.17-2136.316.7
- CVE-2022-42896
- Description:
Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-42896
- Patch: 5.4.17/CVE-2022-42896.patch
- From: 5.4.17-2136.316.7
- CVE-2022-41218
- Description:
media: dvb-core: Fix UAF due to refcount races at releasing
- CVE: https://linux.oracle.com/cve/CVE-2022-41218.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2022-41218-media-dvb-core-Fix-UAF-due-to-refcount-races-at-releasing.patch
- From: 5.4.17-2136.317.5.3.el8uek
- CVE-2022-2873
- Description:
i2c: ismt: Fix an out-of-bounds bug in ismt_access()
- CVE: https://linux.oracle.com/cve/CVE-2022-2873.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2022-2873-i2c-ismt-Fix-an-out-of-bounds-bug-in-ismt_access.patch
- From: 5.4.17-2136.317.5.3
- CVE-2022-45934
- Description:
Bluetooth: L2CAP: Fix u8 overflow
- CVE: https://linux.oracle.com/cve/CVE-2022-45934.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2022-45934-Bluetooth-L2CAP-Fix-u8-overflow.patch
- From: 5.4.17-2136.317.5.3
- CVE-2023-23455
- Description:
net: sched: atm: dont intepret cls results when asked to drop
- CVE: https://linux.oracle.com/cve/CVE-2023-23455.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2023-23455-net-sched-atm-dont-intepret-cls-results-when-asked-to-drop.patch
- From: 5.4.17-2136.317.5.3
- CVE-2023-23454
- Description:
net: sched: cbq: dont intepret cls results when asked to drop
- CVE: https://linux.oracle.com/cve/CVE-2023-23454.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2023-23454-net-sched-cbq-dont-intepret-cls-results-when-asked-to-drop.patch
- From: 5.4.17-2136.317.5.3
- CVE-2023-0394
- Description:
ipv6: raw: Deduct extension header length in rawv6_push_pending_frames
- CVE: https://linux.oracle.com/cve/CVE-2023-0394.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2023-0394-ipv6-raw-Deduct-extension-header-length-in-rawv6_push_pending_frames.patch
- From: 5.4.17-2136.317.5.3
- CVE-2022-47929
- Description:
net: sched: disallow noqueue for qdisc classes
- CVE: https://linux.oracle.com/cve/CVE-2022-47929.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2022-47929-net-sched-disallow-noqueue-for-qdisc-classes.patch
- From: 5.4.17-2136.317.5.3
- CVE-2022-45919 CVE-2022-45887 CVE-2022-45886 CVE-2022-45885 CVE-2022-45884
- Description:
media: dvbdev: adopts refcnt to avoid UAF
- CVE: https://linux.oracle.com/cve/CVE-2022-45919.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2022-45919-media-dvbdev-adopts-refcnt-to-avoid-UAF.patch
- From: 5.4.17-2136.317.5.3
- CVE-2022-45919 CVE-2022-45887 CVE-2022-45886 CVE-2022-45885 CVE-2022-45884
- Description:
media: dvbdev: fix refcnt bug
- CVE: https://linux.oracle.com/cve/CVE-2022-45919.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2022-45919-media-dvbdev-fix-refcnt-bug.patch
- From: 5.4.17-2136.317.5.3
- CVE-2022-45919 CVE-2022-45887 CVE-2022-45886 CVE-2022-45885 CVE-2022-45884
- Description:
media: dvbdev: adopts refcnt to avoid UAF (adaptation)
- CVE: https://linux.oracle.com/cve/CVE-2022-45919.html
- Patch: oel8-uek6/5.4.17-2136.317.5.3.el8uek/CVE-2022-45919-kpatch.patch
- From: 5.4.17-2136.317.5.3
- CVE-2022-3108
- Description:
drm/amdkfd: Check for null pointer after calling kmemdup
- CVE: https://linux.oracle.com/cve/CVE-2022-3108.html
- Patch: oel8-uek6/5.4.17-2136.318.7.1.el8uek/CVE-2022-3108-patch-drm-amdkfd-check-for-null-pointer-after-calling-kmemdup.patch
- From: 5.4.17-2136.318.7.1.el8uek
- CVE-2022-2196
- Description:
KVM: VMX: Execute IBPB on emulated VM-exit when guest has IBRS
- CVE: https://linux.oracle.com/cve/CVE-2022-2196.html
- Patch: oel8-uek6/5.4.17-2136.318.7.1.el8uek/CVE-2022-2196-patch-kvm-vmx-execute-ibpb-on-emulated-vm-exit-when-guest-has.patch
- From: 5.4.17-2136.318.7.1.el8uek
- CVE-2022-4129
- Description:
net: fix a concurrency bug in l2tp_tunnel_register()
- CVE: https://access.redhat.com/security/cve/CVE-2022-4129
- Patch: oel8-uek6/5.4.17-2136.318.7.1.el8uek/CVE-2022-4129-net-fix-a-concurrency-bug-in-l2tp_tunnel_register.patch
- From: 5.4.17-2136.318.7.1
- CVE-2022-4129
- Description:
l2tp: Serialize access to sk_user_data with sk_callback_lock
- CVE: https://access.redhat.com/security/cve/CVE-2022-4129
- Patch: oel8-uek6/5.4.17-2136.318.7.1.el8uek/CVE-2022-4129-l2tp-Serialize-access-to-sk_user_data-with-sk_callback_lock.patch
- From: 5.4.17-2136.318.7.1
- CVE-2022-4129
- Description:
l2tp: Don't sleep and disable BH under writer-side sk_callback_lock
- CVE: https://access.redhat.com/security/cve/CVE-2022-4129
- Patch: oel8-uek6/5.4.17-2136.318.7.1.el8uek/CVE-2022-4129-l2tp-Don-t-sleep-and-disable-BH-under-writer-side-sk_callback_lock.patch
- From: 5.4.17-2136.318.7.1
- CVE-2023-23559
- Description:
wifi: rndis_wlan: Prevent buffer overflow in rndis_query_oid
- CVE: https://access.redhat.com/security/cve/CVE-2023-23559
- Patch: oel8-uek6/5.4.17-2136.318.7.1.el8uek/CVE-2023-23559-wifi-rndis_wlan-Prevent-buffer-overflow-in-rndis_query_oid.patch
- From: 5.4.17-2136.318.7.1
- CVE-2022-27672
- Description:
x86/speculation: Identify processors vulnerable to SMT RSB predictions
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2022-27672.html
- Patch: smt_rsb-enable.patch
- From: N/A
- CVE-2022-27672
- Description:
KVM: x86: Mitigate the cross-thread return address predictions bug
- CVE: https://access.redhat.com/security/cve/CVE-2022-27672
- Patch: oel8-uek6/5.4.17-2136.318.7.1.el8uek/CVE-2022-27672-KVM-x86-Mitigate-the-cross-thread-return-address-predictions-bug-pre309.patch
- From: kernel-uek-5.4.17-2136.318.7.1.el8uek
- CVE-2022-27672
- Description:
KVM: x86: Mitigate the cross-thread return address predictions bug (adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2022-27672
- Patch: oel8-uek6/5.4.17-2136.318.7.1.el8uek/CVE-2022-27672-KVM-x86-Mitigate-the-cross-thread-return-address-predictions-bug-pre309-kpatch.patch
- From: kernel-uek-5.4.17-2136.318.7.1.el8uek
- CVE-2023-32233
- Description:
netfilter: nf_tables: deactivate anonymous set from preparation phase
- CVE: https://linux.oracle.com/cve/CVE-2023-32233.html
- Patch: oel8-uek6/5.4.17-2136.320.7.el8uek/CVE-2023-32233-netfilter-nf_tables-deactivate-anonymous-set-from-pr.patch
- From: 5.4.17-2136.320.7
- CVE-2023-30456
- Description:
KVM: nVMX: add missing consistency checks for CR0 and CR4
- CVE: https://linux.oracle.com/cve/CVE-2023-30456.html
- Patch: oel8-uek6/5.4.17-2136.320.7.el8uek/CVE-2023-30456-KVM-nVMX-add-missing-consistency-checks-for-CR0-and-CR4-2102.patch
- From: 5.4.17-2136.320.7
- CVE-2022-34918
- Description:
netfilter: nf_tables: stricter validation of element data
- CVE: https://linux.oracle.com/cve/CVE-2022-34918.html
- Patch: oel8-uek6/5.4.17-2136.321.4.el8uek/CVE-2022-34918-netfilter-nf_tables-stricter-validation-of-element-data.patch
- From: 5.4.17-2136.321.4
- CVE-2022-39189
- Description:
KVM: x86: do not report a vCPU as preempted outside instruction boundaries (adaptation)
- CVE: https://linux.oracle.com/cve/CVE-2022-39189.html
- Patch: oel8-uek6/5.4.17-2136.321.4.el8uek/CVE-2022-39189-KVM-x86-do-not-report-a-vCPU-as-preempted-outside-instruction-boundaries-kpatch-2011.patch
- From: 5.4.17-2136.321.4
- CVE-2022-40982
- Description:
Complex adaptation required.
- CVE:
- Patch: skipped/CVE-2022-40982.patch
- From:
- CVE-2023-22024
- Description:
rds: Fix lack of reentrancy for connection reset with dst addr zero
- CVE: https://linux.oracle.com/cve/CVE-2023-22024.html
- Patch: 5.4.17/CVE-2023-22024-rds-Fix-lack-of-reentrancy-for-connection-reset-with-dst-addr-zero-2036.patch
- From: 5.4.17-2136.323.8.1
- CVE-2023-42753
- Description:
netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c
- CVE: https://linux.oracle.com/cve/CVE-2023-42753.html
- Patch: 5.4.17/CVE-2023-42753-netfilter-ipset-add-the-missing-IP_SET_HASH_WITH_NET0-macro-for-ip_set_hash_netportnet-c.patch
- From: 5.4.17-2136.323.8.2
- CVE-2023-20569
- Description:
A low priority AMD Inception vulnerability that affects Zen3/Zen4 & relates to RetBleed fixes requiring microcode updates, we can't do much about it in KCare Infra.
- CVE:
- Patch: skipped/CVE-2023-20569.patch
- From:
- CVE-2023-20588
- Description:
x86/CPU/AMD: Do not leak quotient data after a division by 0
- CVE: https://alas.aws.amazon.com/cve/html/CVE-2023-20588.html
- Patch: oel8-uek6/5.4.17-2136.324.5.3.el8uek/CVE-2023-20588-x86-CPU-AMD-Do-not-leak-quotient-data-after-a-division-by-0-2102.patch
- From: kernel-4.14.322-244.539.amzn2
- CVE-2023-1989
- Description:
Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition
- CVE: https://linux.oracle.com/cve/CVE-2023-1989.html
- Patch: oel8-uek6/5.4.17-2136.325.5.el8uek/CVE-2023-1989-patch-bluetooth-btsdio-fix-use-after-free-bug-in-btsdio-remove.patch
- From: 5.4.17-2136.325.5.el8uek
- CVE-2023-5178
- Description:
nvmet-tcp: move send/recv error handling in the send/recv methods instead of call-sites (dependency)
- CVE: https://linux.oracle.com/cve/CVE-2023-5178.html
- Patch: oel8-uek6/5.4.17-2136.326.6.el8uek/CVE-2023-5178-nvmet-tcp-move-send-recv-error-handling-in-the-send-recv-methods-instead-of-call-sites.patch
- From: 5.4.17-2136.326.6.el8uek
- CVE-2023-5178
- Description:
nvmet-tcp: Fix a possible UAF in queue intialization setup
- CVE: https://linux.oracle.com/cve/CVE-2023-5178.html
- Patch: oel8-uek6/5.4.17-2136.326.6.el8uek/CVE-2023-5178-nvmet-tcp-fix-a-possible-uaf-in-queue-intialization-setup.patch
- From: 5.4.17-2136.326.6.el8uek
- CVE-2023-45863
- Description:
kobject: Fix slab-out-of-bounds in fill_kobj_path()
- CVE: https://linux.oracle.com/cve/CVE-2023-45863.html
- Patch: oel8-uek6/5.4.17-2136.328.3.el8uek/CVE-2023-45863-kobject-Fix-slab-out-of-bounds-in-fill_kobj_path.patch
- From: 5.4.17-2136.328.3.
- CVE-2023-4244
- Description:
An introduction of required changes through KernelCare could cause unavoidable problems to applications which use netfilter functionality.
- CVE:
- Patch: skipped/CVE-2023-4244.patch
- From:
- CVE-2024-1086
- Description:
netfilter: nf_tables: reject QUEUE/DROP verdict parameters
- CVE: https://linux.oracle.com/cve/CVE-2024-1086.html
- Patch: oel8-uek6/5.4.17-2136.329.3.2.el8uek/CVE-2024-1086-netfilter-nf_tables-reject-QUEUE-DROP-verdict-parameters-323.patch
- From: 5.4.17-2136.329.3.2
- CVE-2024-0340
- Description:
vhost: use kzalloc() instead of kmalloc() followed by memset()
- CVE: https://linux.oracle.com/cve/CVE-2024-0340.html
- Patch: oel8-uek6/5.4.17-2136.330.7.1.el8uek/CVE-2024-0340-vhost-use-kzalloc-instead-of-kmalloc-followed-by-memset.patch
- From: 5.4.17-2136.330.7.1
- CVE-2024-0607
- Description:
netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- CVE: https://linux.oracle.com/cve/CVE-2024-0607.html
- Patch: oel8-uek6/5.4.17-2136.330.7.1.el8uek/CVE-2024-0607-nf_tables-fix-pointer-math-issue-in-nft_byteorder_eval.patch
- From: 5.4.17-2136.330.7.1
- N/A
- Description:
kpatch add alt asm definitions
- CVE: N/A
- Patch: 5.11.0/kpatch-add-alt-asm-definitions.patch
- From: N/A
- N/A
- Description:
kpatch add alternative2 asm definition
- CVE: https://www.kernel.org
- Patch: 5.4.0/kpatch-add-alt2-asm-definitions.patch
- From: N/A
- CVE-2024-2201
- Description:
x86/bhi: Add support for clearing branch history at syscall entry
- CVE: https://ubuntu.com/security/CVE-2024-2201
- Patch: 5.4.0/CVE-2024-2201-x86-bhi-Add-support-for-clearing-branch-history-at-syscall-entry-5.4-304.patch
- From: kernel-uek-5.4.17-2136.330.7.1.el8uek
- CVE-2024-41090
- Description:
tap: add missing verification for short frame
- CVE: https://access.redhat.com/security/cve/CVE-2024-41090
- Patch: 5.15.0/CVE-2024-41090-tap-add-missing-verification-for-short-frame.patch
- From: 5.15.0-208.159.3.2
- CVE-2024-41091
- Description:
tun: add missing verification for short frame
- CVE: https://access.redhat.com/security/cve/CVE-2024-41091
- Patch: 5.15.0/CVE-2024-41091-tun-add-missing-verification-for-short-frame.patch
- From: 5.15.0-208.159.3.2
- CVE-2024-36971
- Description:
net: fix __dst_negative_advice() race
- CVE: https://linux.oracle.com/cve/CVE-2024-36971.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-36971-net-fix-__dst_negative_advice-race-2136.327.patch
- From: 5.4.17-2136.334.6
- CVE-2024-38583
- Description:
nilfs2: We cannot patch functions that sleep in kthread().
- CVE:
- Patch: skipped/CVE-2024-38583.patch
- From:
- CVE-2024-36015
- Description:
ppdev: Add an error check in register_device
- CVE: https://linux.oracle.com/cve/CVE-2024-36015.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-36015-ppdev-add-an-error-check-in-register-device-5.4.17-2136.333.5.1.el8uek.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38582
- Description:
nilfs2: fix potential hang in nilfs_detach_log_writer()
- CVE: https://linux.oracle.com/cve/CVE-2024-38582.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38582-nilfs2-fix-potential-hang-in-nilfs-detach-log-writer-5.4.17-2136.333.5.1.el8uek.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-39480
- Description:
kdb: Fix buffer overflow during tab-complete
- CVE: https://linux.oracle.com/cve/CVE-2024-39480.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-39480-kdb-Fix-buffer-overflow-during-tab-complete.patch
- From: 5.4.17-2136.334.6
- CVE-2024-38612
- Description:
ipv6: sr: fix invalid unregister error path
- CVE: https://linux.oracle.com/cve/CVE-2024-38612.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38612-ipv6-sr-fix-invalid-unregister-error-path-2136.330.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-36016
- Description:
tty: n_gsm: fix possible out-of-bounds in gsm0_receive()
- CVE: https://linux.oracle.com/cve/CVE-2024-36016.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-36016-tty-n-gsm-fix-possible-out-of-bounds-in-gsm0-receive.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38579
- Description:
crypto: bcm - Fix pointer arithmetic
- CVE: https://linux.oracle.com/cve/CVE-2024-38579.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38579-crypto-bcm-fix-pointer-arithmetic.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38599
- Description:
jffs2: prevent xattr node from overflowing the eraseblock
- CVE: https://linux.oracle.com/cve/CVE-2024-38599.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38599-jffs2-prevent-xattr-node-from-overflowing-the-eraseblock.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38567
- Description:
USB: core: Add routines for endpoint checks in old drivers
- CVE: https://linux.oracle.com/cve/CVE-2024-38567.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38567-USB-core-Add-routines-for-endpoint-checks-in-old-drivers.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38567
- Description:
wifi: carl9170: add a proper sanity check for endpoints
- CVE: https://linux.oracle.com/cve/CVE-2024-38567.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38567-wifi-carl9170-add-a-proper-sanity-check-for-endpoints.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38549
- Description:
drm/mediatek: Add 0 size check to mtk_drm_gem_obj
- CVE: https://linux.oracle.com/cve/CVE-2024-38549.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38549-drm-mediatek-add-0-size-check-to-mtk-drm-gem-obj.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-36014
- Description:
drm/arm/malidp: fix a possible null pointer dereference
- CVE: https://linux.oracle.com/cve/CVE-2024-36014.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-36014-drm-arm-malidp-fix-a-possible-null-pointer-dereference.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38633
- Description:
serial: max3100: Update uart_driver_registered on driver
- CVE: https://linux.oracle.com/cve/CVE-2024-38633.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38633-serial-max3100-update-uart-driver-registered-on-driver.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-36286
- Description:
netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()
- CVE: https://linux.oracle.com/cve/CVE-2024-36286.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-36286-netfilter-nfnetlink-queue-acquire-rcu-read-lock-in.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38659
- Description:
enic: Validate length of nl attributes in enic_set_vf_port
- CVE: https://linux.oracle.com/cve/CVE-2024-38659.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38659-enic-validate-length-of-nl-attributes-in-enic-set-vf-port.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38661
- Description:
Out of scope as the patch is for s390 arch only, x86_64, arm64 is not affected
- CVE:
- Patch: skipped/CVE-2024-38661.patch
- From:
- CVE-2024-35976
- Description:
xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
- CVE: https://linux.oracle.com/cve/CVE-2024-35976.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-35976-xsk-validate-user-input-for-xdp-umem-completion-fill-ring.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38552
- Description:
drm/amd/display: Fix potential index out of bounds in color transformation function
- CVE: https://linux.oracle.com/cve/CVE-2024-38552.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38552-drm-amd-display-fix-potential-index-out-of-bounds-in-color.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38560
- Description:
scsi: bfa: Ensure the copied buf is NUL terminated
- CVE: https://linux.oracle.com/cve/CVE-2024-38560.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38560-scsi-bfa-ensure-the-copied-buf-is-nul-terminated.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38596
- Description:
af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg
- CVE: https://linux.oracle.com/cve/CVE-2024-38596.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38596-af-unix-fix-data-races-in.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38637
- Description:
greybus: lights: check return of get_channel_from_mode
- CVE: https://linux.oracle.com/cve/CVE-2024-38637.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38637-greybus-lights-check-return-of-get-channel-from-mode.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-37353
- Description:
virtio: delete vq in vp_find_vqs_msix() when request_irq() fails
- CVE: https://linux.oracle.com/cve/CVE-2024-37353.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-37353-virtio-delete-vq-in-vp-find-vqs-msix-when-request-irq.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38618
- Description:
ALSA: timer: Set lower bound of start tick time
- CVE: https://linux.oracle.com/cve/CVE-2024-38618.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38618-alsa-timer-set-lower-bound-of-start-tick-time.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-37356
- Description:
tcp: Fix shift-out-of-bounds in dctcp_update_alpha().
- CVE: https://linux.oracle.com/cve/CVE-2024-37356.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-37356-tcp-fix-shift-out-of-bounds-in-dctcp-update-alpha.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-37356
- Description:
tcp: Fix shift-out-of-bounds in dctcp_update_alpha().
- CVE: https://linux.oracle.com/cve/CVE-2024-37356.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-37356-tcp-fix-shift-out-of-bounds-in-dctcp-update-alpha-kpatch.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38565
- Description:
wifi: ar5523: enable proper endpoint verification
- CVE: https://linux.oracle.com/cve/CVE-2024-38565.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38565-wifi-ar5523-enable-proper-endpoint-verification.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38578
- Description:
ecryptfs: Fix buffer size for tag 66 packet
- CVE: https://linux.oracle.com/cve/CVE-2024-38578.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38578-ecryptfs-fix-buffer-size-for-tag-66-packet.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38601
- Description:
ring-buffer: Fix a race between readers and resize checks
- CVE: https://linux.oracle.com/cve/CVE-2024-38601.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38601-ring-buffer-fix-a-race-between-readers-and-resize-checks.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38634
- Description:
serial: max3100: Lock port->lock when calling
- CVE: https://linux.oracle.com/cve/CVE-2024-38634.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38634-serial-max3100-lock-port-lock-when-calling.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-39276
- Description:
ext4: fix mb_cache_entry's e_refcnt leak in
- CVE: https://linux.oracle.com/cve/CVE-2024-39276.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-39276-ext4-fix-mb-cache-entry-s-e-refcnt-leak-in.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-39467
- Description:
f2fs: fix to do sanity check on i_xattr_nid in
- CVE: https://linux.oracle.com/cve/CVE-2024-39467.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-39467-f2fs-fix-to-do-sanity-check-on-i-xattr-nid-in.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-39471
- Description:
drm/amdgpu: add error handle to avoid out-of-bounds
- CVE: https://linux.oracle.com/cve/CVE-2024-39471.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-39471-drm-amdgpu-add-error-handle-to-avoid-out-of-bounds.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-39488
- Description:
Out of scope: ARM64 architecture issue
- CVE:
- Patch: skipped/CVE-2024-39488.patch
- From:
- CVE-2024-33621
- Description:
ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound
- CVE: https://linux.oracle.com/cve/CVE-2024-33621.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-33621-ipvlan-dont-use-skb-sk-in-ipvlan-process-v-46-outbound-5.4.17-2136.320.7.1.el8uek.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-36288
- Description:
SUNRPC: Fix gss_free_in_token_pages()
- CVE: https://linux.oracle.com/cve/CVE-2024-36288.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-36288-sunrpc-fix-gss_free_in_token_pages.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-36288
- Description:
SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
- CVE: https://linux.oracle.com/cve/CVE-2024-36288.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-36288-sunrpc-fix-loop-termination-condition-in-5.4.17-2136.316.7.el8uek.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-36270
- Description:
netfilter: tproxy: bail out if IP has been disabled on the device
- CVE: https://linux.oracle.com/cve/CVE-2024-36270.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-36270-netfilter-tproxy-bail-out-if-ip-has-been-disabled-on-the.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38558
- Description:
net: openvswitch: fix overwriting ct original tuple for ICMPv6
- CVE: https://linux.oracle.com/cve/CVE-2024-38558.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38558-net-openvswitch-fix-overwriting-ct-original-tuple-for.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38559
- Description:
scsi: qedf: Ensure the copied buf is NUL terminated
- CVE: https://linux.oracle.com/cve/CVE-2024-38559.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38559-scsi-qedf-ensure-the-copied-buf-is-nul-terminated.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38635
- Description:
soundwire: Skipped as code which CVE fixes doesn't exists in older releaes
- CVE:
- Patch: skipped/CVE-2024-38635.patch
- From:
- CVE-2024-39301
- Description:
net/9p: fix uninit-value in p9_client_rpc()
- CVE: https://linux.oracle.com/cve/CVE-2024-39301.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-39301-net-9p-fix-uninit-value-in-p9-client-rpc.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38615
- Description:
cpufreq: exit() callback is optional
- CVE: https://linux.oracle.com/cve/CVE-2024-38615.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38615-cpufreq-exit-callback-is-optional.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38613
- Description:
Out of scope as the patch is for m68k arch only, x86_64, arm64 is not affected
- CVE:
- Patch: skipped/CVE-2024-38613.patch
- From:
- CVE-2024-38589
- Description:
netrom: fix possible dead-lock in nr_rt_ioctl()
- CVE: https://linux.oracle.com/cve/CVE-2024-38589.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38589-netrom-fix-possible-dead-lock-in-nr-rt-ioctl.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38627
- Description:
stm class: Fix a double free in stm_register_device()
- CVE: https://linux.oracle.com/cve/CVE-2024-38627.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38627-stm-class-fix-a-double-free-in-stm-register-device.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-39292
- Description:
Out of scope: User-mode Linux isn't supported for current kernel
- CVE:
- Patch: skipped/CVE-2024-39292.patch
- From:
- CVE-2024-38621
- Description:
media: stk1160: fix bounds checking in stk1160_copy_video()
- CVE: https://linux.oracle.com/cve/CVE-2024-38621.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38621-media-stk1160-fix-bounds-checking-in-stk1160-copy-video.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-39489
- Description:
ipv6: sr: fix memleak in seg6_hmac_init_algo
- CVE: https://linux.oracle.com/cve/CVE-2024-39489.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-39489-ipv6-sr-fix-memleak-in-seg6-hmac-init-algo.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-38780
- Description:
dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
- CVE: https://linux.oracle.com/cve/CVE-2024-38780.html
- Patch: oel8-uek6/5.4.17-2136.334.6.el8uek/CVE-2024-38780-dma-buf-sw-sync-don-t-enable-irq-from-sync-print-obj.patch
- From: 5.4.17-2136.334.6.el8uek
- CVE-2024-40958
- Description:
netns: Make get_net_ns() handle zero refcount net
- CVE: https://linux.oracle.com/cve/CVE-2024-40958.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40958-netns-make-get-net-ns-handle-zero-refcount-net-203.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41049
- Description:
filelock: fix potential use-after-free in posix_lock_inode
- CVE: https://linux.oracle.com/cve/CVE-2024-41049.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41049-filelock-fix-potential-use-after-free-in-posix-lock-inode-324.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2023-52628
- Description:
netfilter: nftables: exthdr: fix 4-byte stack OOB write
- CVE: https://linux.oracle.com/cve/CVE-2023-52628.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2023-52628-netfilter-nftables-exthdr-fix-4-byte-stack-oob-write.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42094
- Description:
net/iucv: Avoid explicit cpumask var allocation on stack
- CVE: https://linux.oracle.com/cve/CVE-2024-42094.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42094-net-iucv-avoid-explicit-cpumask-var-allocation-on-stack.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-39487
- Description:
bonding: Fix out-of-bounds read in
- CVE: https://linux.oracle.com/cve/CVE-2024-39487.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-39487-bonding-fix-out-of-bounds-read-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41046
- Description:
net: ethernet: lantiq_etop: fix double free in detach
- CVE: https://linux.oracle.com/cve/CVE-2024-41046.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41046-net-ethernet-lantiq-etop-fix-double-free-in-detach-5.4.17-2136.334.6.el8uek.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42104
- Description:
nilfs2: add missing check for inode numbers on directory
- CVE: https://linux.oracle.com/cve/CVE-2024-42104.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42104-nilfs2-add-missing-check-for-inode-numbers-on-directory.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2022-3567
- Description:
ipv6: annotate some data-races around sk->sk_prot
- CVE: https://linux.oracle.com/cve/CVE-2022-3567.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2022-3567-ipv6-annotate-some-data-races-around-sk-sk_prot.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2022-3567
- Description:
ipv6: Fix data races around sk->sk_prot.
- CVE: https://linux.oracle.com/cve/CVE-2022-3567.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2022-3567-ipv6-fix-data-races-around-sk-sk_prot.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2022-3566
- Description:
tcp: Fix data races around icsk->icsk_af_ops.
- CVE: https://linux.oracle.com/cve/CVE-2022-3566.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2022-3566-tcp-Fix-data-races-around-icsk-icsk_af_ops.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-39469
- Description:
nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors
- CVE: https://linux.oracle.com/cve/CVE-2024-39469.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-39469-nilfs2-fix-nilfs-empty-dir-misjudgment-and-long-loop-on-5.4.17-2136.334.6.1.el8uek.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-39499
- Description:
vmci: prevent speculation leaks by sanitizing event in event_deliver()
- CVE: https://linux.oracle.com/cve/CVE-2024-39499.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-39499-vmci-prevent-speculation-leaks-by-sanitizing-event-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-39506
- Description:
liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet
- CVE: https://linux.oracle.com/cve/CVE-2024-39506.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-39506-liquidio-adjust-a-null-pointer-handling-path-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40904
- Description:
USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages
- CVE: https://linux.oracle.com/cve/CVE-2024-40904.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40904-usb-class-cdc-wdm-fix-cpu-lockup-caused-by-excessive-log.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40932
- Description:
drm/exynos/vidi: fix memory leak in .get_modes()
- CVE: https://linux.oracle.com/cve/CVE-2024-40932.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40932-drm-exynos-vidi-fix-memory-leak-in-get-modes.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40960
- Description:
ipv6: prevent possible NULL dereference in rt6_probe()
- CVE: https://linux.oracle.com/cve/CVE-2024-40960.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40960-ipv6-prevent-possible-null-dereference-in-rt6-probe.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40988
- Description:
drm/radeon: fix UBSAN warning in kv_dpm.c
- CVE: https://linux.oracle.com/cve/CVE-2024-40988.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40988-drm-radeon-fix-ubsan-warning-in-kv-dpm-c.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41035
- Description:
USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor
- CVE: https://linux.oracle.com/cve/CVE-2024-41035.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41035-usb-core-fix-duplicate-endpoint-bug-by-clearing-reserved-5.4.17-2011.7.4.el8uek.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41097
- Description:
usb: atm: cxacru: fix endpoint checking in cxacru_bind()
- CVE: https://linux.oracle.com/cve/CVE-2024-41097.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41097-usb-atm-cxacru-fix-endpoint-checking-in-cxacru-bind.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42076
- Description:
net: can: j1939: Initialize unused data in j1939_send_one()
- CVE: https://linux.oracle.com/cve/CVE-2024-42076.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42076-net-can-j1939-initialize-unused-data-in-j1939-send-one-315.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40943
- Description:
ocfs2: fix races between hole punching and AIO+DIO
- CVE: https://linux.oracle.com/cve/CVE-2024-40943.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40943-ocfs2-fix-races-between-hole-punching-and-aio-dio.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40995
- Description:
net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc()
- CVE: https://linux.oracle.com/cve/CVE-2024-40995.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40995-net-sched-act-api-fix-possible-infinite-loop-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41044
- Description:
ppp: reject claimed-as-LCP but actually malformed packets
- CVE: https://linux.oracle.com/cve/CVE-2024-41044.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41044-ppp-reject-claimed-as-lcp-but-actually-malformed-packets-307.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42089
- Description:
ASoC: fsl-asoc-card: set priv->pdev before using it
- CVE: https://linux.oracle.com/cve/CVE-2024-42089.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42089-asoc-fsl-asoc-card-set-priv-pdev-before-using-it.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41007
- Description:
net: tcp: fix unexcepted socket die when snd_wnd is 0
- CVE: https://linux.oracle.com/cve/CVE-2024-41007.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41007-net-tcp-fix-unexcepted-socket-die-when-snd_wnd-is-0.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41007
- Description:
tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
- CVE: https://linux.oracle.com/cve/CVE-2024-41007.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41007-tcp-use-signed-arithmetic-in-tcp_rtx_probe0_timed_out.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41007
- Description:
tcp: avoid too many retransmit packets
- CVE: https://linux.oracle.com/cve/CVE-2024-41007.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41007-tcp-avoid-too-many-retransmit-packets.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42096
- Description:
x86: stop playing stack games in profile_pc()
- CVE: https://linux.oracle.com/cve/CVE-2024-42096.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42096-x86-stop-playing-stack-games-in-profile-pc.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40978
- Description:
scsi: qedi: Fix crash while reading debugfs attribute
- CVE: https://linux.oracle.com/cve/CVE-2024-40978.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40978-scsi-qedi-fix-crash-while-reading-debugfs-attribute.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42106
- Description:
inet_diag: Initialize pad field in struct inet_diag_req_v2
- CVE: https://linux.oracle.com/cve/CVE-2024-42106.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42106-inet-diag-initialize-pad-field-in-struct-inet-diag-req-v2.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40987
- Description:
drm/amdgpu: fix UBSAN warning in kv_dpm.c
- CVE: https://linux.oracle.com/cve/CVE-2024-40987.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40987-drm-amdgpu-fix-ubsan-warning-in-kv-dpm-c.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-36894
- Description:
USB composite function controllers related patch
- CVE:
- Patch: skipped/CVE-2024-36894.patch
- From:
- CVE-2024-36974
- Description:
net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
- CVE: https://linux.oracle.com/cve/CVE-2024-36974.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-36974-net-sched-taprio-always-validate-tca-taprio-attr-priomap.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-39501
- Description:
drivers: core: synchronize really_probe() and dev_uevent()
- CVE: https://linux.oracle.com/cve/CVE-2024-39501.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-39501-drivers-core-synchronize-really-probe-and-dev-uevent.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-39501
- Description:
driver core: Fix uevent_show() vs driver detach race
- CVE: https://linux.oracle.com/cve/CVE-2024-39501.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-39501-driver-core-fix-uevent_show-vs-driver-detach-race.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-39505
- Description:
ARM related patch
- CVE:
- Patch: skipped/CVE-2024-39505.patch
- From:
- CVE-2024-40959
- Description:
xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
- CVE: https://linux.oracle.com/cve/CVE-2024-40959.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40959-xfrm6-check-ip6-dst-idev-return-value-in-xfrm6-get-saddr.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41034
- Description:
nilfs2 related patch
- CVE:
- Patch: skipped/CVE-2024-41034.patch
- From:
- CVE-2024-41041
- Description:
udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().
- CVE: https://linux.oracle.com/cve/CVE-2024-41041.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41041-udp-set-sock-rcu-free-earlier-in-udp-lib-get-port.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42097
- Description:
ALSA: emux: improve patch ioctl data validation
- CVE: https://linux.oracle.com/cve/CVE-2024-42097.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42097-alsa-emux-improve-patch-ioctl-data-validation.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42105
- Description:
nilfs2 related patch
- CVE:
- Patch: skipped/CVE-2024-42105.patch
- From:
- CVE-2024-42223
- Description:
media: dvb-frontends: tda10048: Fix integer overflow
- CVE: https://linux.oracle.com/cve/CVE-2024-42223.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42223-media-dvb-frontends-tda10048-fix-integer-overflow.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40945
- Description:
iommu: Return right value in iommu_sva_bind_device()
- CVE: https://linux.oracle.com/cve/CVE-2024-40945.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40945-iommu-return-right-value-in-iommu-sva-bind-device.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41022
- Description:
drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()
- CVE: https://linux.oracle.com/cve/CVE-2024-41022.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41022-drm-amdgpu-fix-signedness-bug-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41095
- Description:
drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes
- CVE: https://linux.oracle.com/cve/CVE-2024-41095.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41095-drm-nouveau-dispnv04-fix-null-pointer-dereference-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42087
- Description:
drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep
- CVE: https://linux.oracle.com/cve/CVE-2024-42087.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42087-drm-panel-ilitek-ili9881c-fix-warning-with-gpio-controllers.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42101
- Description:
drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes
- CVE: https://linux.oracle.com/cve/CVE-2024-42101.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42101-drm-nouveau-fix-null-pointer-dereference-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42119
- Description:
drm/amd/display: Skip finding free audio for unknown engine_id
- CVE: https://linux.oracle.com/cve/CVE-2024-42119.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42119-drm-amd-display-skip-finding-free-audio-for-unknown.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-37078
- Description:
nilfs2 is not enabled
- CVE:
- Patch: skipped/CVE-2024-37078.patch
- From:
- CVE-2024-39509
- Description:
HID: core: remove unnecessary WARN_ON() in implement()
- CVE: https://linux.oracle.com/cve/CVE-2024-39509.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-39509-hid-core-remove-unnecessary-warn-on-in-implement.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-38619
- Description:
usb-storage: alauda: Fix uninit-value in alauda_check_media()
- CVE: https://linux.oracle.com/cve/CVE-2024-38619.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-38619-usb-storage-alauda-Fix-uninit-value-in-alauda_check_media.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-38619
- Description:
usb-storage: alauda: Check whether the media is initialized
- CVE: https://linux.oracle.com/cve/CVE-2024-38619.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-38619-usb-storage-alauda-check-whether-the-media-is-initialized.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-38619
- Description:
usb-storage: alauda: Check whether the media is initialized (Adaptation)
- CVE: https://linux.oracle.com/cve/CVE-2024-38619.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-38619-usb-storage-alauda-check-whether-the-media-is-initialized-kpatch.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40901
- Description:
scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory
- CVE: https://linux.oracle.com/cve/CVE-2024-40901.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40901-scsi-mpt3sas-avoid-test-set-bit-operating-in-5.4.17-2102.202.5.el8uek.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40912
- Description:
wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup()
- CVE: https://linux.oracle.com/cve/CVE-2024-40912.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40912-wifi-mac80211-fix-deadlock-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40941
- Description:
wifi: iwlwifi: mvm: don't read past the mfuart notifcation
- CVE: https://linux.oracle.com/cve/CVE-2024-40941.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40941-wifi-iwlwifi-mvm-don-t-read-past-the-mfuart-notifcation.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40942
- Description:
wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects
- CVE: https://linux.oracle.com/cve/CVE-2024-40942.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40942-wifi-mac80211-mesh-fix-leak-of-mesh-preq-queue-objects.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40968
- Description:
MIPS related CVE.
- CVE:
- Patch: skipped/CVE-2024-40968.patch
- From:
- CVE-2024-40993
- Description:
netfilter: ipset: Fix suspicious rcu_dereference_protected()
- CVE: https://linux.oracle.com/cve/CVE-2024-40993.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40993-netfilter-ipset-fix-suspicious-rcu-dereference-protected-5.4.17-2136.327.2.el8uek.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42084
- Description:
ftruncate: pass a signed offset
- CVE: https://linux.oracle.com/cve/CVE-2024-42084.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42084-ftruncate-pass-a-signed-offset.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42127
- Description:
drm/lima: fix shared irq handling on driver remove
- CVE: https://linux.oracle.com/cve/CVE-2024-42127.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42127-drm-lima-fix-shared-irq-handling-on-driver-remove.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42157
- Description:
s390 architecture related CVE.
- CVE:
- Patch: skipped/CVE-2024-42157.patch
- From:
- CVE-2024-40905
- Description:
ipv6: fix possible race in __fib6_drop_pcpu_from()
- CVE: https://linux.oracle.com/cve/CVE-2024-40905.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40905-ipv6-fix-possible-race-in-fib6-drop-pcpu-from-5.4.17-2011.7.4.el8uek.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42070
- Description:
netfilter: nf_tables: fully validate NFT_DATA_VALUE on store
- CVE: https://linux.oracle.com/cve/CVE-2024-42070.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42070-netfilter-nf-tables-fully-validate-nft-data-value-on-store-5.4.17-2136.320.7.1.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40963
- Description:
Out of scope as the patch is for MIPS arch only, x86_64 is not affected
- CVE:
- Patch: skipped/CVE-2024-40963.patch
- From:
- CVE-2024-40974
- Description:
Out of scope as the patch is for powerpc arch only, x86_64 is not affected
- CVE:
- Patch: skipped/CVE-2024-40974.patch
- From:
- CVE-2024-42145
- Description:
IB/core: Implement a limit on UMAD receive List
- CVE: https://linux.oracle.com/cve/CVE-2024-42145.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42145-ib-core-implement-a-limit-on-umad-receive-list.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42145
- Description:
IB/core: Implement a limit on UMAD receive List (adaptation)
- CVE: https://linux.oracle.com/cve/CVE-2024-42145.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42145-ib-core-implement-a-limit-on-umad-receive-list-kpatch.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2023-52803
- Description:
SUNRPC: Fix RPC client cleaned up the freed pipefs dentries kpatch
- CVE: https://linux.oracle.com/cve/CVE-2023-52803.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2023-52803-sunrpc-fix-rpc-client-cleaned-up-the-freed-pipefs-dentries-kpatch.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-36978
- Description:
net: sched: sch_multiq: fix possible OOB write in multiq_tune()
- CVE: https://linux.oracle.com/cve/CVE-2024-36978.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-36978-net-sched-sch-multiq-fix-possible-oob-write-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40902
- Description:
jfs: xattr: fix buffer overflow for invalid xattr
- CVE: https://linux.oracle.com/cve/CVE-2024-40902.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40902-jfs-xattr-fix-buffer-overflow-for-invalid-xattr.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-39495
- Description:
greybus: Fix use-after-free bug in gb_interface_release due to race condition.
- CVE: https://linux.oracle.com/cve/CVE-2024-39495.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-39495-greybus-fix-use-after-free-bug-in-gb-interface-release-due.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42093
- Description:
net/dpaa2: Avoid explicit cpumask var allocation on stack
- CVE: https://linux.oracle.com/cve/CVE-2024-42093.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42093-net-dpaa2-avoid-explicit-cpumask-var-allocation-on-stack.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41087
- Description:
ata: libata-core: Fix double free on error
- CVE: https://linux.oracle.com/cve/CVE-2024-41087.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41087-ata-libata-core-fix-double-free-on-error.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42224
- Description:
net: dsa: mv88e6xxx: Correct check for empty list
- CVE: https://linux.oracle.com/cve/CVE-2024-42224.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42224-net-dsa-mv88e6xxx-correct-check-for-empty-list.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42154
- Description:
tcp_metrics: validate source addr length
- CVE: https://linux.oracle.com/cve/CVE-2024-42154.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42154-tcp-metrics-validate-source-addr-length.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42154
- Description:
tcp_metrics: validate source addr length
- CVE: https://linux.oracle.com/cve/CVE-2024-42154.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42154-tcp-metrics-validate-source-addr-length-kpatch.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42148
- Description:
bnx2x: Fix multiple UBSAN array-index-out-of-bounds
- CVE: https://linux.oracle.com/cve/CVE-2024-42148.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42148-bnx2x-fix-multiple-ubsan-array-index-out-of-bounds-kpatch.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40961
- Description:
ipv6: prevent possible NULL deref in fib6_nh_init()
- CVE: https://linux.oracle.com/cve/CVE-2024-40961.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40961-ipv6-prevent-possible-null-deref-in-fib6-nh-init.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-40981
- Description:
batman-adv: bypass empty buckets in batadv_purge_orig_ref()
- CVE: https://linux.oracle.com/cve/CVE-2024-40981.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40981-batman-adv-bypass-empty-buckets-in-batadv-purge-orig-ref.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-41089
- Description:
drm/nouveau/dispnv04: fix null pointer dereference in
- CVE: https://linux.oracle.com/cve/CVE-2024-41089.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41089-drm-nouveau-dispnv04-fix-null-pointer-dereference-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42092
- Description:
gpio: davinci: Validate the obtained number of IRQs
- CVE: https://linux.oracle.com/cve/CVE-2024-42092.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42092-gpio-davinci-validate-the-obtained-number-of-irqs.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42115
- Description:
jffs2: Fix potential illegal address access in
- CVE: https://linux.oracle.com/cve/CVE-2024-42115.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42115-jffs2-fix-potential-illegal-address-access-in.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-39502
- Description:
Patches a sleepable function, there is a small but non-zero risk of livepatching failure
- CVE:
- Patch: skipped/CVE-2024-39502.patch
- From:
- CVE-2024-41006
- Description:
netrom: Fix a memory leak in nr_heartbeat_expiry()
- CVE: https://linux.oracle.com/cve/CVE-2024-41006.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-41006-netrom-fix-a-memory-leak-in-nr-heartbeat-expiry-5.4.17-2102.204.4.4.el8uek.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42236
- Description:
usb: gadget: configfs: Prevent OOB read/write in
- CVE: https://linux.oracle.com/cve/CVE-2024-42236.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42236-usb-gadget-configfs-prevent-oob-read-write-in-5.4.17-2102.202.5.el8uek.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42090
- Description:
pinctrl: fix deadlock in create_pinctrl() when handling
- CVE: https://linux.oracle.com/cve/CVE-2024-42090.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42090-pinctrl-fix-deadlock-in-create-pinctrl-when-handling.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42086
- Description:
iio: chemical: bme680: Fix overflows in compensate()
- CVE: https://linux.oracle.com/cve/CVE-2024-42086.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42086-iio-chemical-bme680-fix-overflows-in-compensate.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42124
- Description:
scsi: qedf: Make qedf_execute_tmf() non-preemptible
- CVE: https://linux.oracle.com/cve/CVE-2024-42124.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42124-scsi-qedf-make-qedf-execute-tmf-non-preemptible.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42143
- Description:
orangefs: fix out-of-bounds fsid access
- CVE: https://linux.oracle.com/cve/CVE-2024-42143.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42143-orangefs-fix-out-of-bounds-fsid-access.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-36484
- Description:
Patches a sleepable function, there is a small but non-zero risk of livepatching failure
- CVE:
- Patch: skipped/CVE-2024-36484.patch
- From:
- CVE-2024-40980
- Description:
drop_monitor: replace spin_lock by raw_spin_lock
- CVE: https://linux.oracle.com/cve/CVE-2024-40980.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-40980-drop-monitor-replace-spin-lock-by-raw-spin-lock.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42153
- Description:
i2c: pnx: Fix potential deadlock warning from
- CVE: https://linux.oracle.com/cve/CVE-2024-42153.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42153-i2c-pnx-fix-potential-deadlock-warning-from.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42153
- Description:
i2c: pnx: Fix potential deadlock warning from
- CVE: https://linux.oracle.com/cve/CVE-2024-42153.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42153-i2c-pnx-fix-potential-deadlock-warning-from-kpatch.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-42232
- Description:
libceph: fix race between delayed_work() and ceph_monc_stop()
- CVE: https://linux.oracle.com/cve/CVE-2024-42232.html
- Patch: oel8-uek6/5.4.17-2136.335.4.el8uek/CVE-2024-42232-libceph-fix-race-between-delayed-work-and-ceph-monc-stop.patch
- From: 5.4.17-2136.335.4.el8uek
- CVE-2024-49863
- Description:
vhost/scsi: null-ptr-dereference in vhost_scsi_get_req()
- CVE: https://linux.oracle.com/cve/CVE-2024-49863.html
- Patch: oel8-uek6/5.4.17-2136.335.4.1.el8uek/CVE-2024-49863-vhost-scsi-null-ptr-dereference-in-vhost_scsi_get_req-uek6-lt-5.4.17-2036.102.patch
- From: 5.4.17-2136.335.4.1.el8uek
- CVE-2024-44954
- Description:
ALSA: line6: Fix racy access to midibuf
- CVE: https://linux.oracle.com/cve/CVE-2024-44954.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-44954-alsa-line6-fix-racy-access-to-midibuf-5.4.17-2011.7.4.el8uek.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-41070
- Description:
KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()
- CVE: https://linux.oracle.com/cve/CVE-2024-41070.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-41070-kvm-ppc-book3s-hv-prevent-uaf-in-kvm-spapr-tce-attach-iommu-group-5.4.17-2011.7.4.el8uek.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42301
- Description:
dev/parport: fix the array out-of-bounds risk
- CVE: https://linux.oracle.com/cve/CVE-2024-42301.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42301-dev-parport-fix-the-array-out-of-bounds-risk-5.4.17-2136.335.4.1.el8uek.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-41059
- Description:
hfsplus: fix uninit-value in copy_name
- CVE: https://linux.oracle.com/cve/CVE-2024-41059.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-41059-hfsplus-fix-uninit-value-in-copy-name.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42313
- Description:
media: venus: fix use after free in vdec_close
- CVE: https://linux.oracle.com/cve/CVE-2024-42313.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42313-media-venus-fix-use-after-free-in-vdec-close.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42285
- Description:
RDMA/iwcm: Fix a use-after-free related to destroying CM IDs
- CVE: https://linux.oracle.com/cve/CVE-2024-42285.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42285-rdma-iwcm-fix-a-use-after-free-related-to-destroying-cm-ids.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43858
- Description:
jfs: Fix array-index-out-of-bounds in diFree
- CVE: https://linux.oracle.com/cve/CVE-2024-43858.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43858-jfs-fix-array-index-out-of-bounds-in-difree.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42284
- Description:
tipc: Return non-zero value from tipc_udp_addr2str() on error
- CVE: https://linux.oracle.com/cve/CVE-2024-42284.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42284-tipc-return-non-zero-value-from-tipc-udp-addr2str-on-error.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42280
- Description:
mISDN: Fix a use after free in hfcmulti_tx()
- CVE: https://linux.oracle.com/cve/CVE-2024-42280.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42280-misdn-fix-a-use-after-free-in-hfcmulti-tx.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42271
- Description:
net/iucv: fix use after free in iucv_sock_close()
- CVE: https://linux.oracle.com/cve/CVE-2024-42271.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42271-net-iucv-fix-use-after-free-in-iucv-sock-close.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43882
- Description:
exec: Fix ToCToU between perm check and set-uid/gid usage
- CVE: https://linux.oracle.com/cve/CVE-2024-43882.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43882-exec-fix-toctou-between-perm-check-and-set-uid-gid-usage.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-46738
- Description:
VMCI: Fix use-after-free when removing resource in vmci_resource_remove()
- CVE: https://linux.oracle.com/cve/CVE-2024-46738.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-46738-vmci-fix-use-after-free-when-removing-resource-in-vmci-resource-remove.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-41072
- Description:
wifi: cfg80211: wext: add extra SIOCSIWSCAN data check
- CVE: https://linux.oracle.com/cve/CVE-2024-41072.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-41072-wifi-cfg80211-wext-add-extra-siocsiwscan-data-check.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42297
- Description:
f2fs: fix to don't dirty inode for readonly filesystem
- CVE: https://linux.oracle.com/cve/CVE-2024-42297.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42297-f2fs-fix-to-don-t-dirty-inode-for-readonly-filesystem.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42292
- Description:
kobject_uevent: Fix OOB access within zap_modalias_env()
- CVE: https://linux.oracle.com/cve/CVE-2024-42292.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42292-kobject-uevent-fix-oob-access-within-zap-modalias-env.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43856
- Description:
dma: fix call order in dmam_free_coherent
- CVE: https://linux.oracle.com/cve/CVE-2024-43856.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43856-dma-fix-call-order-in-dmam-free-coherent.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42131
- Description:
mm: avoid overflows in dirty throttling logic
- CVE: https://linux.oracle.com/cve/CVE-2024-42131.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42131-mm-avoid-overflows-in-dirty-throttling-logic.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43867
- Description:
drm/nouveau: prime: fix refcount underflow
- CVE: https://linux.oracle.com/cve/CVE-2024-43867.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43867-drm-nouveau-prime-fix-refcount-underflow.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-44969
- Description:
s390 arch not supported.
- CVE:
- Patch: skipped/CVE-2024-44969.patch
- From:
- CVE-2024-43894
- Description:
drm/client: fix null pointer dereference in drm_client_modeset_probe
- CVE: https://linux.oracle.com/cve/CVE-2024-43894.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43894-drm-client-fix-null-pointer-dereference-in-drm-client-modeset-probe-2136.322.6.5.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43890
- Description:
tracing: Fix overflow in get_free_elt()
- CVE: https://linux.oracle.com/cve/CVE-2024-43890.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43890-tracing-fix-overflow-in-get-free-elt.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-44944
- Description:
netfilter: ctnetlink: use helper function to calculate expect ID
- CVE: https://linux.oracle.com/cve/CVE-2024-44944.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-44944-netfilter-ctnetlink-use-helper-function-to-calculate-expect-id.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42289
- Description:
scsi: qla2xxx: During vport delete send async logout explicitly
- CVE: https://linux.oracle.com/cve/CVE-2024-42289.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42289-scsi-qla2xxx-during-vport-delete-send-async-logout-explicitly.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43880
- Description:
mlxsw: spectrum_acl_erp: Fix object nesting warning
- CVE: https://linux.oracle.com/cve/CVE-2024-43880.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43880-mlxsw-spectrum-acl-erp-fix-object-nesting-warning.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43880
- Description:
mlxsw: spectrum_acl_erp: Fix object nesting warning
- CVE: https://linux.oracle.com/cve/CVE-2024-43880.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43880-mlxsw-spectrum-acl-erp-fix-object-nesting-warning-kpatch.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43846
- Description:
lib: objagg: Fix general protection fault
- CVE: https://linux.oracle.com/cve/CVE-2024-43846.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43846-lib-objagg-fix-general-protection-fault.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42265
- Description:
protect the fetch of ->fd[fd] in do_dup2() from mispredictions
- CVE: https://linux.oracle.com/cve/CVE-2024-42265.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42265-protect-the-fetch-of-fd-fd-in-do-dup2-from-mispredictions.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42283
- Description:
net: nexthop: Initialize all fields in dumped nexthops
- CVE: https://linux.oracle.com/cve/CVE-2024-42283.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42283-net-nexthop-initialize-all-fields-in-dumped-nexthops.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-41068
- Description:
Out of scope as the patch is for s390 arch only, x86_64 is not affected
- CVE:
- Patch: skipped/CVE-2024-41068.patch
- From:
- CVE-2024-43830
- Description:
leds: trigger: Unregister sysfs attributes before calling deactivate()
- CVE: https://linux.oracle.com/cve/CVE-2024-43830.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43830-leds-trigger-unregister-sysfs-attributes-before-calling-deactivate.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-41015
- Description:
ocfs2: add bounds checking to ocfs2_check_dir_entry()
- CVE: https://linux.oracle.com/cve/CVE-2024-41015.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-41015-ocfs2-add-bounds-checking-to-ocfs2-check-dir-entry.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42286
- Description:
scsi: qla2xxx: validate nvme_local_port correctly
- CVE: https://linux.oracle.com/cve/CVE-2024-42286.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42286-scsi-qla2xxx-validate-nvme-local-port-correctly.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42305
- Description:
ext4: check dot and dotdot of dx_root before making dir indexed
- CVE: https://linux.oracle.com/cve/CVE-2024-42305.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42305-ext4-check-dot-and-dotdot-of-dx-root-before-making-dir-indexed.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42308
- Description:
drm/amd/display: Check for NULL pointer
- CVE: https://linux.oracle.com/cve/CVE-2024-42308.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42308-drm-amd-display-check-for-null-pointer.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42309
- Description:
drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes
- CVE: https://linux.oracle.com/cve/CVE-2024-42309.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42309-drm-gma500-fix-null-pointer-dereference-in-psb-intel-lvds-get-modes.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43893
- Description:
serial: core: check uartclk for zero to avoid divide by zero
- CVE: https://linux.oracle.com/cve/CVE-2024-43893.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43893-serial-core-check-uartclk-for-zero-to-avoid-divide-by-zero.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43908
- Description:
drm/amdgpu: Fix the null pointer dereference to ras_manager
- CVE: https://linux.oracle.com/cve/CVE-2024-43908.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43908-drm-amdgpu-fix-the-null-pointer-dereference-to-ras-manager.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-44968
- Description:
This CVE was introduced and fixed in the same kernel verison
- CVE:
- Patch: skipped/CVE-2024-44968.patch
- From:
- CVE-2024-43871
- Description:
devres: Fix memory leakage caused by driver API devm_free_percpu()
- CVE: https://linux.oracle.com/cve/CVE-2024-43871.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43871-devres-fix-memory-leakage-caused-by-driver-api-devm-free-percpu.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43883
- Description:
usb: vhci-hcd: Do not drop references before new references are gained
- CVE: https://linux.oracle.com/cve/CVE-2024-43883.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43883-usb-vhci-hcd-do-not-drop-references-before-new-references-are-gained.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-44935
- Description:
sctp: Fix null-ptr-deref in reuseport_add_sock().
- CVE: https://linux.oracle.com/cve/CVE-2024-44935.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-44935-sctp-fix-null-ptr-deref-in-reuseport-add-sock.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-44948
- Description:
x86/mtrr: Check if fixed MTRRs exist before saving them
- CVE: https://linux.oracle.com/cve/CVE-2024-44948.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-44948-x86-mtrr-check-if-fixed-mtrrs-exist-before-saving-them.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42288
- Description:
scsi: qla2xxx: Fix for possible memory corruption
- CVE: https://linux.oracle.com/cve/CVE-2024-42288.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42288-scsi-qla2xxx-fix-for-possible-memory-corruption.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43829
- Description:
drm/qxl: Add check for drm_cvt_mode
- CVE: https://linux.oracle.com/cve/CVE-2024-43829.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43829-drm-qxl-add-check-for-drm-cvt-mode.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43861
- Description:
net: usb: qmi_wwan: fix memory leak for not ip packets
- CVE: https://linux.oracle.com/cve/CVE-2024-43861.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43861-net-usb-qmi-wwan-fix-memory-leak-for-not-ip-packets.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43914
- Description:
md/raid5: avoid BUG_ON() while continue reshape after reassembling
- CVE: https://linux.oracle.com/cve/CVE-2024-43914.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43914-md-raid5-avoid-bug-on-while-continue-reshape-after-reassembling.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-44960
- Description:
usb: gadget: core: Check for unset descriptor
- CVE: https://linux.oracle.com/cve/CVE-2024-44960.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-44960-usb-gadget-core-check-for-unset-descriptor.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-44965
- Description:
x86/mm: Fix pti_clone_pgtable() alignment assumption
- CVE: https://linux.oracle.com/cve/CVE-2024-44965.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-44965-x86-mm-fix-pti-clone-pgtable-alignment-assumption.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43860
- Description:
remoteproc: imx_rproc: Skip over memory region when node value is NULL
- CVE: https://linux.oracle.com/cve/CVE-2024-43860.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43860-remoteproc-imx-rproc-skip-over-memory-region-when-node-value-is-null-5.4.17-2136.335.4.1.el8uek.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42295
- Description:
nilfs2: handle inconsistent state in nilfs_btnode_create_block()
- CVE: https://linux.oracle.com/cve/CVE-2024-42295.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42295-nilfs2-handle-inconsistent-state-in-nilfs-btnode-create-block.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42304
- Description:
ext4: make sure the first directory block is not a hole
- CVE: https://linux.oracle.com/cve/CVE-2024-42304.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42304-ext4-make-sure-the-first-directory-block-is-not-a-hole-5.4.17-2136.309.5.1.el8uek.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-41017
- Description:
jfs: don't walk off the end of ealist
- CVE: https://linux.oracle.com/cve/CVE-2024-41017.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-41017-jfs-don-t-walk-off-the-end-of-ealist.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42310
- Description:
drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes
- CVE: https://linux.oracle.com/cve/CVE-2024-42310.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42310-drm-gma500-fix-null-pointer-dereference-in-cdv-intel-lvds-get-modes.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-41042
- Description:
netfilter: nf_tables: prefer nft_chain_validate
- CVE: https://linux.oracle.com/cve/CVE-2024-41042.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-41042-netfilter-nf-tables-prefer-nft-chain-validate.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42281
- Description:
bpf: Fix a segment issue when downgrading gso_size
- CVE: https://linux.oracle.com/cve/CVE-2024-42281.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42281-bpf-fix-a-segment-issue-when-downgrading-gso-size.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43879
- Description:
wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()
- CVE: https://linux.oracle.com/cve/CVE-2024-43879.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43879-wifi-cfg80211-handle-2x996-ru-allocation-in-cfg80211-calculate-bitrate-he.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43839
- Description:
bna: adjust 'name' buf size of bna_tcb and bna_ccb structures
- CVE: https://linux.oracle.com/cve/CVE-2024-43839.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43839-bna-adjust-name-buf-size-of-bna_tcb-and-bna_ccb-structures.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-41081
- Description:
ila: block BH in ila_output()
- CVE: https://linux.oracle.com/cve/CVE-2024-41081.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-41081-ila-block-bh-in-ila-output.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-41065
- Description:
CVE patch is for powerpc arch only
- CVE:
- Patch: skipped/CVE-2024-41065.patch
- From:
- CVE-2024-41064
- Description:
CVE patch is for powerpc arch only
- CVE:
- Patch: skipped/CVE-2024-41064.patch
- From:
- CVE-2024-41063
- Description:
Bluetooth: hci_core: cancel all works upon hci_unregister_dev()
- CVE: https://linux.oracle.com/cve/CVE-2024-41063.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-41063-bluetooth-hci-core-cancel-all-works-upon-hci-unregister-dev.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42311
- Description:
hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()
- CVE: https://linux.oracle.com/cve/CVE-2024-42311.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42311-hfs-fix-to-initialize-fields-of-hfs-inode-info-after-hfs-alloc-inode.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42276
- Description:
nvme-pci: add missing condition check for existence of mapped data
- CVE: https://linux.oracle.com/cve/CVE-2024-42276.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42276-nvme-pci-add-missing-condition-check-for-existence-of-mapped-data.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42259
- Description:
drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
- CVE: https://linux.oracle.com/cve/CVE-2024-42259.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42259-drm-i915-gem-fix-virtual-memory-mapping-boundaries-calculation.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43841
- Description:
wifi: virt_wifi: avoid reporting connection success with wrong SSID
- CVE: https://linux.oracle.com/cve/CVE-2024-43841.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43841-wifi-virt_wifi-avoid-reporting-connection-success-with-wrong-SSID-204.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-43841
- Description:
wifi: virt_wifi: avoid reporting connection success with wrong SSID
- CVE: https://linux.oracle.com/cve/CVE-2024-43841.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-43841-wifi-virt_wifi-avoid-reporting-connection-success-with-wrong-SSID-kpatch-204.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-42290
- Description:
irqchip/imx-irqsteer: Handle runtime power management correctly
- CVE: https://linux.oracle.com/cve/CVE-2024-42290.html
- Patch: oel8-uek6/5.4.17-2136.336.5.1.el8uek/CVE-2024-42290-irqchip-imx-irqsteer-handle-runtime-power-management-correctly.patch
- From: 5.4.17-2136.336.5.1.el8uek
- CVE-2024-47674
- Description:
mm: clarify a confusing comment for remap_pfn_range()
- CVE: https://linux.oracle.com/cve/CVE-2024-47674.html
- Patch: oel8-uek6/5.4.17-2136.336.5.3.1.el8uek/CVE-2024-47674-mm-clarify-a-confusing-comment-for-remap_pfn_range.patch
- From: 5.4.17-2136.336.5.3.1.el8uek
- CVE-2024-47674
- Description:
mm: fix ambiguous comments for better code readability
- CVE: https://linux.oracle.com/cve/CVE-2024-47674.html
- Patch: oel8-uek6/5.4.17-2136.336.5.3.1.el8uek/CVE-2024-47674-mm-fix-ambiguous-comments-for-better-code-readability.patch
- From: 5.4.17-2136.336.5.3.1.el8uek
- CVE-2024-47674
- Description:
mm/memory.c: make remap_pfn_range() reject unaligned addr
- CVE: https://linux.oracle.com/cve/CVE-2024-47674.html
- Patch: oel8-uek6/5.4.17-2136.336.5.3.1.el8uek/CVE-2024-47674-mm-memory.c-make-remap_pfn_range-reject-unaligned-addr.patch
- From: 5.4.17-2136.336.5.3.1.el8uek
- CVE-2024-47674
- Description:
mm: add remap_pfn_range_notrack
- CVE: https://linux.oracle.com/cve/CVE-2024-47674.html
- Patch: oel8-uek6/5.4.17-2136.336.5.3.1.el8uek/CVE-2024-47674-mm-add-remap_pfn_range_notrack.patch
- From: 5.4.17-2136.336.5.3.1.el8uek
- CVE-2024-47674
- Description:
mm: avoid leaving partial pfn mappings around in error case
- CVE: https://linux.oracle.com/cve/CVE-2024-47674.html
- Patch: oel8-uek6/5.4.17-2136.336.5.3.1.el8uek/CVE-2024-47674-mm-avoid-leaving-partial-pfn-mappings-around-in-error-case.patch
- From: 5.4.17-2136.336.5.3.1.el8uek
- CVE-2024-46740
- Description:
binder: fix UAF caused by offsets overwrite
- CVE: https://linux.oracle.com/cve/CVE-2024-46740.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46740-binder-fix-uaf-caused-by-offsets-overwrite-5.4.17-2136.315.5.8.el8uek.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-44998
- Description:
atm: idt77252: prevent use after free in dequeue_rx()
- CVE: https://linux.oracle.com/cve/CVE-2024-44998.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-44998-atm-idt77252-prevent-use-after-free-in-dequeue-rx.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-44999
- Description:
gtp: pull network headers in gtp_dev_xmit()
- CVE: https://linux.oracle.com/cve/CVE-2024-44999.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-44999-gtp-pull-network-headers-in-gtp-dev-xmit.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-42228
- Description:
drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc
- CVE: https://linux.oracle.com/cve/CVE-2024-42228.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-42228-drm-amdgpu-using-uninitialized-value-size-when-calling-amdgpu-vce-cs-reloc.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46674
- Description:
usb: dwc3: st: fix probed platform device ref count on probe error path
- CVE: https://linux.oracle.com/cve/CVE-2024-46674.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46674-usb-dwc3-st-fix-probed-platform-device-ref-count-on-probe-error-path.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46673
- Description:
scsi: aacraid: Fix double-free on probe failure
- CVE: https://linux.oracle.com/cve/CVE-2024-46673.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46673-scsi-aacraid-fix-double-free-on-probe-failure.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46818
- Description:
drm/amd/display: Check gpio_id before used as array index
- CVE: https://linux.oracle.com/cve/CVE-2024-46818.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46818-drm-amd-display-check-gpio-id-before-used-as-array-index.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46723
- Description:
drm/amdgpu: fix ucode out-of-bounds read warning
- CVE: https://linux.oracle.com/cve/CVE-2024-46723.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46723-drm-amdgpu-fix-ucode-out-of-bounds-read-warning.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46722
- Description:
drm/amdgpu: fix mc_data out-of-bounds read warning
- CVE: https://linux.oracle.com/cve/CVE-2024-46722.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46722-drm-amdgpu-fix-mc-data-out-of-bounds-read-warning.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46782
- Description:
ila: call nf_unregister_net_hooks() sooner
- CVE: https://linux.oracle.com/cve/CVE-2024-46782.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46782-ila-call-nf-unregister-net-hooks-sooner-kpatch.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46756
- Description:
hwmon: (w83627ehf) Fix underflows seen when writing limit attributes
- CVE: https://linux.oracle.com/cve/CVE-2024-46756.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46756-hwmon-w83627ehf-fix-underflows-seen-when-writing-limit-attributes.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46747
- Description:
HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
- CVE: https://linux.oracle.com/cve/CVE-2024-46747.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46747-hid-cougar-fix-slab-out-of-bounds-read-in-cougar-report-fixup.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46743
- Description:
of/irq: Prevent device address out-of-bounds read in interrupt map walk
- CVE: https://linux.oracle.com/cve/CVE-2024-46743.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46743-of-irq-prevent-device-address-out-of-bounds-read-in-interrupt-map-walk.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46781
- Description:
nilfs2 module is not included
- CVE:
- Patch: skipped/CVE-2024-46781.patch
- From:
- CVE-2024-44946
- Description:
module is not included
- CVE:
- Patch: skipped/CVE-2024-44946.patch
- From:
- CVE-2024-45026
- Description:
Architecture is not supported
- CVE:
- Patch: skipped/CVE-2024-45026.patch
- From:
- CVE-2024-46844
- Description:
Architecture um is not supported
- CVE:
- Patch: skipped/CVE-2024-46844.patch
- From:
- CVE-2024-46781
- Description:
nilfs2: fix missing cleanup on rollforward recovery error
- CVE: https://linux.oracle.com/cve/CVE-2024-46781.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46781-Add-BUILD_BUD_ON-for-nilfs-module.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-44946
- Description:
kcm: Serialise kcm_sendmsg() for the same socket.
- CVE: https://linux.oracle.com/cve/CVE-2024-44946.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-44946-Add-BUILD_BUG_ON-for-kcm-module.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-44988
- Description:
net: dsa: mv88e6xxx: Fix out-of-bound access
- CVE: https://linux.oracle.com/cve/CVE-2024-44988.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-44988-net-dsa-mv88e6xxx-fix-out-of-bound-access.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46675
- Description:
usb: dwc3: core: Prevent USB core invalid event buffer address access
- CVE: https://linux.oracle.com/cve/CVE-2024-46675.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46675-usb-dwc3-core-prevent-usb-core-invalid-event-buffer-address-access.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-43853
- Description:
cgroup/cpuset: Prevent UAF in proc_cpuset_show()
- CVE: https://linux.oracle.com/cve/CVE-2024-43853.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-43853-cgroup-cpuset-prevent-uaf-in-proc-cpuset-show.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-45008
- Description:
Input: MT - limit max slots
- CVE: https://linux.oracle.com/cve/CVE-2024-45008.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-45008-input-mt-limit-max-slots.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-45025
- Description:
fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
- CVE: https://linux.oracle.com/cve/CVE-2024-45025.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-45025-fix-bitmap-corruption-on-close-range-with-close-range-unshare.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46714
- Description:
drm/amd/display: Skip wbscl_set_scaler_filter if filter is null
- CVE: https://linux.oracle.com/cve/CVE-2024-46714.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46714-drm-amd-display-skip-wbscl-set-scaler-filter-if-filter-is-null.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46719
- Description:
usb: typec: ucsi: Fix null pointer dereference in trace
- CVE: https://linux.oracle.com/cve/CVE-2024-46719.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46719-usb-typec-ucsi-fix-null-pointer-dereference-in-trace.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-47667
- Description:
PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)
- CVE: https://linux.oracle.com/cve/CVE-2024-47667.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-47667-pci-keystone-add-workaround-for-errata-i2037-am65x-sr-1-0.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-44987
- Description:
ipv6: prevent UAF in ip6_send_skb()
- CVE: https://linux.oracle.com/cve/CVE-2024-44987.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-44987-ipv6-prevent-uaf-in-ip6-send-skb.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-41011
- Description:
drm/amdkfd: don't allow mapping the MMIO HDP page with large pages
- CVE: https://linux.oracle.com/cve/CVE-2024-41011.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-41011-drm-amdkfd-don-t-allow-mapping-the-mmio-hdp-page-with-large-pages.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46800
- Description:
sch/netem: fix use after free in netem_dequeue
- CVE: https://linux.oracle.com/cve/CVE-2024-46800.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46800-sch-netem-fix-use-after-free-in-netem-dequeue.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46798
- Description:
ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object
- CVE: https://linux.oracle.com/cve/CVE-2024-46798.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46798-asoc-dapm-fix-uaf-for-snd-soc-pcm-runtime-object.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46759
- Description:
hwmon: (adc128d818) Fix underflows seen when writing limit attributes
- CVE: https://linux.oracle.com/cve/CVE-2024-46759.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46759-hwmon-adc128d818-fix-underflows-seen-when-writing-limit-attributes.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46758
- Description:
hwmon: (lm95234) Fix underflows seen when writing limit attributes
- CVE: https://linux.oracle.com/cve/CVE-2024-46758.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46758-hwmon-lm95234-fix-underflows-seen-when-writing-limit-attributes.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46757
- Description:
hwmon: (nct6775-core) Fix underflows seen when writing limit attributes
- CVE: https://linux.oracle.com/cve/CVE-2024-46757.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46757-hwmon-nct6775-core-fix-underflows-seen-when-writing-limit-attributes.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46744
- Description:
Squashfs: sanity check symbolic link size
- CVE: https://linux.oracle.com/cve/CVE-2024-46744.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46744-squashfs-sanity-check-symbolic-link-size.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46828
- Description:
sched: sch_cake: fix bulk flow accounting logic for host fairness
- CVE: https://linux.oracle.com/cve/CVE-2024-46828.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46828-sched-sch-cake-fix-bulk-flow-accounting-logic-for-host-fairness.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-45006
- Description:
xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration
- CVE: https://linux.oracle.com/cve/CVE-2024-45006.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-45006-xhci-fix-panther-point-null-pointer-deref-at-full-speed-re-enumeration-5.4.17-2136.307.3.6.el8uek.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-45016
- Description:
netem: fix return value if duplicate enqueue fails
- CVE: https://linux.oracle.com/cve/CVE-2024-45016.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-45016-netem-fix-return-value-if-duplicate-enqueue-fails.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46817
- Description:
drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6
- CVE: https://linux.oracle.com/cve/CVE-2024-46817.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46817-drm-amd-display-stop-amdgpu-dm-initialize-when-stream-nums-greater-than-6.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46815
- Description:
drm/amd/display: Check num_valid_sets before accessing reader_wm_sets[]
- CVE: https://linux.oracle.com/cve/CVE-2024-46815.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46815-drm-amd-display-check-num-valid-sets-before-accessing-reader-wm-sets.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-43854
- Description:
block: initialize integrity buffer to zero before writing it to media
- CVE: https://linux.oracle.com/cve/CVE-2024-43854.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-43854-block-initialize-integrity-buffer-to-zero-before-writing-it-to-media.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46783
- Description:
tcp_bpf: fix return value of tcp_bpf_sendmsg()
- CVE: https://linux.oracle.com/cve/CVE-2024-46783.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46783-tcp-bpf-fix-return-value-of-tcp-bpf-sendmsg.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46840
- Description:
btrfs: clean up our handling of refs == 0 in snapshot delete
- CVE: https://linux.oracle.com/cve/CVE-2024-46840.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46840-btrfs-clean-up-our-handling-of-refs-0-in-snapshot-delete.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-47668
- Description:
lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc()
- CVE: https://linux.oracle.com/cve/CVE-2024-47668.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-47668-lib-generic-radix-tree-c-fix-rare-race-in-genradix-ptr-alloc.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-47663
- Description:
staging: iio: frequency: ad9834: Validate frequency parameter value
- CVE: https://linux.oracle.com/cve/CVE-2024-47663.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-47663-staging-iio-frequency-ad9834-validate-frequency-parameter-value.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46679
- Description:
ethtool: check device is present when getting link settings
- CVE: https://linux.oracle.com/cve/CVE-2024-46679.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46679-ethtool-check-device-is-present-when-getting-link-settings-206.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46755
- Description:
wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
- CVE: https://linux.oracle.com/cve/CVE-2024-46755.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46755-wifi-mwifiex-do-not-return-unused-priv-in-mwifiex-get-priv-by-id.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46822
- Description:
arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry
- CVE: https://linux.oracle.com/cve/CVE-2024-46822.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46822-arm64-acpi-harden-get-cpu-for-acpi-id-against-missing-cpu-entry.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-49958
- Description:
ocfs2: reserve space for inline xattr before attaching reflink tree
- CVE: https://linux.oracle.com/cve/CVE-2024-49958.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-49958-ocfs2-reserve-space-for-inline-xattr-before-attaching-reflink-tree.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-43884
- Description:
Bluetooth: MGMT: Add error handling to pair_device()
- CVE: https://linux.oracle.com/cve/CVE-2024-43884.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-43884-bluetooth-mgmt-add-error-handling-to-pair-device.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-41098
- Description:
ata: libata-core: Fix null pointer dereference on error
- CVE: https://linux.oracle.com/cve/CVE-2024-41098.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-41098-ata-libata-core-fix-null-pointer-dereference-on-error.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-43835
- Description:
virtio_net: Fix napi_skb_cache_put warning
- CVE: https://linux.oracle.com/cve/CVE-2024-43835.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-43835-virtio-net-fix-napi-skb-cache-put-warning-204.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2023-31083
- Description:
Bluetooth: hci_ldisc: check HCI_UART_PROTO_READY flag in HCIUARTGETPROTO
- CVE: https://linux.oracle.com/cve/CVE-2023-31083.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2023-31083-bluetooth-hci_ldisc-check-HCI_UART_PROTO_READY-flag-in-HCIUARTGETPROTO.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-45028
- Description:
mmc: mmc_test: Fix NULL dereference on allocation failure
- CVE: https://linux.oracle.com/cve/CVE-2024-45028.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-45028-mmc-mmc-test-fix-null-dereference-on-allocation-failure.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46677
- Description:
gtp: fix a potential NULL pointer dereference
- CVE: https://linux.oracle.com/cve/CVE-2024-46677.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46677-gtp-fix-a-potential-null-pointer-dereference.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46685
- Description:
pinctrl: single: fix potential NULL dereference in pcs_get_function()
- CVE: https://linux.oracle.com/cve/CVE-2024-46685.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46685-pinctrl-single-fix-potential-null-dereference-in-pcs-get-function.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46739
- Description:
uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind
- CVE: https://linux.oracle.com/cve/CVE-2024-46739.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46739-uio-hv-generic-fix-kernel-null-pointer-dereference-in-hv-uio-rescind.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46745
- Description:
Input: uinput - reject requests with unreasonable number of slots
- CVE: https://linux.oracle.com/cve/CVE-2024-46745.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46745-input-uinput-reject-requests-with-unreasonable-number-of-slots.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46750
- Description:
Complex adaptation required. Low impact CVE.
- CVE:
- Patch: skipped/CVE-2024-46750.patch
- From:
- CVE-2024-46761
- Description:
Out of scope: CVE patch is for PCI Hotplug Driver for PowerPC PowerNV platform
- CVE:
- Patch: skipped/CVE-2024-46761.patch
- From:
- CVE-2024-46771
- Description:
can: bcm: Remove proc entry when dev is unregistered.
- CVE: https://linux.oracle.com/cve/CVE-2024-46771.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46771-can-bcm-remove-proc-entry-when-dev-is-unregistered.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46829
- Description:
rtmutex: Drop rt_mutex::wait_lock before scheduling
- CVE: https://linux.oracle.com/cve/CVE-2024-46829.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46829-rtmutex-Drop-rt_mutex-wait_lock-before-scheduling.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-45003
- Description:
vfs: Don't evict inode under the inode lru traversing context
- CVE: https://linux.oracle.com/cve/CVE-2024-45003.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-45003-vfs-don-t-evict-inode-under-the-inode-lru-traversing-context.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46676
- Description:
nfc: pn533: Add poll mod list filling check
- CVE: https://linux.oracle.com/cve/CVE-2024-46676.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46676-nfc-pn533-add-poll-mod-list-filling-check.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46780
- Description:
nilfs2: protect references to superblock parameters exposed in sysfs
- CVE: https://linux.oracle.com/cve/CVE-2024-46780.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46780-nilfs2-protect-references-to-superblock-parameters-exposed-in-sysfs.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-44947
- Description:
fuse: Initialize beyond-EOF page contents before setting uptodate
- CVE: https://linux.oracle.com/cve/CVE-2024-44947.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-44947-fuse-initialize-beyond-eof-page-contents-before-setting-uptodate.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-45021
- Description:
Patches a function that is sleepable due to a call to vfs_poll
- CVE:
- Patch: skipped/CVE-2024-45021.patch
- From:
- CVE-2024-44995
- Description:
net: hns3: fix a deadlock problem when config TC during resetting
- CVE: https://linux.oracle.com/cve/CVE-2024-44995.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-44995-net-hns3-fix-a-deadlock-problem-when-config-tc-during-resetting.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46721
- Description:
apparmor: fix possible NULL pointer dereference
- CVE: https://linux.oracle.com/cve/CVE-2024-46721.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46721-apparmor-fix-possible-null-pointer-dereference.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-47669
- Description:
nilfs2: fix state management in error path of log writing function
- CVE: https://linux.oracle.com/cve/CVE-2024-47669.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-47669-nilfs2-fix-state-management-in-error-path-of-log-writing-function.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46777
- Description:
udf: Avoid excessive partition lengths
- CVE: https://linux.oracle.com/cve/CVE-2024-46777.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46777-udf-avoid-excessive-partition-lengths.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-46737
- Description:
nvmet-tcp: fix kernel crash if commands allocation fails
- CVE: https://linux.oracle.com/cve/CVE-2024-46737.html
- Patch: oel8-uek6/5.4.17-2136.337.5.el8uek/CVE-2024-46737-nvmet-tcp-fix-kernel-crash-if-commands-allocation-fails.patch
- From: 5.4.17-2136.337.5.el8uek
- CVE-2024-26885
- Description:
bpf: Fix DEVMAP_HASH overflow check on 32-bit arches
- CVE: https://linux.oracle.com/cve/CVE-2024-26885.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-26885-bpf-fix-devmap-hash-overflow-check-on-32-bit-arches.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47685
- Description:
netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put()
- CVE: https://linux.oracle.com/cve/CVE-2024-47685.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47685-netfilter-nf-reject-ipv6-fix-nf-reject-ip6-tcphdr-put.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-46849
- Description:
ASoC: meson: axg-card: fix 'use-after-free'
- CVE: https://linux.oracle.com/cve/CVE-2024-46849.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-46849-asoc-meson-axg-card-fix-use-after-free-5.4.17-2011.7.4.el8uek.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49995
- Description:
tipc: guard against string buffer overrun
- CVE: https://linux.oracle.com/cve/CVE-2024-49995.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49995-tipc-guard-against-string-buffer-overrun.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49924
- Description:
fbdev: pxafb: Fix possible use after free in pxafb_task()
- CVE: https://linux.oracle.com/cve/CVE-2024-49924.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49924-fbdev-pxafb-fix-possible-use-after-free-in-pxafb-task.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49882
- Description:
ext4: fix double brelse() the buffer of the extents path
- CVE: https://linux.oracle.com/cve/CVE-2024-49882.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49882-ext4-fix-double-brelse-the-buffer-of-the-extents-path.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50074
- Description:
parport: Proper fix for array out-of-bounds access
- CVE: https://linux.oracle.com/cve/CVE-2024-50074.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50074-parport-proper-fix-for-array-out-of-bounds-access-5.4.17-2136.335.4.1.el8uek.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50262
- Description:
bpf: Fix out-of-bounds write in trie_get_next_key()
- CVE: https://linux.oracle.com/cve/CVE-2024-50262.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50262-bpf-fix-out-of-bounds-write-in-trie-get-next-key.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49894
- Description:
drm/amd/display: Fix index out of bounds in degamma hardware format translation
- CVE: https://linux.oracle.com/cve/CVE-2024-49894.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49894-drm-amd-display-fix-index-out-of-bounds-in-degamma-hardware-format-translation.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47701
- Description:
ext4: avoid OOB when system.data xattr changes underneath the filesystem
- CVE: https://linux.oracle.com/cve/CVE-2024-47701.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47701-ext4-avoid-oob-when-system-data-xattr-changes-underneath-the-filesystem.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47742
- Description:
firmware_loader: Block path traversal
- CVE: https://linux.oracle.com/cve/CVE-2024-47742.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47742-firmware-loader-block-path-traversal-5.4.17-2102.204.4.4.el8uek.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49967
- Description:
ext4: no need to continue when the number of entries is 1
- CVE: https://linux.oracle.com/cve/CVE-2024-49967.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49967-ext4-no-need-to-continue-when-the-number-of-entries-is-1.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49883
- Description:
ext4: aovid use-after-free in ext4_ext_insert_extent()
- CVE: https://linux.oracle.com/cve/CVE-2024-49883.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49883-ext4-aovid-use-after-free-in-ext4-ext-insert-extent.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50180
- Description:
fbdev: sisfb: Fix strbuf array overflow
- CVE: https://linux.oracle.com/cve/CVE-2024-50180.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50180-fbdev-sisfb-fix-strbuf-array-overflow.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50143
- Description:
udf: fix uninit-value use in udf_get_fileshortad
- CVE: https://linux.oracle.com/cve/CVE-2024-50143.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50143-udf-fix-uninit-value-use-in-udf-get-fileshortad.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50131
- Description:
tracing: Consider the NULL character when validating the event length
- CVE: https://linux.oracle.com/cve/CVE-2024-50131.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50131-tracing-consider-the-null-character-when-validating-the-event-length.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-46853
- Description:
spi: nxp-fspi: fix the KASAN report out-of-bounds bug
- CVE: https://linux.oracle.com/cve/CVE-2024-46853.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-46853-spi-nxp-fspi-fix-the-kasan-report-out-of-bounds-bug.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50127
- Description:
net: sched: fix use-after-free in taprio_change()
- CVE: https://linux.oracle.com/cve/CVE-2024-50127.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50127-net-sched-fix-use-after-free-in-taprio-change.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47670
- Description:
ocfs2: add bounds checking to ocfs2_xattr_find_entry()
- CVE: https://linux.oracle.com/cve/CVE-2024-47670.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47670-ocfs2-add-bounds-checking-to-ocfs2-xattr-find-entry.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47698
- Description:
drivers: media: dvb-frontends/rtl2832: fix an out-of-bounds write error
- CVE: https://linux.oracle.com/cve/CVE-2024-47698.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47698-drivers-media-dvb-frontends-rtl2832-fix-an-out-of-bounds-write-error.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47697
- Description:
drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds write error
- CVE: https://linux.oracle.com/cve/CVE-2024-47697.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47697-drivers-media-dvb-frontends-rtl2830-fix-an-out-of-bounds-write-error.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50007
- Description:
ALSA: asihpi: Fix potential OOB array access
- CVE: https://linux.oracle.com/cve/CVE-2024-50007.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50007-alsa-asihpi-fix-potential-oob-array-access.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49966
- Description:
ocfs2: cancel dqi_sync_work before freeing oinfo
- CVE: https://linux.oracle.com/cve/CVE-2024-49966.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49966-ocfs2-cancel-dqi-sync-work-before-freeing-oinfo.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50151
- Description:
smb: client: fix OOBs when building SMB2_IOCTL request
- CVE: https://linux.oracle.com/cve/CVE-2024-50151.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50151-smb-client-fix-oobs-when-building-smb2-ioctl-request.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-53059
- Description:
wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd()
- CVE: https://linux.oracle.com/cve/CVE-2024-53059.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-53059-wifi-iwlwifi-mvm-fix-response-handling-in-iwl-mvm-send-recovery-cmd.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-53057
- Description:
net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT
- CVE: https://linux.oracle.com/cve/CVE-2024-53057.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-53057-net-sched-stop-qdisc-tree-reduce-backlog-on-tc-h-root.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50230
- Description:
nilfs2: fix kernel bug due to missing clearing of checked flag
- CVE: https://linux.oracle.com/cve/CVE-2024-50230.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50230-nilfs2-fix-kernel-bug-due-to-missing-clearing-of-checked-flag.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49997
- Description:
net: ethernet: lantiq_etop: fix memory disclosure
- CVE: https://linux.oracle.com/cve/CVE-2024-49997.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49997-net-ethernet-lantiq-etop-fix-memory-disclosure-5.4.17-2136.314.6.3.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47723
- Description:
jfs: fix divide error in dbNextAG
- CVE: https://linux.oracle.com/cve/CVE-2024-47723.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47723-jfs-fix-divide-error-in-dbNextAG.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47723
- Description:
jfs: fix out-of-bounds in dbNextAG() and diAlloc()
- CVE: https://linux.oracle.com/cve/CVE-2024-47723.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47723-jfs-fix-out-of-bounds-in-dbnextag-and-dialloc-5.4.17-2136.316.7.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49900
- Description:
jfs: Fix uninit-value access of new_ea in ea_buffer
- CVE: https://linux.oracle.com/cve/CVE-2024-49900.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49900-jfs-fix-uninit-value-access-of-new-ea-in-ea-buffer.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49860
- Description:
ACPI: sysfs: validate return type of _STR method
- CVE: https://linux.oracle.com/cve/CVE-2024-49860.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49860-acpi-sysfs-validate-return-type-of-str-method.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50033
- Description:
slip: make slhc_remember() more robust against malicious packets
- CVE: https://linux.oracle.com/cve/CVE-2024-50033.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50033-slip-make-slhc-remember-more-robust-against-malicious-packets.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50035
- Description:
ppp: fix ppp_async_encode() illegal access
- CVE: https://linux.oracle.com/cve/CVE-2024-50035.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50035-ppp-fix-ppp-async-encode-illegal-access.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47757
- Description:
nilfs2: fix potential oob read in nilfs_btree_check_delete()
- CVE: https://linux.oracle.com/cve/CVE-2024-47757.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47757-nilfs2-fix-potential-oob-read-in-nilfs-btree-check-delete.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-46854
- Description:
net: dpaa: Pad packets to ETH_ZLEN
- CVE: https://linux.oracle.com/cve/CVE-2024-46854.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-46854-net-dpaa-pad-packets-to-eth-zlen.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50234
- Description:
wifi: iwlegacy: Clear stale interrupts before resuming device
- CVE: https://linux.oracle.com/cve/CVE-2024-50234.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50234-wifi-iwlegacy-clear-stale-interrupts-before-resuming-device.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49981
- Description:
media: venus: fix use after free bug in venus_remove due to race condition
- CVE: https://linux.oracle.com/cve/CVE-2024-49981.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49981-media-venus-fix-use-after-free-bug-in-venus-remove-due-to-race-condition.patch
- From: 5.4.17-2136.338.4.1.el7uek
- CVE-2024-50228
- Description:
Vendor reverted in d1aa0c04294 as it causes deadlocks
- CVE:
- Patch: skipped/CVE-2024-50228.patch
- From:
- CVE-2024-49903
- Description:
jfs: Fix uaf in dbFreeBits
- CVE: https://linux.oracle.com/cve/CVE-2024-49903.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49903-jfs-fix-uaf-in-dbfreebits.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50059
- Description:
ntb: ntb_hw_switchtec: Fix use after free vulnerability in switchtec_ntb_remove due to race condition
- CVE: https://linux.oracle.com/cve/CVE-2024-50059.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50059-ntb-ntb-hw-switchtec-fix-use-after-free-vulnerability-in-switchtec-ntb-remove-due-to-race-condition.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47747
- Description:
net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition
- CVE: https://linux.oracle.com/cve/CVE-2024-47747.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47747-net-seeq-fix-use-after-free-vulnerability-in-ether3-driver-due-to-race-condition.patch
- From: 5.4.17-2136.338.4.1.el7uek
- CVE-2023-6270 CVE-2024-26898
- Description:
aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2023-6270
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2023-6270-CVE-2024-26898-aoe-fix-the-potential-use-after-free-problem-in-aoecmd_cfg_pkts.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49982
- Description:
aoe: fix the potential use-after-free problem in more places
- CVE: https://linux.oracle.com/cve/CVE-2024-49982.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49982-aoe-fix-the-potential-use-after-free-problem-in-more-places.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47696
- Description:
RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency
- CVE: https://linux.oracle.com/cve/CVE-2024-47696.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47696-rdma-iwcm-fix-warning-at_kernel-workqueue.c-check_flush_dependency-5.4.17-2136.301.1.4.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47696
- Description:
RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency kpatch
- CVE: https://linux.oracle.com/cve/CVE-2024-47696.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47696-rdma-iwcm-fix-warning-at_kernel-workqueue.c-check_flush_dependency-kpatch-5.4.17-2136.301.1.4.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47692
- Description:
nfsd: return -EINVAL when namelen is 0
- CVE: https://linux.oracle.com/cve/CVE-2024-47692.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47692-nfsd-return-einval-when-namelen-is-0.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47692
- Description:
nfsd: enforce upper limit for namelen in __cld_pipe_inprogress_downcall()
- CVE: https://linux.oracle.com/cve/CVE-2024-47692.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47692-nfsd-enforce-upper-limit-for-namelen-in-__cld_pipe_inprogress_downcall.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50251
- Description:
netfilter: nft_payload: sanitize offset and length before calling skb_checksum()
- CVE: https://linux.oracle.com/cve/CVE-2024-50251.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50251-netfilter-nft-payload-sanitize-offset-and-length-before-calling-skb-checksum.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-44931
- Description:
gpio: prevent potential speculation leaks in gpio_device_get_desc()
- CVE: https://linux.oracle.com/cve/CVE-2024-44931.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-44931-gpio-prevent-potential-speculation-leaks-in-gpio-device-get-desc.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47709
- Description:
can: bcm: Clear bo->bcm_proc_read after remove_proc_entry().
- CVE: https://linux.oracle.com/cve/CVE-2024-47709.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47709-can-bcm-clear-bo-bcm-proc-read-after-remove-proc-entry.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47737
- Description:
nfsd: call cache_put if xdr_reserve_space returns NULL
- CVE: https://linux.oracle.com/cve/CVE-2024-47737.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47737-nfsd-call-cache-put-if-xdr-reserve-space-returns-null.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49985
- Description:
i2c: stm32f7: Do not prepare/unprepare clock during runtime suspend/resume
- CVE: https://linux.oracle.com/cve/CVE-2024-49985.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49985-i2c-stm32f7-do-not-prepare-unprepare-clock-during-runtime-suspend-resume.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50117
- Description:
drm/amd: Guard against bad data for ATIF ACPI method
- CVE: https://linux.oracle.com/cve/CVE-2024-50117.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50117-drm-amd-guard-against-bad-data-for-atif-acpi-method.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50117
- Description:
drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported
- CVE: https://linux.oracle.com/cve/CVE-2024-50117.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50117-drm-amdgpu-prevent-NULL-pointer-dereference-if-ATIF-is-not-supported.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49877
- Description:
ocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate
- CVE: https://linux.oracle.com/cve/CVE-2024-49877.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49877-ocfs2-fix-possible-null-ptr-deref-in-ocfs2-set-buffer-uptodate.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49957
- Description:
ocfs2: fix null-ptr-deref when journal load failed.
- CVE: https://linux.oracle.com/cve/CVE-2024-49957.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49957-ocfs2-fix-null-ptr-deref-when-journal-load-failed.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50006
- Description:
ext4: fix i_data_sem unlock order in ext4_ind_migrate()
- CVE: https://linux.oracle.com/cve/CVE-2024-50006.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50006-ext4-fix-i-data-sem-unlock-order-in-ext4-ind-migrate-5.4.17-2011.7.4.el8uek.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-41016
- Description:
ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()
- CVE: https://linux.oracle.com/cve/CVE-2024-41016.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-41016-ocfs2-strict-bound-check-before-memcmp-in-ocfs2-xattr-find-entry.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47749
- Description:
RDMA/cxgb4: Added NULL check for lookup_atid
- CVE: https://linux.oracle.com/cve/CVE-2024-47749.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47749-rdma-cxgb4-added-null-check-for-lookup-atid.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49878
- Description:
resource: fix region_intersects() vs add_memory_driver_managed()
- CVE: https://linux.oracle.com/cve/CVE-2024-49878.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49878-resource-fix-region-intersects-vs-add-memory-driver-managed.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49879
- Description:
drm: omapdrm: Add missing check for alloc_ordered_workqueue
- CVE: https://linux.oracle.com/cve/CVE-2024-49879.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49879-drm-omapdrm-add-missing-check-for-alloc-ordered-workqueue.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49938
- Description:
wifi: ath9k_htc: Use __skb_set_length() for resetting urb before resubmit
- CVE: https://linux.oracle.com/cve/CVE-2024-49938.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49938-wifi-ath9k-htc-use-skb-set-length-for-resetting-urb-before-resubmit-5.4.17-2136.316.7.el8uek.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49952
- Description:
netfilter: nf_tables: prevent nf_skb_duplicated corruption
- CVE: https://linux.oracle.com/cve/CVE-2024-49952.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49952-netfilter-nf-tables-prevent-nf-skb-duplicated-corruption.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50008
- Description:
wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()
- CVE: https://linux.oracle.com/cve/CVE-2024-50008.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50008-wifi-mwifiex-fix-memcpy-field-spanning-write-warning-in-mwifiex-cmd-802-11-scan-ext.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50218
- Description:
ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow
- CVE: https://linux.oracle.com/cve/CVE-2024-50218.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50218-ocfs2-pass-u64-to-ocfs2-truncate-inline-maybe-overflow.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50233
- Description:
staging: iio: frequency: ad9832: fix division by zero in ad9832_calc_freqreg()
- CVE: https://linux.oracle.com/cve/CVE-2024-50233.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50233-staging-iio-frequency-ad9832-fix-division-by-zero-in-ad9832-calc-freqreg.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50167
- Description:
be2net: fix potential memory leak in be_xmit()
- CVE: https://linux.oracle.com/cve/CVE-2024-50167.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50167-be2net-fix-potential-memory-leak-in-be-xmit.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50171
- Description:
net: systemport: fix potential memory leak in bcm_sysport_xmit()
- CVE: https://linux.oracle.com/cve/CVE-2024-50171.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50171-net-systemport-fix-potential-memory-leak-in-bcm-sysport-xmit.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50195
- Description:
posix-clock: Fix missing timespec64 check in pc_clock_settime()
- CVE: https://linux.oracle.com/cve/CVE-2024-50195.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50195-posix-clock-Fix-missing-timespec64-check-in-pc_clock_settime.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50210
- Description:
posix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()
- CVE: https://linux.oracle.com/cve/CVE-2024-50210.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50210-posix-clock-posix-clock-fix-unbalanced-locking-in-pc-clock-settime.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-26921
- Description:
Live-patching will introduce network performance degradation in the best case scenario, or even some more serious issues. N/A or Low cvss3 score from NVD or vendors.
- CVE:
- Patch: skipped/CVE-2024-26921.patch
- From:
- CVE-2024-49867
- Description:
Btrfs: fix crash during unmount due to race with delayed inode workers
- CVE: https://linux.oracle.com/cve/CVE-2024-49867.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49867-Btrfs-fix-crash-during-unmount-due-to-race-with-delayed-inode-workers.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49867
- Description:
btrfs: wait for fixup workers before stopping cleaner kthread during umount
- CVE: https://linux.oracle.com/cve/CVE-2024-49867.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49867-btrfs-wait-for-fixup-workers-before-stopping-cleaner-kthread-during-umount.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50082
- Description:
blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race
- CVE: https://linux.oracle.com/cve/CVE-2024-50082.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50082-blk-rq-qos-fix-crash-on-rq-qos-wait-vs-rq-qos-wake-function-race-5.4.17-2136.321.4.1.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50142
- Description:
xfrm: validate new SA's prefixlen using SA family when sel.family is unset
- CVE: https://linux.oracle.com/cve/CVE-2024-50142.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50142-xfrm-validate-new-sa-s-prefixlen-using-sa-family-when-sel-family-is-unset.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50229
- Description:
nilfs2: fix potential deadlock with newly created symlinks
- CVE: https://linux.oracle.com/cve/CVE-2024-50229.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50229-nilfs2-fix-potential-deadlock-with-newly-created-symlinks.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50039
- Description:
net/sched: accept TCA_STAB only for root qdisc
- CVE: https://linux.oracle.com/cve/CVE-2024-50039.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50039-net-sched-accept-tca-stab-only-for-root-qdisc.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50039
- Description:
net/sched: accept TCA_STAB only for root qdisc
- CVE: https://linux.oracle.com/cve/CVE-2024-50039.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50039-net-sched-accept-tca-stab-only-for-root-qdisc-kpatch.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47672
- Description:
wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead
- CVE: https://linux.oracle.com/cve/CVE-2024-47672.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47672-wifi-iwlwifi-mvm-don-t-wait-for-tx-queues-if-firmware-is-dead.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49851
- Description:
tpm: Clean up TPM space after command failure
- CVE: https://linux.oracle.com/cve/CVE-2024-49851.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49851-tpm-clean-up-tpm-space-after-command-failure.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47756
- Description:
PCI: keystone: Fix if-statement expression in ks_pcie_quirk()
- CVE: https://linux.oracle.com/cve/CVE-2024-47756.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47756-pci-keystone-fix-if-statement-expression-in-ks-pcie-quirk.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50179
- Description:
ceph: remove the incorrect Fw reference check when dirtying pages
- CVE: https://linux.oracle.com/cve/CVE-2024-50179.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50179-ceph-remove-the-incorrect-fw-reference-check-when-dirtying-pages.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49948
- Description:
net: add more sanity checks to qdisc_pkt_len_init()
- CVE: https://linux.oracle.com/cve/CVE-2024-49948.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49948-net-add-more-sanity-checks-to-qdisc-pkt-len-init.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2023-52799
- Description:
jfs: fix array-index-out-of-bounds in dbFindLeaf
- CVE: https://nvd.nist.gov/vuln/detail/cve-2023-52799
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2023-52799-jfs-fix-array-index-out-of-bounds-in-dbFindLeaf-323.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49902
- Description:
jfs: check if leafidx greater than num leaves per dmap tree
- CVE: https://linux.oracle.com/cve/CVE-2024-49902.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49902-jfs-check-if-leafidx-greater-than-num-leaves-per-dmap-tree.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49965
- Description:
ocfs2: remove unreasonable unlock in ocfs2_read_blocks
- CVE: https://linux.oracle.com/cve/CVE-2024-49965.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49965-ocfs2-remove-unreasonable-unlock-in-ocfs2-read-blocks.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50199
- Description:
mm/swapfile: skip HugeTLB pages for unuse_vma
- CVE: https://linux.oracle.com/cve/CVE-2024-50199.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50199-mm-swapfile-skip-hugetlb-pages-for-unuse-vma.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49896
- Description:
drm/amd/display: Check stream before comparing them
- CVE: https://linux.oracle.com/cve/CVE-2024-49896.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49896-drm-amd-display-check-stream-before-comparing-them.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50202
- Description:
nilfs2: propagate directory read errors from nilfs_find_entry()
- CVE: https://linux.oracle.com/cve/CVE-2024-50202.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50202-nilfs2-propagate-directory-read-errors-from-nilfs-find-entry-5.4.17-2136.334.6.1.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47699
- Description:
nilfs2: fix potential null-ptr-deref in nilfs_btree_insert()
- CVE: https://linux.oracle.com/cve/CVE-2024-47699.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47699-nilfs2-fix-potential-null-ptr-deref-in-nilfs-btree-insert-5.4.17-2136.331.7.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49962
- Description:
ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package()
- CVE: https://linux.oracle.com/cve/CVE-2024-49962.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49962-acpica-check-null-return-of-acpi-allocate-zeroed-in-acpi-db-convert-to-package.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49955
- Description:
ACPI: battery: Fix possible crash when unregistering a battery hook
- CVE: https://linux.oracle.com/cve/CVE-2024-49955.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49955-acpi-battery-fix-possible-crash-when-unregistering-a-battery-hook.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50045
- Description:
netfilter: br_netfilter: fix panic with metadata_dst skb
- CVE: https://linux.oracle.com/cve/CVE-2024-50045.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50045-netfilter-br-netfilter-fix-panic-with-metadata-dst-skb.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50096
- Description:
nouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error
- CVE: https://linux.oracle.com/cve/CVE-2024-50096.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50096-nouveau-dmem-fix-vulnerability-in-migrate-to-ram-upon-copy-error.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-40953
- Description:
KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()
- CVE: https://linux.oracle.com/cve/CVE-2024-40953.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-40953-kvm-fix-a-data-race-on-last-boosted-vcpu-in-kvm-vcpu-on-spin.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50194
- Description:
Out of scope as the patch is for arm64 arch only, x86_64 not affected
- CVE:
- Patch: skipped/CVE-2024-50194.patch
- From:
- CVE-2024-53060
- Description:
Current kernel is not vulnerable.
- CVE:
- Patch: skipped/CVE-2024-53060.patch
- From:
- CVE-2024-26734
- Description:
Affects only boot __init stage, already booted kernels are not affected
- CVE:
- Patch: skipped/CVE-2024-26734.patch
- From:
- CVE-2024-49944
- Description:
sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start
- CVE: https://linux.oracle.com/cve/CVE-2024-49944.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49944-sctp-set-sk-state-back-to-closed-if-autobind-fails-in-sctp-listen-start.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49944
- Description:
sctp: ensure sk_state is set to CLOSED if hashing fails in sctp_listen_start
- CVE: https://linux.oracle.com/cve/CVE-2024-49944.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49944-sctp-ensure-sk_state-is-set-to-CLOSED-if-hashing-fails-in-sctp_listen_start.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50024
- Description:
net: Fix an unsafe loop on the list
- CVE: https://linux.oracle.com/cve/CVE-2024-50024.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50024-net-fix-an-unsafe-loop-on-the-list.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50116
- Description:
nilfs2: fix kernel bug due to missing clearing of buffer delay flag
- CVE: https://linux.oracle.com/cve/CVE-2024-50116.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50116-nilfs2-fix-kernel-bug-due-to-missing-clearing-of-buffer-delay-flag.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50168
- Description:
net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()
- CVE: https://linux.oracle.com/cve/CVE-2024-50168.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50168-net-sun3-82586-fix-potential-memory-leak-in-sun3-82586-send-packet.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50236
- Description:
wifi: ath10k: Fix memory leak in management tx
- CVE: https://linux.oracle.com/cve/CVE-2024-50236.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50236-wifi-ath10k-fix-memory-leak-in-management-tx-5.4.17-2011.7.4.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47671
- Description:
USB: usbtmc: prevent kernel-usb-infoleak
- CVE: https://linux.oracle.com/cve/CVE-2024-47671.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47671-usb-usbtmc-prevent-kernel-usb-infoleak.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49892
- Description:
drm/amd/display: Initialize get_bytes_per_element's default to 1
- CVE: https://linux.oracle.com/cve/CVE-2024-49892.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49892-drm-amd-display-initialize-get-bytes-per-element-s-default-to-1.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50044
- Description:
Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change
- CVE: https://linux.oracle.com/cve/CVE-2024-50044.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50044-bluetooth-rfcomm-fix-possible-deadlock-in-rfcomm-sk-state-change.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-53097
- Description:
in rhel9 blamed commit 1a83a716ec233 is present neither in newest nor in the oldest kernel
- CVE:
- Patch: skipped/CVE-2024-53097.patch
- From:
- CVE-2024-42229
- Description:
crypto: aead,cipher - zeroize key buffer after use
- CVE: https://linux.oracle.com/cve/CVE-2024-42229.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-42229-crypto-aead-cipher-zeroize-key-buffer-after-use.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49868
- Description:
btrfs: fix a NULL pointer dereference when failed to start a new trasacntion
- CVE: https://linux.oracle.com/cve/CVE-2024-49868.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49868-btrfs-fix-a-null-pointer-dereference-when-failed-to-start-a-new-trasacntion.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50184
- Description:
virtio_pmem: Check device status before requesting flush
- CVE: https://linux.oracle.com/cve/CVE-2024-50184.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50184-virtio-pmem-check-device-status-before-requesting-flush.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50148
- Description:
Bluetooth: bnep: fix wild-memory-access in proto_unregister
- CVE: https://linux.oracle.com/cve/CVE-2024-50148.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50148-bluetooth-bnep-fix-wild-memory-access-in-proto-unregister.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50148
- Description:
Bluetooth: bnep: fix wild-memory-access in proto_unregister kpatch
- CVE: https://linux.oracle.com/cve/CVE-2024-50148.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50148-bluetooth-bnep-fix-wild-memory-access-in-proto-unregister-kpatch.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49963
- Description:
Out of scope as the patch is for arm64 arch only, x86_64 not affected
- CVE:
- Patch: skipped/CVE-2024-49963.patch
- From:
- CVE-2024-50134
- Description:
drm/vboxvideo: Replace fake VLA at end of vbva_mouse_pointer_shape with real VLA
- CVE: https://linux.oracle.com/cve/CVE-2024-50134.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50134-drm-vboxvideo-replace-fake-vla-at-end-of-vbva_mouse_pointer_shape-with-real-vla.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47679
- Description:
vfs: fix race between evice_inodes() and find_inode()&iput()
- CVE: https://linux.oracle.com/cve/CVE-2024-47679.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47679-vfs-fix-race-between-evice_inodes-and-find_inode-iput.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47684
- Description:
tcp: check skb is non-NULL in tcp_rto_delta_us()
- CVE: https://linux.oracle.com/cve/CVE-2024-47684.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47684-tcp-check-skb-is-non-NULL-in-tcp_rto_delta_us.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47712
- Description:
wifi: wilc1000: fix declarations ordering
- CVE: https://linux.oracle.com/cve/CVE-2024-47712.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47712-wifi-wilc1000-fix-declarations-ordering.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-27053
- Description:
wifi: wilc1000: fix RCU usage in connect path
- CVE: https://security-tracker.debian.org/tracker/CVE-2024-27053
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47712-wifi-wilc1000-fix-RCU-usage-in-connect-path.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47712
- Description:
wifi: wilc1000: fix ies_len type in connect path
- CVE: https://linux.oracle.com/cve/CVE-2024-47712.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47712-wifi-wilc1000-fix-ies_len-type-in-connect-path.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47712
- Description:
wifi: wilc1000: fix potential RCU dereference issue in wilc_parse_join_bss_param
- CVE: https://linux.oracle.com/cve/CVE-2024-47712.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47712-wifi-wilc1000-fix-potential-RCU-dereference-issue-in-wilc_parse_join_bss_param.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47713
- Description:
wifi: mac80211: use two-phase skb reclamation in ieee80211_do_stop()
- CVE: https://linux.oracle.com/cve/CVE-2024-47713.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47713-wifi-mac80211-use-two-phase-skb-reclamation-in-ieee80211_do_stop.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-47740
- Description:
f2fs: Require FMODE_WRITE for atomic write ioctls
- CVE: https://linux.oracle.com/cve/CVE-2024-47740.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-47740-f2fs-Require-FMODE_WRITE-for-atomic-write-ioctls.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50205
- Description:
ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size()
- CVE: https://linux.oracle.com/cve/CVE-2024-50205.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50205-ALSA-firewire-lib-Avoid-division-by-zero-in-apply_constraint_to_size.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50237
- Description:
wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower
- CVE: https://linux.oracle.com/cve/CVE-2024-50237.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50237-wifi-mac80211-do-not-pass-a-stopped-vif-to-the-driver-in-.get_txpower.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-50089
- Description:
This CVE was rejected and fix reverted.
- CVE:
- Patch: skipped/CVE-2024-50089.patch
- From:
- CVE-2024-50099
- Description:
arm64: probes: Remove broken LDR (literal) uprobe support
- CVE: https://linux.oracle.com/cve/CVE-2024-50099.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-50099-arm64-probes-Remove-broken-LDR-literal-uprobe-suppor.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49959
- Description:
jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error
- CVE: https://linux.oracle.com/cve/CVE-2024-49959.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49959-jbd2-stop-waiting-for-space-when-jbd2-cleanup-journal-tail-returns-error.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49973
- Description:
r8169: add tally counter fields added with RTL8125
- CVE: https://linux.oracle.com/cve/CVE-2024-49973.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49973-r8169-add-tally-counter-fields-added-with-RTL8125.patch
- From: 5.4.17-2136.338.4.1.el8uek
- CVE-2024-49973
- Description:
r8169: add tally counter fields added with RTL8125
- CVE: https://linux.oracle.com/cve/CVE-2024-49973.html
- Patch: oel8-uek6/5.4.17-2136.338.4.1.el8uek/CVE-2024-49973-r8169-add-tally-counter-fields-added-with-RTL8125-kpatch.patch
- From: 5.4.17-2136.338.4.1.el8uek
- n/a
- Description:
x86/xen: Add xenpv_restore_regs_and_return_to_usermode()
- CVE: n/a
- Patch: 5.4.17/x86-xen-Add-xenpv_restore_regs_and_return_to_usermode.patch
- From: v5.16
- N/A
- Description:
kpatch add paravirt asm definitions
- CVE: N/A
- Patch: 5.11.0/kpatch-add-paravirt-asm-definitions.patch
- From: N/A
- N/A
- Description:
Restrict access to pagemap/kpageflags/kpagecount
- CVE: http://googleprojectzero.blogspot.ru/2015/03/exploiting-dram-rowhammer-bug-to-gain.html
- Patch: 4.15.0/proc-restrict-pagemap-access.patch
- From: N/A
- CVE-2024-38538
- Description:
net: bridge: xmit: make sure we have at least eth header len bytes
- CVE: https://linux.oracle.com/cve/CVE-2024-38538.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-38538-net-bridge-xmit-make-sure-we-have-at-least-eth-header-len-bytes-5.4.17-2136.307.3.6.el8uek.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50279
- Description:
dm cache: fix out-of-bounds access to the dirty bitset when resizing
- CVE: https://linux.oracle.com/cve/CVE-2024-50279.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50279-dm-cache-fix-out-of-bounds-access-to-the-dirty-bitset-when-resizing.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50278
- Description:
dm cache: optimize dirty bit checking with find_next_bit when resizing
- CVE: https://linux.oracle.com/cve/CVE-2024-50278.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50278-dm-cache-optimize-dirty-bit-checking-with-find_next_.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50278
- Description:
dm cache: fix potential out-of-bounds access on the first resume
- CVE: https://linux.oracle.com/cve/CVE-2024-50278.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50278-dm-cache-fix-potential-out-of-bounds-access-on-the-first-resume.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50301
- Description:
security/keys: fix slab-out-of-bounds in key_task_permission
- CVE: https://linux.oracle.com/cve/CVE-2024-50301.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50301-security-keys-fix-slab-out-of-bounds-in-key-task-permission.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53150
- Description:
ALSA: usb-audio: Fix out of bounds reads when finding clock sources
- CVE: https://linux.oracle.com/cve/CVE-2024-53150.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53150-alsa-usb-audio-fix-out-of-bounds-reads-when-finding-clock-sources.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56650
- Description:
netfilter: x_tables: fix LED ID check in led_tg_check()
- CVE: https://linux.oracle.com/cve/CVE-2024-56650.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56650-netfilter-x-tables-fix-led-id-check-in-led-tg-check.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53155
- Description:
ocfs2: fix uninitialized value in ocfs2_file_read_iter()
- CVE: https://linux.oracle.com/cve/CVE-2024-53155.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53155-ocfs2-fix-uninitialized-value-in-ocfs2-file-read-iter.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53061
- Description:
media: s5p-jpeg: prevent buffer overflows
- CVE: https://linux.oracle.com/cve/CVE-2024-53061.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53061-media-s5p-jpeg-prevent-buffer-overflows.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53104
- Description:
media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
- CVE: https://linux.oracle.com/cve/CVE-2024-53104.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53104-media-uvcvideo-skip-parsing-frames-of-type-uvc-vs-undefined-in-uvc-parse-format.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50269
- Description:
usb: musb: sunxi: Fix accessing an released usb phy
- CVE: https://linux.oracle.com/cve/CVE-2024-50269.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50269-usb-musb-sunxi-fix-accessing-an-released-usb-phy.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50267
- Description:
USB: serial: io_edgeport: fix use after free in debug printk
- CVE: https://linux.oracle.com/cve/CVE-2024-50267.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50267-usb-serial-io-edgeport-fix-use-after-free-in-debug-printk.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53103
- Description:
hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer
- CVE: https://linux.oracle.com/cve/CVE-2024-53103.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53103-hv-sock-initializing-vsk-trans-to-null-to-prevent-a-dangling-pointer.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50264
- Description:
vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
- CVE: https://linux.oracle.com/cve/CVE-2024-50264.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50264-vsock-virtio-initialization-of-the-dangling-pointer-occurring-in-vsk-trans.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-49996
- Description:
cifs: Fix buffer overflow when parsing NFS reparse points
- CVE: https://linux.oracle.com/cve/CVE-2024-49996.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-49996-cifs-fix-buffer-overflow-when-parsing-nfs-reparse-points.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53141
- Description:
netfilter: ipset: add missing range check in bitmap_ip_uadt
- CVE: https://linux.oracle.com/cve/CVE-2024-53141.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53141-netfilter-ipset-add-missing-range-check-in-bitmap-ip-uadt.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50282
- Description:
Kernel is not affected
- CVE:
- Patch: skipped/CVE-2024-50282.patch
- From:
- CVE-2024-53156
- Description:
wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()
- CVE: https://linux.oracle.com/cve/CVE-2024-53156.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53156-wifi-ath9k-add-range-check-for-conn-rsp-epid-in-htc-connect-service.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53173
- Description:
NFSv4.0: Fix a use-after-free problem in the asynchronous open()
- CVE: https://linux.oracle.com/cve/CVE-2024-53173.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53173-nfsv4-0-fix-a-use-after-free-problem-in-the-asynchronous-open.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56704
- Description:
9p/xen: fix release of IRQ
- CVE: https://linux.oracle.com/cve/CVE-2024-56704.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56704-9p-xen-fix-release-of-irq.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53165
- Description:
Out of scope: SuperH architecture isn't supported for current kernel
- CVE:
- Patch: skipped/CVE-2024-53165.patch
- From:
- CVE-2024-56606
- Description:
af_packet: avoid erroring out after sock_init_data() in packet_create()
- CVE: https://linux.oracle.com/cve/CVE-2024-56606.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56606-af-packet-avoid-erroring-out-after-sock-init-data-in-packet-create.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56605
- Description:
Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()
- CVE: https://linux.oracle.com/cve/CVE-2024-56605.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56605-bluetooth-l2cap-do-not-leave-dangling-sk-pointer-on-error-in-l2cap-sock-create.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56605
- Description:
Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc
- CVE: https://linux.oracle.com/cve/CVE-2024-56605.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56605-Bluetooth-L2CAP-handle-NULL-sock-pointer-in-l2cap_sock_alloc.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56601
- Description:
net: inet: do not leave a dangling sk pointer in inet_create()
- CVE: https://linux.oracle.com/cve/CVE-2024-56601.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56601-net-inet-do-not-leave-a-dangling-sk-pointer-in-inet-create.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56615
- Description:
bpf: fix OOB devmap writes when deleting elements
- CVE: https://linux.oracle.com/cve/CVE-2024-56615.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56615-bpf-fix-oob-devmap-writes-when-deleting-elements.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53142
- Description:
Patch affects initramfs
- CVE:
- Patch: skipped/CVE-2024-53142.patch
- From:
- CVE-2024-53227
- Description:
scsi: bfa: Fix use-after-free in bfad_im_module_exit()
- CVE: https://linux.oracle.com/cve/CVE-2024-53227.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53227-scsi-bfa-fix-use-after-free-in-bfad-im-module-exit.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53171
- Description:
ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit
- CVE: https://linux.oracle.com/cve/CVE-2024-53171.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53171-ubifs-authentication-fix-use-after-free-in-ubifs-tnc-end-commit.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56603
- Description:
net: af_can: do not leave a dangling sk pointer in can_create()
- CVE: https://linux.oracle.com/cve/CVE-2024-56603.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56603-net-af-can-do-not-leave-a-dangling-sk-pointer-in-can-create.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56596
- Description:
jfs: fix array-index-out-of-bounds in jfs_readdir
- CVE: https://linux.oracle.com/cve/CVE-2024-56596.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56596-jfs-fix-array-index-out-of-bounds-in-jfs-readdir.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56595
- Description:
jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree
- CVE: https://linux.oracle.com/cve/CVE-2024-56595.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56595-jfs-add-a-check-to-prevent-array-index-out-of-bounds-in-dbadjtree.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56598
- Description:
jfs: array-index-out-of-bounds fix in dtReadFirst
- CVE: https://linux.oracle.com/cve/CVE-2024-56598.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56598-jfs-array-index-out-of-bounds-fix-in-dtreadfirst.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56602
- Description:
net: ieee802154: do not leave a dangling sk pointer in ieee802154_create()
- CVE: https://linux.oracle.com/cve/CVE-2024-56602.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56602-net-ieee802154-do-not-leave-a-dangling-sk-pointer-in-ieee802154-create.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56600
- Description:
net: inet6: do not leave a dangling sk pointer in inet6_create()
- CVE: https://linux.oracle.com/cve/CVE-2024-56600.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56600-net-inet6-do-not-leave-a-dangling-sk-pointer-in-inet6-create.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56581
- Description:
btrfs: ref-verify: fix use-after-free after invalid ref action
- CVE: https://linux.oracle.com/cve/CVE-2024-56581.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56581-btrfs-ref-verify-fix-use-after-free-after-invalid-ref-action-5.4.17-2036.104.5.el8uek.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53239
- Description:
ALSA: 6fire: Release resources at card release
- CVE: https://linux.oracle.com/cve/CVE-2024-53239.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53239-ALSA-6fire-Release-resources-at-card-release.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53239
- Description:
ALSA: 6fire: Release resources at card release
- CVE: https://linux.oracle.com/cve/CVE-2024-53239.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53239-ALSA-6fire-Release-resources-at-card-release-kpatch.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53240
- Description:
xen/netfront: fix crash when removing device
- CVE: https://linux.oracle.com/cve/CVE-2024-53240.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53240-xen-netfront-fix-crash-when-removing-device.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50302
- Description:
HID: core: zero-initialize the report buffer
- CVE: https://linux.oracle.com/cve/CVE-2024-50302.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50302-hid-core-zero-initialize-the-report-buffer.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53101
- Description:
fs: Fix uninitialized value issue in from_kuid and from_kgid
- CVE: https://linux.oracle.com/cve/CVE-2024-53101.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53101-fs-fix-uninitialized-value-issue-in-from-kuid-and-from-kgid.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53131
- Description:
nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint
- CVE: https://linux.oracle.com/cve/CVE-2024-53131.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53131-nilfs2-fix-null-ptr-deref-in-block-touch-buffer-tracepoint.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50287
- Description:
media: v4l2-tpg: prevent the risk of a division by zero
- CVE: https://linux.oracle.com/cve/CVE-2024-50287.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50287-media-v4l2-tpg-prevent-the-risk-of-a-division-by-zero.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50290
- Description:
media: cx24116: prevent overflows on SNR calculus
- CVE: https://linux.oracle.com/cve/CVE-2024-50290.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50290-media-cx24116-prevent-overflows-on-snr-calculus.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50273
- Description:
btrfs: reinitialize delayed ref list after deleting it from the list
- CVE: https://linux.oracle.com/cve/CVE-2024-50273.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50273-btrfs-reinitialize-delayed-ref-list-after-deleting-it-from-the-list.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-50299
- Description:
sctp: properly validate chunk size in sctp_sf_ootb()
- CVE: https://linux.oracle.com/cve/CVE-2024-50299.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-50299-sctp-properly-validate-chunk-size-in-sctp-sf-ootb.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53063
- Description:
media: dvbdev: prevent the risk of out of memory access
- CVE: https://linux.oracle.com/cve/CVE-2024-53063.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53063-media-dvbdev-prevent-the-risk-of-out-of-memory-access-5.4.17-2136.321.4.1.el8uek.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53066
- Description:
nfs: Fix KMSAN warning in decode_getfattr_attrs()
- CVE: https://linux.oracle.com/cve/CVE-2024-53066.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53066-nfs-fix-kmsan-warning-in-decode-getfattr-attrs.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53112
- Description:
ocfs2: uncache inode which has failed entering the group
- CVE: https://linux.oracle.com/cve/CVE-2024-53112.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53112-ocfs2-uncache-inode-which-has-failed-entering-the-group.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53130
- Description:
nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
- CVE: https://linux.oracle.com/cve/CVE-2024-53130.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53130-nilfs2-fix-null-ptr-deref-in-block-dirty-buffer-tracepoint.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53194
- Description:
PCI: Fix use-after-free of slot->bus on hot remove
- CVE: https://linux.oracle.com/cve/CVE-2024-53194.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53194-pci-fix-use-after-free-of-slot-bus-on-hot-remove-5.4.17-2036.104.4.el8uek.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53194
- Description:
PCI: Fix use-after-free of slot->bus on hot remove
- CVE: https://linux.oracle.com/cve/CVE-2024-53194.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53194-pci-fix-use-after-free-of-slot-bus-on-hot-remove-kpatch.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53217
- Description:
nfsd: Fix svc_xprt refcnt leak when setup callback client failed
- CVE: https://linux.oracle.com/cve/CVE-2024-53217.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53217-nfsd-Fix-svc_xprt-refcnt-leak-when-setup-callback-client-failed.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53217
- Description:
nfsd: under NFSv4.1, fix double svc_xprt_put on rpc_create failure
- CVE: https://linux.oracle.com/cve/CVE-2024-53217.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53217-nfsd-under-NFSv4.1-fix-double-svc_xprt_put-on-rpc_create-failure.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53217
- Description:
NFSD: Prevent NULL dereference in nfsd4_process_cb_update()
- CVE: https://linux.oracle.com/cve/CVE-2024-53217.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53217-nfsd-prevent-null-dereference-in-nfsd4-process-cb-update.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53217
- Description:
nfsd: restore callback functionality for NFSv4.0
- CVE: https://linux.oracle.com/cve/CVE-2024-53217.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53217-nfsd-restore-callback-functionality-for-NFSv4.0.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56567
- Description:
ad7780: fix division by zero in ad7780_write_raw()
- CVE: https://linux.oracle.com/cve/CVE-2024-56567.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56567-ad7780-fix-division-by-zero-in-ad7780-write-raw.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56670
- Description:
usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer
- CVE: https://linux.oracle.com/cve/CVE-2024-56670.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56670-usb-gadget-u_serial-Fix-the-issue-that-gs_start_io-crashed-2011.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56558
- Description:
nfsd: make sure exp active before svc_export_show
- CVE: https://linux.oracle.com/cve/CVE-2024-56558.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56558-nfsd-make-sure-exp-active-before-svc_export_show.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56572
- Description:
media: platform: allegro-dvt: Fix possible memory leak in allocate_buffers_internal()
- CVE: https://linux.oracle.com/cve/CVE-2024-56572.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56572-media-platform-allegro-dvt-Fix-possible-memory-leak-in-allocate_buffers_internal.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56574
- Description:
media: ts2020: fix null-ptr-deref in ts2020_probe()
- CVE: https://linux.oracle.com/cve/CVE-2024-56574.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56574-media-ts2020-fix-null-ptr-deref-in-ts2020_probe.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56633
- Description:
bpf, sockmap: Fix more uncharged while msg has more_data
- CVE: https://linux.oracle.com/cve/CVE-2024-56633.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56633-01-bpf-sockmap-Fix-more-uncharged-while-msg-has-more_data-302.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56633
- Description:
bpf, sockmap: Fix the sk->sk_forward_alloc warning of sk_stream_kill_queues
- CVE: https://linux.oracle.com/cve/CVE-2024-56633.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56633-02-bpf-sockmap-Fix-the-sk-sk_forward_alloc-warning-of-sk_stream_kill_queues-302.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56633
- Description:
tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg
- CVE: https://linux.oracle.com/cve/CVE-2024-56633.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56633-tcp_bpf-Fix-the-sk_mem_uncharge-logic-in-tcp_bpf_sendmsg-302.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56629
- Description:
HID: wacom: fix when get product name maybe null pointer
- CVE: https://linux.oracle.com/cve/CVE-2024-56629.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56629-HID-wacom-fix-when-get-product-name-maybe-null-pointer-307.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56630
- Description:
ocfs2: free inode when ocfs2_get_init_inode() fails
- CVE: https://linux.oracle.com/cve/CVE-2024-56630.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56630-ocfs2-free-inode-when-ocfs2_get_init_inode-fails-329.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53157
- Description:
firmware: arm_scpi: Check the DVFS OPP count returned by the firmware
- CVE: https://linux.oracle.com/cve/CVE-2024-53157.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53157-firmware-arm_scpi-Check-the-DVFS-OPP-count-returned-by-the-firmware.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53172
- Description:
ubi: fastmap: Fix duplicate slab cache names while attaching
- CVE: https://linux.oracle.com/cve/CVE-2024-53172.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53172-ubi-fastmap-Fix-duplicate-slab-cache-names-while-attaching.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53181
- Description:
Out of scope: User-mode Linux isn't supported for current kernel
- CVE:
- Patch: skipped/CVE-2024-53181.patch
- From:
- CVE-2024-53148
- Description:
comedi: Flush partial mappings in error case
- CVE: https://linux.oracle.com/cve/CVE-2024-53148.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53148-comedi-flush-partial-mappings-in-error-case.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53183
- Description:
Out of scope: User-mode Linux isn't supported for current kernel
- CVE:
- Patch: skipped/CVE-2024-53183.patch
- From:
- CVE-2024-53214
- Description:
vfio/pci: Properly hide first-in-list PCIe extended capability
- CVE: https://linux.oracle.com/cve/CVE-2024-53214.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53214-vfio-pci-properly-hide-first-in-list-PCIe-extended-capability.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56586
- Description:
f2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode.
- CVE: https://linux.oracle.com/cve/CVE-2024-56586.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56586-f2fs-fix-f2fs_bug_on-when-uninstalling-filesystem-call-f2fs_evict_inode.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56597
- Description:
jfs: fix shift-out-of-bounds in dbSplit
- CVE: https://linux.oracle.com/cve/CVE-2024-56597.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56597-jfs-fix-shift-out-of-bounds-in-dbSplit.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56688
- Description:
sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport
- CVE: https://linux.oracle.com/cve/CVE-2024-56688.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56688-sunrpc-clear-XPRT_SOCK_UPD_TIMEOUT-when-reset-transport.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56747
- Description:
scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()
- CVE: https://linux.oracle.com/cve/CVE-2024-56747.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56747-scsi-qedi-fix-a-possible-memory-leak-in-qedi_alloc_and_init_sb.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53135
- Description:
KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN
- CVE: https://linux.oracle.com/cve/CVE-2024-53135.html
- Patch: 2024/CVE-2024-53135/CVE-2024-53135-kvm-vmx-bury-intel-pt-virtualization-guest-host-mode-behind-config-broken.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53135
- Description:
KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN
- CVE: https://linux.oracle.com/cve/CVE-2024-53135.html
- Patch: 2024/CVE-2024-53135/CVE-2024-53135-kvm-vmx-bury-intel-pt-virtualization-guest-host-mode-behind-config-broken-kpatch.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56748
- Description:
scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb()
- CVE: https://linux.oracle.com/cve/CVE-2024-56748.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56748-scsi-qedf-Fix-a-possible-memory-leak-in-qedf_alloc_and_init_sb.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56637
- Description:
netfilter: ipset: Hold module reference while requesting a module
- CVE: https://linux.oracle.com/cve/CVE-2024-56637.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56637-netfilter-ipset-Hold-module-reference-while-requesting-a-module.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56739
- Description:
rtc: check if __rtc_read_time was successful in rtc_timer_do_work()
- CVE: https://linux.oracle.com/cve/CVE-2024-56739.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56739-rtc-check-if-__rtc_read_time-was-successful-in-rtc_timer_do_work.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53145
- Description:
Out of scope: User-mode Linux isn't supported
- CVE:
- Patch: skipped/CVE-2024-53145.patch
- From:
- CVE-2024-53184
- Description:
Out of scope: User-mode Linux isn't supported
- CVE:
- Patch: skipped/CVE-2024-53184.patch
- From:
- CVE-2024-53198
- Description:
xen: Fix the issue of resource not being properly released in xenbus_dev_probe()
- CVE: https://linux.oracle.com/cve/CVE-2024-53198.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53198-xen-Fix-the-issue-of-resource-not-being-properly-released-in-xenbus_dev_probe.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56746
- Description:
fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem()
- CVE: https://linux.oracle.com/cve/CVE-2024-56746.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56746-fbdev-sh7760fb-Fix-a-possible-memory-leak-in-sh7760fb_alloc_mem.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56532
- Description:
ALSA: us122l: Use snd_card_free_when_closed() at disconnection
- CVE: https://linux.oracle.com/cve/CVE-2024-56532.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56532-ALSA-us122l-Use-snd_card_free_when_closed()-at-disconnection.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56548
- Description:
hfsplus: don't query the device logical block size multiple times
- CVE: https://linux.oracle.com/cve/CVE-2024-56548.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56548-hfsplus-don-t-query-the-device-logical-block-size-multiple-times.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53174
- Description:
SUNRPC: make sure cache entry active before cache_show
- CVE: https://linux.oracle.com/cve/CVE-2024-53174.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53174-sunrpc-make-sure-cache-entry-active-before-cache-show.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53197
- Description:
ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
- CVE: https://linux.oracle.com/cve/CVE-2024-53197.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53197-alsa-usb-audio-fix-potential-out-of-bound-accesses-for-extigy-and-mbox-devices.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53146
- Description:
NFSD: Prevent a potential integer overflow
- CVE: https://linux.oracle.com/cve/CVE-2024-53146.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53146-nfsd-prevent-a-potential-integer-overflow.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56576
- Description:
media: i2c: tc358743: Fix crash in the probe error path when using polling
- CVE: https://linux.oracle.com/cve/CVE-2024-56576.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56576-media-i2c-tc358743-fix-crash-in-the-probe-error-path-when-using-polling.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56569
- Description:
ftrace: Fix regression with module command in stack_trace_filter
- CVE: https://linux.oracle.com/cve/CVE-2024-56569.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56569-ftrace-fix-regression-with-module-command-in-stack-trace-filter.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56634
- Description:
gpio: grgpio: Add NULL check in grgpio_probe
- CVE: https://linux.oracle.com/cve/CVE-2024-56634.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56634-gpio-grgpio-add-NULL-check-in-grgpio_probe-kpatch.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56593
- Description:
wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw()
- CVE: https://linux.oracle.com/cve/CVE-2024-56593.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56593-wifi-brcmfmac-fix-oops-due-to-null-pointer-dereference-in-brcmf-sdiod-sglist-rw.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56570
- Description:
ovl: Filter invalid inodes with missing lookup function
- CVE: https://linux.oracle.com/cve/CVE-2024-56570.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56570-ovl-filter-invalid-inodes-with-missing-lookup-function.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56700
- Description:
media: wl128x: Fix atomicity violation in fmc_send_cmd()
- CVE: https://linux.oracle.com/cve/CVE-2024-56700.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56700-media-wl128x-Fix-atomicity-violation-in-fmc_send_cmd.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56587
- Description:
leds: class: Protect brightness_show() with led_cdev->led_access mutex
- CVE: https://linux.oracle.com/cve/CVE-2024-56587.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56587-leds-class-Protect-brightness_show-with-led_cdev-led.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56594
- Description:
drm/amdgpu: set the right AMDGPU sg segment limitation
- CVE: https://linux.oracle.com/cve/CVE-2024-56594.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56594-drm-amdgpu-set-the-right-AMDGPU-sg-segment-limitatio.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56643
- Description:
dccp: Fix memory leak in dccp_feat_change_recv
- CVE: https://linux.oracle.com/cve/CVE-2024-56643.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56643-dccp-Fix-memory-leak-in-dccp_feat_change_recv.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56681
- Description:
crypto: bcm - add error check in the ahash_hmac_init function
- CVE: https://linux.oracle.com/cve/CVE-2024-56681.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56681-crypto-bcm-add-error-check-in-the-ahash_hmac_init-fu.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53161
- Description:
EDAC/bluefield: Fix potential integer overflow
- CVE: https://linux.oracle.com/cve/CVE-2024-53161.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53161-EDAC-bluefield-Fix-potential-integer-overflow.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56562
- Description:
i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs()
- CVE: https://linux.oracle.com/cve/CVE-2024-56562.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56562-i3c-master-Fix-miss-free-init_dyn_addr-at-i3c_master.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53158
- Description:
soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()
- CVE: https://linux.oracle.com/cve/CVE-2024-53158.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-53158-soc-qcom-geni-se-fix-array-underflow-in-geni_se_clk_.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56659
- Description:
net: lapb: increase LAPB_HEADER_LEN
- CVE: https://linux.oracle.com/cve/CVE-2024-56659.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56659-net-lapb-increase-LAPB_HEADER_LEN.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56539
- Description:
The patch only fixes warning, no functional changes.
- CVE:
- Patch: skipped/CVE-2024-56539.patch
- From:
- CVE-2024-56724
- Description:
mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device
- CVE: https://linux.oracle.com/cve/CVE-2024-56724.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56724-mfd-intel_soc_pmic_bxtwc-Use-IRQ-domain-for-TMU-device.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-56723
- Description:
mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device
- CVE: https://linux.oracle.com/cve/CVE-2024-56723.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-56723-mfd-intel_soc_pmic_bxtwc-Use-IRQ-domain-for-PMIC-devices.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-38588
- Description:
ftrace: Fix possible use-after-free issue in ftrace_location()
- CVE: https://linux.oracle.com/cve/CVE-2024-38588.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-38588-ftrace-Check-if-pages-were-allocated-before-calling-free_pages.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-38588
- Description:
ftrace: Fix possible use-after-free issue in ftrace_location()
- CVE: https://linux.oracle.com/cve/CVE-2024-38588.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-38588-ftrace-Fix-possible-warning-on-checking-all-pages-used-in-ftrace_process_locs.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-38588
- Description:
ftrace: Fix possible use-after-free issue in ftrace_location()
- CVE: https://linux.oracle.com/cve/CVE-2024-38588.html
- Patch: oel8-uek6/5.4.17-2136.340.4.1.el8uek/CVE-2024-38588-ftrace-fix-possible-use-after-free-issue-in-ftrace-location-323.patch
- From: 5.4.17-2136.340.4.1.el8uek
- CVE-2024-53164
- Description:
net: sched: fix ordering of qlen adjustment
- CVE: https://linux.oracle.com/cve/CVE-2024-53164.html
- Patch: oel8-uek6/5.4.17-2136.341.3.1.el8uek/CVE-2024-53164-net-sched-fix-ordering-of-qlen-adjustment.patch
- From: 5.4.17-2136.341.3.1.el8uek
- CVE-2024-56769
- Description:
media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg
- CVE: https://linux.oracle.com/cve/CVE-2024-56769.html
- Patch: oel8-uek6/5.4.17-2136.341.3.1.el8uek/CVE-2024-56769-media-dvb-frontends-dib3000mb-fix-uninit-value-in-dib3000-write-reg.patch
- From: 5.4.17-2136.341.3.1.el8uek
- CVE-2024-56767
- Description:
dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset
- CVE: https://linux.oracle.com/cve/CVE-2024-56767.html
- Patch: oel8-uek6/5.4.17-2136.341.3.1.el8uek/CVE-2024-56767-dmaengine-at-xdmac-avoid-null-prt-deref-in-at-xdmac-prep-dma-memset.patch
- From: 5.4.17-2136.341.3.1.el8uek
- CVE-2024-57892
- Description:
ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv
- CVE: https://linux.oracle.com/cve/CVE-2024-57892.html
- Patch: oel8-uek6/5.4.17-2136.341.3.3.el8uek/CVE-2024-57892-ocfs2-fix-slab-use-after-free-due-to-dangling-pointer-dqi-priv.patch
- From: 5.4.17-2136.341.3.3.el8uek
- CVE-2024-39494
- Description:
ima: Fix use-after-free on a dentry's dname.name
- CVE: https://linux.oracle.com/cve/CVE-2024-39494.html
- Patch: oel8-uek6/5.4.17-2136.341.3.3.el8uek/CVE-2024-39494-ima-fix-use-after-free-on-a-dentry-s-dname-name-5.4.17-2136.327.2.el8uek.patch
- From: 5.4.17-2136.341.3.3.el8uek
- CVE-2024-36929
- Description:
net: core: reject skb_copy(_expand) for fraglist GSO skbs
- CVE: https://linux.oracle.com/cve/CVE-2024-36929.html
- Patch: oel8-uek6/5.4.17-2136.343.5.1.el8uek/CVE-2024-36929-net-core-reject-skb-copy-expand-for-fraglist-gso-skbs.patch
- From: 5.4.17-2136.343.5.1.el8uek
- CVE-2024-38555
- Description:
net/mlx5: Discard command completions in internal error
- CVE: https://linux.oracle.com/cve/CVE-2024-38555.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2024-38555-net-mlx5-discard-command-completions-in-internal-error.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-21956
- Description:
drm/amd/display: Assign normalized_pix_clk when color depth = 14
- CVE: https://linux.oracle.com/cve/CVE-2025-21956.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-21956-drm-amd-display-assign-normalized-pix-clk-when-color-depth-14.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-21957
- Description:
scsi: qla1280: Fix kernel oops when debug level > 2
- CVE: https://linux.oracle.com/cve/CVE-2025-21957.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-21957-scsi-qla1280-fix-kernel-oops-when-debug-level-2.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-21993
- Description:
iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in ibft_attr_show_nic()
- CVE: https://linux.oracle.com/cve/CVE-2025-21993.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-21993-iscsi-ibft-fix-ubsan-shift-out-of-bounds-warning-in-ibft-attr-show-nic.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22004
- Description:
net: atm: fix use after free in lec_send()
- CVE: https://linux.oracle.com/cve/CVE-2025-22004.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-22004-net-atm-fix-use-after-free-in-lec-send.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-37937
- Description:
objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds()
- CVE: https://linux.oracle.com/cve/CVE-2025-37937.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-37937-objtool-media-dib8000-prevent-divide-by-zero-in-dib8000-set-dds.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22007
- Description:
Bluetooth: Fix error code in chan_alloc_skb_cb()
- CVE: https://linux.oracle.com/cve/CVE-2025-22007.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-22007-bluetooth-fix-error-code-in-chan-alloc-skb-cb.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22005
- Description:
ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().
- CVE: https://linux.oracle.com/cve/CVE-2025-22005.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-22005-ipv6-fix-memleak-of-nhc-pcpu-rth-output-in-fib-check-nh-v6-gw.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-21996
- Description:
drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse()
- CVE: https://linux.oracle.com/cve/CVE-2025-21996.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-21996-drm-radeon-fix-uninitialized-size-issue-in-radeon-vce-cs-parse.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22018
- Description:
atm: Fix NULL pointer dereference
- CVE: https://linux.oracle.com/cve/CVE-2025-22018.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-22018-atm-fix-null-pointer-dereference.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22021
- Description:
netfilter: socket: Lookup orig tuple for IPv6 SNAT
- CVE: https://linux.oracle.com/cve/CVE-2025-22021.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-22021-netfilter-socket-lookup-orig-tuple-for-ipv6-snat.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-23136
- Description:
thermal: int340x: Add NULL check for adev
- CVE: https://linux.oracle.com/cve/CVE-2025-23136.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-23136-thermal-int340x-add-null-check-for-adev.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22086
- Description:
RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
- CVE: https://linux.oracle.com/cve/CVE-2025-22086.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-22086-rdma-mlx5-fix-mlx5-poll-one-cur-qp-update-flow.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22079
- Description:
ocfs2: validate l_tree_depth to avoid out-of-bounds access
- CVE: https://linux.oracle.com/cve/CVE-2025-22079.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-22079-ocfs2-validate-l-tree-depth-to-avoid-out-of-bounds-access.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22073
- Description:
Out of scope: PowerPC architecture isn't supported for current kernel
- CVE:
- Patch: skipped/CVE-2025-22073.patch
- From:
- CVE-2025-22071
- Description:
Out of scope: PowerPC architecture isn't supported for current kernel
- CVE:
- Patch: skipped/CVE-2025-22071.patch
- From:
- CVE-2025-22063
- Description:
netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets
- CVE: https://linux.oracle.com/cve/CVE-2025-22063.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-22063-netlabel-fix-null-pointer-exception-caused-by-calipso-on-ipv4-sockets.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-38637
- Description:
net_sched: skbprio: Remove overly strict queue assertions
- CVE: https://linux.oracle.com/cve/CVE-2025-38637.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-38637-net-sched-skbprio-remove-overly-strict-queue-assertions.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22045
- Description:
Low score CVE with no well understood impact.
- CVE:
- Patch: skipped/CVE-2025-22045.patch
- From:
- CVE-2025-21959
- Description:
netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()
- CVE: https://linux.oracle.com/cve/CVE-2025-21959.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-21959-netfilter-nf-conncount-fully-initialize-struct-nf-conncount-tuple-in-insert-tree-5.4.17-2136.336.5.3.2.el8uek.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-22020
- Description:
memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove
- CVE: https://linux.oracle.com/cve/CVE-2025-22020.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-22020-memstick-rtsx-usb-ms-fix-slab-use-after-free-in-rtsx-usb-ms-drv-remove.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-21992
- Description:
HID: ignore non-functional sensor in HP 5MP Camera
- CVE: https://linux.oracle.com/cve/CVE-2025-21992.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-21992-hid-ignore-non-functional-sensor-in-hp-5mp-camera.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-21992
- Description:
HID: ignore non-functional sensor in HP 5MP Camera
- CVE: https://linux.oracle.com/cve/CVE-2025-21992.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-21992-hid-ignore-non-functional-sensor-in-hp-5mp-camera-kpatch-2011.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-21971
- Description:
net_sched: Prevent creation of classes with TC_H_ROOT
- CVE: https://linux.oracle.com/cve/CVE-2025-21971.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-21971-net_sched-Prevent-creation-of-classes-with-TC_H_ROOT.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2025-21971
- Description:
net_sched: Prevent creation of classes with TC_H_ROOT
- CVE: https://linux.oracle.com/cve/CVE-2025-21971.html
- Patch: oel8-uek6/5.4.17-2136.344.4.1.el8uek/CVE-2025-21971-net_sched-Prevent-creation-of-classes-with-TC_H_ROOT-kpatch.patch
- From: 5.4.17-2136.344.4.1.el8uek
- CVE-2021-47352
- Description:
virtio-net: Add validation for used length
- CVE: https://linux.oracle.com/cve/CVE-2021-47352.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2021-47352-virtio-net-Add-validation-for-used-length-202.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2024-26744
- Description:
RDMA/srpt: Support specifying the srpt_service_guid
- CVE: https://access.redhat.com/security/cve/CVE-2024-26744
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2024-26744-rdma-srpt-support-specifying-the-srpt-service-guid-kpatch.patch
- From: 5.4.17-2136.345.5.3.el7uek
- CVE-2025-37983
- Description:
qibfs: fix _another_ leak
- CVE: https://linux.oracle.com/cve/CVE-2025-37983.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37983-qibfs-fix-another-leak.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2024-28956
- Description:
Patch meant for use with microcode update
- CVE:
- Patch: skipped/CVE-2024-28956.patch
- From:
- CVE-2025-37838
- Description:
HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition
- CVE: https://linux.oracle.com/cve/CVE-2025-37838.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37838-hsi-ssi-protocol-fix-use-after-free-vulnerability-in-ssi-protocol-driver-due-to-race-condition.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2024-50154
- Description:
tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink().
- CVE: https://linux.oracle.com/cve/CVE-2024-50154.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2024-50154-tcp-dccp-don-t-use-timer-pending-in-reqsk-queue-unlink-202.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37738
- Description:
ext4: ignore xattrs past end
- CVE: https://linux.oracle.com/cve/CVE-2025-37738.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37738-ext4-ignore-xattrs-past-end.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37862
- Description:
HID: pidff: Fix null pointer dereference in pidff_find_fields
- CVE: https://linux.oracle.com/cve/CVE-2025-37862.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37862-hid-pidff-fix-null-pointer-dereference-in-pidff-find-fields.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37839
- Description:
jbd2: remove wrong sb->s_sequence check
- CVE: https://linux.oracle.com/cve/CVE-2025-37839.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37839-jbd2-remove-wrong-sb-s-sequence-check.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37808
- Description:
crypto: null - Use spin lock instead of mutex
- CVE: https://linux.oracle.com/cve/CVE-2025-37808.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37808-crypto-null-Use-spin-lock-instead-of-mutex.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37808
- Description:
crypto: null - Use spin lock instead of mutex
- CVE: https://linux.oracle.com/cve/CVE-2025-37808.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37808-crypto-null-Use-spin-lock-instead-of-mutex-kpatch.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37859
- Description:
page_pool: avoid infinite loop to schedule delayed worker
- CVE: https://linux.oracle.com/cve/CVE-2025-37859.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37859-page-pool-avoid-infinite-loop-to-schedule-delayed-worker.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37841
- Description:
Out of scope: not affected
- CVE:
- Patch: skipped/CVE-2025-37841.patch
- From:
- CVE-2025-37858
- Description:
fs/jfs: Prevent integer overflow in AG size calculation
- CVE: https://linux.oracle.com/cve/CVE-2025-37858.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37858-fs-jfs-prevent-integer-overflow-in-ag-size-calculation.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37741
- Description:
jfs: Prevent copying of nlink with value 0 from disk inode
- CVE: https://linux.oracle.com/cve/CVE-2025-37741.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37741-jfs-prevent-copying-of-nlink-with-value-0-from-disk-inode.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37740
- Description:
jfs: add sanity check for agwidth in dbMount
- CVE: https://linux.oracle.com/cve/CVE-2025-37740.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37740-jfs-add-sanity-check-for-agwidth-in-dbmount-2136.316.7.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-23157
- Description:
media: venus: hfi_parser: add check to avoid out of bound access
- CVE: https://linux.oracle.com/cve/CVE-2025-23157.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-23157-media-venus-hfi_parser-add-check-to-avoid-out-of-bound-access-327.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-23158
- Description:
media: venus: hfi: add check to handle incorrect queue size
- CVE: https://linux.oracle.com/cve/CVE-2025-23158.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-23158-media-venus-hfi-add-check-to-handle-incorrect-queue-size.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-23159
- Description:
media: venus: hfi: add a check to handle OOB in sfr region
- CVE: https://linux.oracle.com/cve/CVE-2025-23159.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-23159-media-venus-hfi-add-a-check-to-handle-oob-in-sfr-region.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-23140
- Description:
misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error
- CVE: https://linux.oracle.com/cve/CVE-2025-23140.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-23140-misc-pci-endpoint-test-avoid-issue-of-interrupts-remaining-after-request-irq-error.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37840
- Description:
mtd: rawnand: brcmnand: fix PM resume warning
- CVE: https://linux.oracle.com/cve/CVE-2025-37840.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37840-mtd-rawnand-brcmnand-fix-pm-resume-warning.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37817
- Description:
mcb: fix a double free bug in chameleon_parse_gdd()
- CVE: https://linux.oracle.com/cve/CVE-2025-37817.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37817-mcb-fix-a-double-free-bug-in-chameleon-parse-gdd.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37881
- Description:
CONFIG_USB_ASPEED_VHUB is not enabled.
- CVE:
- Patch: skipped/CVE-2025-37881.patch
- From:
- CVE-2025-37857
- Description:
scsi: st: Fix array overflow in st_setup()
- CVE: https://linux.oracle.com/cve/CVE-2025-37857.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37857-scsi-st-fix-array-overflow-in-st-setup.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-23163
- Description:
net: vlan: don't propagate flags on open
- CVE: https://linux.oracle.com/cve/CVE-2025-23163.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-23163-net-vlan-don-t-propagate-flags-on-open.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37812
- Description:
usb: cdns3: Fix deadlock when using NCM gadget
- CVE: https://linux.oracle.com/cve/CVE-2025-37812.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37812-usb-cdns3-fix-deadlock-when-using-ncm-gadget.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37785
- Description:
ext4: optimize __ext4_check_dir_entry()
- CVE: https://linux.oracle.com/cve/CVE-2025-37785.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37785-ext4-optimize-__ext4_check_dir_entry.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37785
- Description:
ext4: fix OOB read when checking dotdot dir
- CVE: https://linux.oracle.com/cve/CVE-2025-37785.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37785-ext4-fix-oob-read-when-checking-dotdot-dir.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37766
- Description:
drm/amd/pm: Prevent division by zero
- CVE: https://linux.oracle.com/cve/CVE-2025-37766.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37766-drm-amd-pm-prevent-division-by-zero.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37770
- Description:
drm/amd/pm/powerplay: Prevent division by zero
- CVE: https://linux.oracle.com/cve/CVE-2025-37770.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37770-drm-amd-pm-powerplay-prevent-division-by-zero.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37768
- Description:
drm/amd/pm: Prevent division by zero
- CVE: https://linux.oracle.com/cve/CVE-2025-37768.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37768-drm-amd-pm-prevent-division-by-zero.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37803
- Description:
udmabuf: fix a buf size overflow issue during udmabuf creation
- CVE: https://linux.oracle.com/cve/CVE-2025-37803.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37803-udmabuf-fix-a-buf-size-overflow-issue-during-udmabuf-creation.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37794
- Description:
wifi: mac80211: Purge vif txq in ieee80211_do_stop()
- CVE: https://linux.oracle.com/cve/CVE-2025-37794.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37794-wifi-mac80211-purge-vif-txq-in-ieee80211-do-stop.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-23147
- Description:
i3c: Add NULL pointer check in i3c_master_queue_ibi()
- CVE: https://linux.oracle.com/cve/CVE-2025-23147.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-23147-i3c-add-null-pointer-check-in-i3c-master-queue-ibi.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37765
- Description:
drm/nouveau: prime: fix ttm_bo_delayed_delete oops
- CVE: https://linux.oracle.com/cve/CVE-2025-37765.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37765-drm-nouveau-prime-fix-ttm_bo_delayed_delete-oops-2011.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37796
- Description:
wifi: at76c50x: fix use after free access in at76_disconnect
- CVE: https://linux.oracle.com/cve/CVE-2025-37796.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37796-wifi-at76c50x-fix-use-after-free-access-in-at76-disconnect.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37982
- Description:
wifi: wl1251: fix memory leak in wl1251_tx_work
- CVE: https://linux.oracle.com/cve/CVE-2025-37982.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37982-wifi-wl1251-fix-memory-leak-in-wl1251-tx-work.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37940
- Description:
ftrace: Add cond_resched() to ftrace_graph_set_hash()
- CVE: https://linux.oracle.com/cve/CVE-2025-37940.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37940-ftrace-add-cond-resched-to-ftrace-graph-set-hash.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37850
- Description:
pwm: mediatek: Prevent divide-by-zero in pwm_mediatek_config()
- CVE: https://linux.oracle.com/cve/CVE-2025-37850.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37850-pwm-mediatek-Prevent-divide-by-zero-in-pwm_mediatek_config.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37892
- Description:
mtd: inftlcore: Add error check for inftl_read_oob()
- CVE: https://linux.oracle.com/cve/CVE-2025-37892.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37892-mtd-inftlcore-add-error-check-for-inftl-read-oob.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37792
- Description:
Bluetooth: btrtl: Prevent potential NULL dereference
- CVE: https://linux.oracle.com/cve/CVE-2025-37792.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37792-bluetooth-btrtl-prevent-potential-null-dereference.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37810
- Description:
usb: dwc3: gadget: check that event count does not exceed event buffer length
- CVE: https://linux.oracle.com/cve/CVE-2025-37810.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37810-usb-dwc3-gadget-check-that-event-count-does-not-exceed-event-buffer-length.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37757
- Description:
tipc: fix memory leak in tipc_link_xmit
- CVE: https://linux.oracle.com/cve/CVE-2025-37757.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37757-tipc-fix-memory-leak-in-tipc-link-xmit.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37780
- Description:
isofs: Prevent the use of too small fid
- CVE: https://linux.oracle.com/cve/CVE-2025-37780.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37780-isofs-prevent-the-use-of-too-small-fid.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37758
- Description:
CONFIG_PATA_PXA is not enabled.
- CVE:
- Patch: skipped/CVE-2025-37758.patch
- From:
- CVE-2025-23142
- Description:
sctp: detect and prevent references to a freed transport in sendmsg
- CVE: https://linux.oracle.com/cve/CVE-2025-23142.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-23142-sctp-detect-and-prevent-references-to-a-freed-transport-in-sendmsg-319.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-23142
- Description:
sctp: detect and prevent references to a freed transport in sendmsg
- CVE: https://linux.oracle.com/cve/CVE-2025-23142.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-23142-sctp-detect-and-prevent-references-to-a-freed-transport-in-sendmsg-kpatch.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37773
- Description:
virtiofs: add filesystem context source name check
- CVE: https://linux.oracle.com/cve/CVE-2025-37773.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37773-virtiofs-add-filesystem-context-source-name-check.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37781
- Description:
i2c: cros-ec-tunnel: defer probe if parent EC is not present
- CVE: https://linux.oracle.com/cve/CVE-2025-37781.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37781-i2c-cros-ec-tunnel-defer-probe-if-parent-ec-is-not-present.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37829
- Description:
cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate()
- CVE: https://linux.oracle.com/cve/CVE-2025-37829.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37829-cpufreq-scpi-fix-null-ptr-deref-in-scpi-cpufreq-get-rate.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37749
- Description:
net: ppp: Add bound checking for skb data on ppp_sync_txmung
- CVE: https://linux.oracle.com/cve/CVE-2025-37749.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37749-net-ppp-add-bound-checking-for-skb-data-on-ppp-sync-txmung.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37789
- Description:
net: openvswitch: fix nested key length validation in the set() action
- CVE: https://linux.oracle.com/cve/CVE-2025-37789.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37789-net-openvswitch-fix-nested-key-length-validation-in-the-set-action.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37989
- Description:
Complex adaptation required. Low impact CVE.
- CVE:
- Patch: skipped/CVE-2025-37989.patch
- From:
- CVE-2025-37824
- Description:
tipc: fix NULL pointer dereference in tipc_mon_reinit_self()
- CVE: https://linux.oracle.com/cve/CVE-2025-37824.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37824-tipc-fix-null-pointer-dereference-in-tipc-mon-reinit-self.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37797
- Description:
net_sched: hfsc: Fix a UAF vulnerability in class handling
- CVE: https://linux.oracle.com/cve/CVE-2025-37797.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37797-net-sched-hfsc-fix-a-uaf-vulnerability-in-class-handling.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2025-37823
- Description:
net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
- CVE: https://linux.oracle.com/cve/CVE-2025-37823.html
- Patch: oel8-uek6/5.4.17-2136.345.5.3.el8uek/CVE-2025-37823-net-sched-hfsc-fix-a-potential-uaf-in-hfsc-dequeue-too.patch
- From: 5.4.17-2136.345.5.3.el8uek
- CVE-2023-6931
- Description:
perf: Fix perf_event_validate_size()
- CVE: https://linux.oracle.com/cve/CVE-2023-6931.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2023-6931-perf-fix-perf-event-validate-size.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2023-6931
- Description:
perf: Fix perf_event_validate_size()
- CVE: https://linux.oracle.com/cve/CVE-2023-6931.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2023-6931-perf-Fix-perf_event_validate_size-lockdep-splat.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2024-38541
- Description:
of: module: add buffer overflow check in of_modalias()
- CVE: https://linux.oracle.com/cve/CVE-2024-38541.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2024-38541-of-module-add-buffer-overflow-check-in-of-modalias.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38075
- Description:
scsi: target: iscsi: Fix timeout on deleted connection
- CVE: https://linux.oracle.com/cve/CVE-2025-38075.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38075-scsi-target-iscsi-fix-timeout-on-deleted-connection-5.4.17-2011.7.4.el8uek.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38061
- Description:
net: pktgen: fix access outside of user given buffer in pktgen_thread_write()
- CVE: https://linux.oracle.com/cve/CVE-2025-38061.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38061-net-pktgen-fix-access-outside-of-user-given-buffer-in-pktgen-thread-write.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38044
- Description:
media: cx231xx: set device_caps for 417
- CVE: https://linux.oracle.com/cve/CVE-2025-38044.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38044-media-cx231xx-set-device-caps-for-417.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38065
- Description:
Affects only 32bit systems
- CVE:
- Patch: skipped/CVE-2025-38065.patch
- From:
- CVE-2025-38066
- Description:
dm cache: prevent BUG_ON by blocking retries on failed device resumes
- CVE: https://linux.oracle.com/cve/CVE-2025-38066.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38066-dm-cache-prevent-bug-on-by-blocking-retries-on-failed-device-resumes.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37970
- Description:
iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo
- CVE: https://linux.oracle.com/cve/CVE-2025-37970.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37970-iio-imu-st-lsm6dsx-fix-possible-lockup-in-st-lsm6dsx-read-fifo.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37969
- Description:
iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo
- CVE: https://linux.oracle.com/cve/CVE-2025-37969.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37969-iio-imu-st-lsm6dsx-fix-possible-lockup-in-st-lsm6dsx-read-tagged-fifo.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38072
- Description:
libnvdimm/labels: Fix divide error in nd_label_data_init()
- CVE: https://linux.oracle.com/cve/CVE-2025-38072.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38072-libnvdimm-labels-fix-divide-error-in-nd-label-data-init.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38024
- Description:
RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug
- CVE: https://linux.oracle.com/cve/CVE-2025-38024.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38024-rdma-rxe-fix-slab-use-after-free-read-in-rxe-queue-cleanup-bug.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38023
- Description:
nfs: handle failure of nfs_get_lock_context in unlock path
- CVE: https://linux.oracle.com/cve/CVE-2025-38023.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38023-nfs-handle-failure-of-nfs-get-lock-context-in-unlock-path.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37990
- Description:
wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage()
- CVE: https://linux.oracle.com/cve/CVE-2025-37990.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37990-wifi-brcm80211-fmac-add-error-handling-for-brcmf-usb-dl-writeimage.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37923
- Description:
tracing: Fix oob write in trace_seq_to_buffer()
- CVE: https://linux.oracle.com/cve/CVE-2025-37923.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37923-tracing-fix-oob-write-in-trace-seq-to-buffer.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38035
- Description:
nvmet-tcp: don't restore null sk_state_change
- CVE: https://linux.oracle.com/cve/CVE-2025-38035.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38035-nvmet-tcp-don-t-restore-null-sk-state-change.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37994
- Description:
usb: typec: ucsi: displayport: Fix NULL pointer dereference
- CVE: https://linux.oracle.com/cve/CVE-2025-37994.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37994-usb-typec-ucsi-displayport-Fix-NULL-pointer-dereference.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37994
- Description:
usb: typec: ucsi: displayport: Fix NULL pointer access
- CVE: https://linux.oracle.com/cve/CVE-2025-37994.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37994-usb-typec-ucsi-displayport-fix-null-pointer-access.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37915
- Description:
net_sched: drr: Fix double list add in class with netem as child qdisc
- CVE: https://linux.oracle.com/cve/CVE-2025-37915.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37915-net-sched-drr-fix-double-list-add-in-class-with-netem-as-child-qdisc.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37890
- Description:
net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc
- CVE: https://linux.oracle.com/cve/CVE-2025-37890.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37890-net-sched-hfsc-fix-a-uaf-vulnerability-in-class-with-netem-as-child-qdisc.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38000
- Description:
sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
- CVE: https://linux.oracle.com/cve/CVE-2025-38000.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38000-sch-hfsc-fix-qlen-accounting-bug-when-using-peek-in-hfsc-enqueue.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38001
- Description:
net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
- CVE: https://linux.oracle.com/cve/CVE-2025-38001.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38001-net-sched-hfsc-address-reentrant-enqueue-adding-class-to-eltree-twice.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37913
- Description:
net_sched: qfq: Fix double list add in class with netem as child qdisc
- CVE: https://linux.oracle.com/cve/CVE-2025-37913.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37913-net-sched-qfq-fix-double-list-add-in-class-with-netem-as-child-qdisc.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38058
- Description:
__legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock
- CVE: https://linux.oracle.com/cve/CVE-2025-38058.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38058-legitimize-mnt-check-for-mnt-sync-umount-should-be-under-mount-lock.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37991
- Description:
Out of scope: PA-RISC architecture isn't supported for current kernel
- CVE:
- Patch: skipped/CVE-2025-37991.patch
- From:
- CVE-2025-37998
- Description:
openvswitch: Fix unsafe attribute parsing in output_userspace()
- CVE: https://linux.oracle.com/cve/CVE-2025-37998.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37998-openvswitch-fix-unsafe-attribute-parsing-in-output-userspace.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-37995
- Description:
module: ensure that kobject_put() is safe for module type kobjects
- CVE: https://linux.oracle.com/cve/CVE-2025-37995.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-37995-module-ensure-that-kobject-put-is-safe-for-module-type-kobjects.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38051
- Description:
smb: client: Fix use-after-free in cifs_fill_dirent
- CVE: https://linux.oracle.com/cve/CVE-2025-38051.html
- Patch: oel8-uek6/5.4.17-2136.346.6.el8uek/CVE-2025-38051-smb-client-fix-use-after-free-in-cifs-fill-dirent.patch
- From: 5.4.17-2136.346.6.el8uek
- CVE-2025-38174
- Description:
thunderbolt: Do not double dequeue a configuration request
- CVE: https://linux.oracle.com/cve/CVE-2025-38174.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38174-thunderbolt-do-not-double-dequeue-a-configuration-request.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38298
- Description:
EDAC/skx_common: Fix general protection fault
- CVE: https://linux.oracle.com/cve/CVE-2025-38298.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38298-edac-skx-common-fix-general-protection-fault-5.4.17-2136.335.4.1.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38285
- Description:
bpf: Fix WARN() in get_bpf_raw_tp_regs
- CVE: https://linux.oracle.com/cve/CVE-2025-38285.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38285-bpf-fix-warn-in-get-bpf-raw-tp-regs.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38157
- Description:
wifi: ath9k_htc: Abort software beacon handling if disabled
- CVE: https://linux.oracle.com/cve/CVE-2025-38157.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38157-wifi-ath9k-htc-abort-software-beacon-handling-if-disabled.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38147
- Description:
calipso: Don't call calipso functions for AF_INET sk.
- CVE: https://linux.oracle.com/cve/CVE-2025-38147.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38147-calipso-don-t-call-calipso-functions-for-af-inet-sk.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38147
- Description:
calipso: unlock rcu before returning -EAFNOSUPPORT
- CVE: https://linux.oracle.com/cve/CVE-2025-38147.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38147-calipso-unlock-rcu-before-returning-EAFNOSUPPORT.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38415
- Description:
Squashfs: check return result of sb_min_blocksize
- CVE: https://linux.oracle.com/cve/CVE-2025-38415.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38415-squashfs-check-return-result-of-sb-min-blocksize.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38415
- Description:
Squashfs: check return result of sb_min_blocksize
- CVE: https://linux.oracle.com/cve/CVE-2025-38415.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38415-squashfs-check-return-result-of-sb-min-blocksize-kpatch.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38312
- Description:
fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
- CVE: https://linux.oracle.com/cve/CVE-2025-38312.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38312-fbdev-core-fbcvt-avoid-division-by-0-in-fb-cvt-hperiod.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38136
- Description:
usb: renesas_usbhs: Reorder clock handling and power management in probe
- CVE: https://linux.oracle.com/cve/CVE-2025-38136.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38136-usb-renesas-usbhs-reorder-clock-handling-and-power-management-in-probe.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38135
- Description:
serial: Fix potential null-ptr-deref in mlb_usio_probe()
- CVE: https://linux.oracle.com/cve/CVE-2025-38135.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38135-serial-fix-potential-null-ptr-deref-in-mlb-usio-probe.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38498
- Description:
do_change_type(): refuse to operate on unmounted/not ours mounts
- CVE: https://linux.oracle.com/cve/CVE-2025-38498.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38498-do-change-type-refuse-to-operate-on-unmounted-not-ours-mounts.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2022-48828
- Description:
NFSD: Fix ia_size underflow
- CVE: https://linux.oracle.com/cve/CVE-2022-48828.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2022-48828-nfsd-fix-ia-size-underflow.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2022-48829
- Description:
NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes
- CVE: https://linux.oracle.com/cve/CVE-2022-48829.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2022-48829-nfsd-fix-nfsv3-setattr-create-s-handling-of-large-file-sizes.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38115
- Description:
net_sched: sch_sfq: fix a potential crash on gso_skb handling
- CVE: https://linux.oracle.com/cve/CVE-2025-38115.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38115-net-sched-sch-sfq-fix-a-potential-crash-on-gso-skb-handling.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38083
- Description:
net_sched: prio: fix a race in prio_tune()
- CVE: https://linux.oracle.com/cve/CVE-2025-38083.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38083-net-sched-prio-fix-a-race-in-prio-tune.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38108
- Description:
net_sched: red: fix a race in __red_change()
- CVE: https://linux.oracle.com/cve/CVE-2025-38108.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38108-net-sched-red-fix-a-race-in-red-change.patch
- From: 5.4.17-2136.347.6.el8uek
- 2025-38348
- Description:
wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
- CVE: https://linux.oracle.com/cve/CVE-2025-38348.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38348-wifi-p54-prevent-buffer-overflow-in-p54_rx_eeprom_readback.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38430
- Description:
nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
- CVE: https://linux.oracle.com/cve/CVE-2025-38430.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38430-nfsd-nfsd4-spo-must-allow-must-check-this-is-a-v4-compound-request.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38336
- Description:
ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
- CVE: https://linux.oracle.com/cve/CVE-2025-38336.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38336-ata-pata-via-force-pio-for-atapi-devices-on-vt6415-vt6330.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38222
- Description:
ext4: inline: fix len overflow in ext4_prepare_inline_data
- CVE: https://linux.oracle.com/cve/CVE-2025-38222.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38222-ext4-inline-fix-len-overflow-in-ext4-prepare-inline-data.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38214
- Description:
fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var
- CVE: https://linux.oracle.com/cve/CVE-2025-38214.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38214-fbdev-fix-fb-set-var-to-prevent-null-ptr-deref-in-fb-videomode-to-var.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38212
- Description:
ipc: fix to protect IPCS lookups using RCU
- CVE: https://linux.oracle.com/cve/CVE-2025-38212.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38212-ipc-fix-to-protect-ipcs-lookups-using-rcu.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38346
- Description:
ftrace: Fix UAF when lookup kallsym after ftrace disabled
- CVE: https://linux.oracle.com/cve/CVE-2025-38346.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38346-ftrace-fix-uaf-when-lookup-kallsym-after-ftrace-disabled.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38086
- Description:
net: ch9200: fix uninitialised access during mii_nway_restart
- CVE: https://linux.oracle.com/cve/CVE-2025-38086.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38086-net-ch9200-fix-uninitialised-access-during-mii-nway-restart.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38345
- Description:
Kernel is not vulnerable.
- CVE:
- Patch: skipped/CVE-2025-38345.patch
- From:
- CVE-2025-38344
- Description:
ACPICA: fix acpi parse and parseext cache leaks
- CVE: https://linux.oracle.com/cve/CVE-2025-38344.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38344-acpica-fix-acpi-parse-and-parseext-cache-leaks.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38332
- Description:
scsi: lpfc: Use memcpy() for BIOS version
- CVE: https://linux.oracle.com/cve/CVE-2025-38332.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38332-scsi-lpfc-use-memcpy-for-bios-version.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38200
- Description:
i40e: fix MMIO write access to an invalid page in i40e_clear_hw
- CVE: https://linux.oracle.com/cve/CVE-2025-38200.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38200-i40e-fix-mmio-write-access-to-an-invalid-page-in-i40e-clear-hw.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38194
- Description:
jffs2: check that raw node were preallocated before writing summary
- CVE: https://linux.oracle.com/cve/CVE-2025-38194.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38194-jffs2-check-that-raw-node-were-preallocated-before-writing-summary.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38328
- Description:
jffs2: check jffs2_prealloc_raw_node_refs() result in few other places
- CVE: https://linux.oracle.com/cve/CVE-2025-38328.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38328-jffs2-check-jffs2-prealloc-raw-node-refs-result-in-few-other-places.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38190
- Description:
atm: Revert atm_account_tx() if copy_from_iter_full() fails.
- CVE: https://linux.oracle.com/cve/CVE-2025-38190.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38190-atm-revert-atm-account-tx-if-copy-from-iter-full-fails.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38103
- Description:
HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse()
- CVE: https://linux.oracle.com/cve/CVE-2025-38103.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38103-hid-usbhid-eliminate-recurrent-out-of-bounds-bug-in-usbhid-parse.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38326
- Description:
aoe: clean device rq_list in aoedev_downdev()
- CVE: https://linux.oracle.com/cve/CVE-2025-38326.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38326-aoe-clean-device-rq-list-in-aoedev-downdev.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38420
- Description:
wifi: carl9170: do not ping device which has failed to load firmware
- CVE: https://linux.oracle.com/cve/CVE-2025-38420.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38420-wifi-carl9170-do-not-ping-device-which-has-failed-to-load-firmware.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38324
- Description:
mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
- CVE: https://linux.oracle.com/cve/CVE-2025-38324.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38324-mpls-use-rcu-dereference-rtnl-in-mpls-route-input-rcu.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38185
- Description:
atm: atmtcp: Free invalid length skb in atmtcp_c_send().
- CVE: https://linux.oracle.com/cve/CVE-2025-38185.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38185-atm-atmtcp-free-invalid-length-skb-in-atmtcp-c-send.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38184
- Description:
tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer
- CVE: https://linux.oracle.com/cve/CVE-2025-38184.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38184-tipc-fix-null-ptr-deref-when-acquiring-remote-ip-of-ethernet-bearer.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38181
- Description:
calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
- CVE: https://linux.oracle.com/cve/CVE-2025-38181.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38181-calipso-fix-null-ptr-deref-in-calipso-req-set-del-attr.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38323
- Description:
net: atm: add lec_mutex
- CVE: https://linux.oracle.com/cve/CVE-2025-38323.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38323-net-atm-add-lec-mutex.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38180
- Description:
net: atm: fix /proc/net/atm/lec handling
- CVE: https://linux.oracle.com/cve/CVE-2025-38180.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38180-net-atm-fix-proc-net-atm-lec-handling.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38352
- Description:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
- CVE: https://linux.oracle.com/cve/CVE-2025-38352.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38352-posix-cpu-timers-fix-race-between-handle-posix-cpu-timers-and-posix-cpu-timer-del.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2022-48773
- Description:
xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
- CVE: https://linux.oracle.com/cve/CVE-2022-48773.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2022-48773-xprtrdma-fix-pointer-derefs-in-error-cases-of-rpcrdma-ep-create.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2022-48773
- Description:
xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create
- CVE: https://linux.oracle.com/cve/CVE-2022-48773.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2022-48773-xprtrdma-fix-pointer-derefs-in-error-cases-of-rpcrdma-ep-create-kpatch.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-37958
- Description:
mm/huge_memory: fix dereferencing invalid pmd migration entry
- CVE: https://linux.oracle.com/cve/CVE-2025-37958.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-37958-mm-huge-memory-fix-dereferencing-invalid-pmd-migration-entry-2011.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38424
- Description:
perf: Fix sample vs do_exit()
- CVE: https://linux.oracle.com/cve/CVE-2025-38424.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38424-perf-fix-sample-vs-do-exit-307.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38320
- Description:
arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
- CVE: https://linux.oracle.com/cve/CVE-2025-38320.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-38320-arm64-ptrace-fix-stack-out-of-bounds-read-in-regs-get-kernel-stack-nth.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2024-57996
- Description:
net_sched: sch_sfq: don't allow 1 packet limit
- CVE: https://linux.oracle.com/cve/CVE-2024-57996.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2024-57996-net-sched-sch-sfq-don-t-allow-1-packet-limit.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-37752
- Description:
net_sched: sch_sfq: use a temporary work area for validating configuration
- CVE: https://linux.oracle.com/cve/CVE-2025-37752.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-37752-net-sched-sch-sfq-use-a-temporary-work-area-for-validating-configuration.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-37752
- Description:
net_sched: sch_sfq: move the limit validation
- CVE: https://linux.oracle.com/cve/CVE-2025-37752.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-37752-net-sched-sch-sfq-move-the-limit-validation.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-37752
- Description:
net_sched: sch_sfq: move the limit validation
- CVE: https://linux.oracle.com/cve/CVE-2025-37752.html
- Patch: oel8-uek6/5.4.17-2136.347.6.el8uek/CVE-2025-37752-net-sched-sch-sfq-move-the-limit-validation-kpatch.patch
- From: 5.4.17-2136.347.6.el8uek
- CVE-2025-38494
- Description:
HID: core: do not bypass hid_hw_raw_request
- CVE: https://linux.oracle.com/cve/CVE-2025-38494.html
- Patch: oel8-uek6/5.4.17-2136.347.6.3.el8uek/CVE-2025-38494-HID-core-do-not-bypass-hid_hw_raw_request.patch
- From: 5.4.17-2136.347.6.3.el8uek
- CVE-2025-38495
- Description:
HID: core: ensure the allocated report buffer can contain the reserved report ID
- CVE: https://linux.oracle.com/cve/CVE-2025-38495.html
- Patch: oel8-uek6/5.4.17-2136.347.6.3.el8uek/CVE-2025-38495-HID-core-ensure-the-allocated-report-buffer-can-contain-the-reserved-report-ID.patch
- From: 5.4.17-2136.347.6.3.el8uek
- CVE-2025-38618
- Description:
vsock: Do not allow binding to VMADDR_PORT_ANY
- CVE: https://linux.oracle.com/cve/CVE-2025-38618.html
- Patch: oel8-uek6/5.4.17-2136.347.6.3.el8uek/CVE-2025-38618-vsock-Do-not-allow-binding-to-VMADDR_PORT_ANY.patch
- From: 5.4.17-2136.347.6.3.el8uek
- CVE-2025-38724
- Description:
nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
- CVE: https://linux.oracle.com/cve/CVE-2025-38724.html
- Patch: oel8-uek6/5.4.17-2136.347.6.4.el8uek/CVE-2025-38724-nfsd-handle-get-client-locked-failure-in-nfsd4-setclientid-confirm.patch
- From: 5.4.17-2136.347.6.4.el8uek
- CVE-2025-39742
- Description:
RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask()
- CVE: https://linux.oracle.com/cve/CVE-2025-39742.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39742-rdma-hfi1-fix-possible-divide-by-zero-in-find-hw-thread-mask.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38695
- Description:
scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure
- CVE: https://linux.oracle.com/cve/CVE-2025-38695.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38695-scsi-lpfc-check-for-hdwq-null-ptr-when-cleaning-up-lpfc-vport-structure.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38694
- Description:
media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb()
- CVE: https://linux.oracle.com/cve/CVE-2025-38694.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38694-media-dvb-frontends-dib7090p-fix-null-ptr-deref-in-dib7090p-rw-on-apb.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38693
- Description:
media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar
- CVE: https://linux.oracle.com/cve/CVE-2025-38693.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38693-media-dvb-frontends-w7090p-fix-null-ptr-deref-in-w7090p-tuner-write-serpar-and-w7090p-tuner-read-serpar.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38680
- Description:
media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
- CVE: https://linux.oracle.com/cve/CVE-2025-38680.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38680-media-uvcvideo-fix-1-byte-out-of-bounds-read-in-uvc-parse-format.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39783
- Description:
PCI: endpoint: Fix configfs group list head handling
- CVE: https://linux.oracle.com/cve/CVE-2025-39783.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39783-pci-endpoint-fix-configfs-group-list-head-handling.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39691
- Description:
fs/buffer: fix use-after-free when call bh_read() helper
- CVE: https://linux.oracle.com/cve/CVE-2025-39691.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39691-fs-buffer-fix-use-after-free-when-call-bh-read-helper.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39689
- Description:
ftrace: Also allocate and copy hash for reading of filter files
- CVE: https://linux.oracle.com/cve/CVE-2025-39689.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39689-ftrace-also-allocate-and-copy-hash-for-reading-of-filter-files.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38664
- Description:
ice: Fix a null pointer dereference in ice_copy_and_init_pkg()
- CVE: https://linux.oracle.com/cve/CVE-2025-38664.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38664-ice-fix-a-null-pointer-dereference-in-ice-copy-and-init-pkg.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39798
- Description:
NFS: Fix the setting of capabilities when automounting a new filesystem
- CVE: https://linux.oracle.com/cve/CVE-2025-39798.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39798-nfs-fix-the-setting-of-capabilities-when-automounting-a-new-filesystem.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39798
- Description:
NFS: Fix the setting of capabilities when automounting a new filesystem
- CVE: https://linux.oracle.com/cve/CVE-2025-39798.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39798-nfs-fix-the-setting-of-capabilities-when-automounting-a-new-filesystem-kpatch.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38403
- Description:
vsock/vmci: Clear the vmci transport packet properly when initializing it
- CVE: https://linux.oracle.com/cve/CVE-2025-38403.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38403-vsock-vmci-clear-the-vmci-transport-packet-properly-when-initializing-it.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38464
- Description:
tipc: Fix use-after-free in tipc_conn_close().
- CVE: https://linux.oracle.com/cve/CVE-2025-38464.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38464-tipc-fix-use-after-free-in-tipc-conn-close.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38457
- Description:
net/sched: Abort __tc_modify_qdisc if parent class does not exist
- CVE: https://linux.oracle.com/cve/CVE-2025-38457.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38457-net-sched-abort-tc-modify-qdisc-if-parent-class-does-not-exist.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38445
- Description:
md/raid1: Fix stack memory use after return in raid1_reshape
- CVE: https://linux.oracle.com/cve/CVE-2025-38445.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38445-md-raid1-fix-stack-memory-use-after-return-in-raid1-reshape.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38439
- Description:
bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
- CVE: https://linux.oracle.com/cve/CVE-2025-38439.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38439-bnxt-en-set-dma-unmap-len-correctly-for-xdp-redirect.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38497
- Description:
usb: gadget: configfs: Fix OOB read on empty string write
- CVE: https://linux.oracle.com/cve/CVE-2025-38497.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38497-usb-gadget-configfs-fix-oob-read-on-empty-string-write.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38477
- Description:
net/sched: sch_qfq: Fix race condition on qfq_aggregate
- CVE: https://linux.oracle.com/cve/CVE-2025-38477.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38477-net-sched-sch-qfq-fix-race-condition-on-qfq-aggregate.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38477
- Description:
net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class
- CVE: https://linux.oracle.com/cve/CVE-2025-38477.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38477-net-sched-sch_qfq-Avoid-triggering-might_sleep-in-atomic-context-in-qfq_delete_class.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38474
- Description:
usb: net: sierra: check for no status endpoint
- CVE: https://linux.oracle.com/cve/CVE-2025-38474.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38474-usb-net-sierra-check-for-no-status-endpoint.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39730
- Description:
NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
- CVE: https://linux.oracle.com/cve/CVE-2025-39730.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39730-nfs-fix-filehandle-bounds-checking-in-nfs-fh-to-dentry.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38718
- Description:
sctp: linearize cloned gso packets in sctp_rcv
- CVE: https://linux.oracle.com/cve/CVE-2025-38718.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38718-sctp-linearize-cloned-gso-packets-in-sctp-rcv.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38245
- Description:
atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister().
- CVE: https://linux.oracle.com/cve/CVE-2025-38245.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38245-atm-release-atm-dev-mutex-after-removing-procfs-in-atm-dev-deregister.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2024-26644
- Description:
btrfs: don't abort filesystem when attempting to snapshot deleted subvolume
- CVE: https://linux.oracle.com/cve/CVE-2024-26644.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2024-26644-btrfs-don-t-abort-filesystem-when-attempting-to-snapshot-deleted-subvolume.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38406
- Description:
wifi: ath6kl: remove WARN on bad firmware input
- CVE: https://linux.oracle.com/cve/CVE-2025-38406.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38406-wifi-ath6kl-remove-warn-on-bad-firmware-input.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38514
- Description:
rxrpc: Fix oops due to non-existence of prealloc backlog struct
- CVE: https://linux.oracle.com/cve/CVE-2025-38514.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38514-rxrpc-fix-oops-due-to-non-existence-of-prealloc-backlog-struct.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38691
- Description:
pNFS: Fix uninited ptr deref in block/scsi layout
- CVE: https://linux.oracle.com/cve/CVE-2025-38691.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38691-pnfs-fix-uninited-ptr-deref-in-block-scsi-layout.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39713
- Description:
media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt()
- CVE: https://linux.oracle.com/cve/CVE-2025-39713.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39713-media-rainshadow-cec-fix-toctou-race-condition-in-rain-interrupt.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38177
- Description:
sch_hfsc: make hfsc_qlen_notify() idempotent
- CVE: https://linux.oracle.com/cve/CVE-2025-38177.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38177-sch-hfsc-make-hfsc-qlen-notify-idempotent.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39766
- Description:
net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit
- CVE: https://linux.oracle.com/cve/CVE-2025-39766.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39766-net-sched-make-cake-enqueue-return-net-xmit-cn-when-past-buffer-limit.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39817
- Description:
efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
- CVE: https://linux.oracle.com/cve/CVE-2025-39817.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39817-efivarfs-fix-slab-out-of-bounds-in-efivarfs-d-compare.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39824
- Description:
HID: asus: fix UAF via HID_CLAIMED_INPUT validation
- CVE: https://linux.oracle.com/cve/CVE-2025-39824.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39824-hid-asus-fix-uaf-via-hid-claimed-input-validation.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38249
- Description:
ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3()
- CVE: https://linux.oracle.com/cve/CVE-2025-38249.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38249-alsa-usb-audio-fix-out-of-bounds-read-in-snd-usb-get-audioformat-uac3.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38386
- Description:
ACPICA: Refuse to evaluate a method if arguments are missing
- CVE: https://linux.oracle.com/cve/CVE-2025-38386.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38386-acpica-refuse-to-evaluate-a-method-if-arguments-are-missing.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38473
- Description:
Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()
- CVE: https://linux.oracle.com/cve/CVE-2025-38473.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38473-bluetooth-fix-null-ptr-deref-in-l2cap-sock-resume-cb.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38668
- Description:
regulator: core: fix NULL dereference on unbind due to stale coupling data
- CVE: https://linux.oracle.com/cve/CVE-2025-38668.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38668-regulator-core-fix-null-dereference-on-unbind-due-to-stale-coupling-data.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38581
- Description:
crypto: ccp - Fix crash when rebind ccp device for ccp.ko
- CVE: https://linux.oracle.com/cve/CVE-2025-38581.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38581-crypto-ccp-fix-crash-when-rebind-ccp-device-for-ccp-ko.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39757
- Description:
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
- CVE: https://linux.oracle.com/cve/CVE-2025-39757.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39757-alsa-usb-audio-validate-uac3-cluster-segment-descriptors.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39757
- Description:
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
- CVE: https://linux.oracle.com/cve/CVE-2025-39757.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39757-ALSA-usb-audio-fix-size-validation-in-convert_chmap_v3.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38699
- Description:
scsi: bfa: Double-free fix
- CVE: https://linux.oracle.com/cve/CVE-2025-38699.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38699-scsi-bfa-double-free-fix.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38698
- Description:
jfs: Regular file corruption check
- CVE: https://linux.oracle.com/cve/CVE-2025-38698.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38698-jfs-regular-file-corruption-check.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38468
- Description:
net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree
- CVE: https://linux.oracle.com/cve/CVE-2025-38468.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38468-net-sched-return-null-when-htb-lookup-leaf-encounters-an-empty-rbtree.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38650
- Description:
hfsplus: remove mutex_lock check in hfsplus_free_extents
- CVE: https://linux.oracle.com/cve/CVE-2025-38650.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38650-hfsplus-remove-mutex-lock-check-in-hfsplus-free-extents.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38604
- Description:
wifi: rtl818x: Kill URBs before clearing tx status queue
- CVE: https://linux.oracle.com/cve/CVE-2025-38604.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38604-wifi-rtl818x-kill-urbs-before-clearing-tx-status-queue.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38602
- Description:
iwlwifi: Add missing check for alloc_ordered_workqueue
- CVE: https://linux.oracle.com/cve/CVE-2025-38602.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38602-iwlwifi-add-missing-check-for-alloc-ordered-workqueue.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38574
- Description:
pptp: ensure minimal skb length in pptp_xmit()
- CVE: https://linux.oracle.com/cve/CVE-2025-38574.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38574-pptp-ensure-minimal-skb-length-in-pptp-xmit.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38574
- Description:
pptp: fix pptp_xmit() error path
- CVE: https://linux.oracle.com/cve/CVE-2025-38574.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38574-pptp-fix-pptp_xmit-error-path.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38555
- Description:
usb: gadget : fix use-after-free in composite_dev_cleanup()
- CVE: https://linux.oracle.com/cve/CVE-2025-38555.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38555-usb-gadget-fix-use-after-free-in-composite-dev-cleanup.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38714
- Description:
hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()
- CVE: https://linux.oracle.com/cve/CVE-2025-38714.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38714-hfsplus-fix-slab-out-of-bounds-in-hfsplus-bnode-read.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38713
- Description:
hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
- CVE: https://linux.oracle.com/cve/CVE-2025-38713.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38713-hfsplus-fix-slab-out-of-bounds-read-in-hfsplus-uni2asc.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38713
- Description:
hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
- CVE: https://linux.oracle.com/cve/CVE-2025-38713.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38713-hfsplus-fix-slab-out-of-bounds-read-in-hfsplus_uni2asc.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39751
- Description:
This CVE has been rejected or withdrawn by its CVE Numbering Authority as per NVD website
- CVE:
- Patch: skipped/CVE-2025-39751.patch
- From:
- CVE-2025-38700
- Description:
scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated
- CVE: https://linux.oracle.com/cve/CVE-2025-38700.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38700-scsi-libiscsi-initialize-iscsi-conn-dd-data-only-if-memory-is-allocated.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38478
- Description:
comedi: Fix initialization of data for instructions that write to subdevice
- CVE: https://linux.oracle.com/cve/CVE-2025-38478.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38478-comedi-fix-initialization-of-data-for-instructions-that-write-to-subdevice.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38480
- Description:
comedi: Fix use of uninitialized data in insn_rw_emulate_bits()
- CVE: https://linux.oracle.com/cve/CVE-2025-38480.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38480-comedi-fix-use-of-uninitialized-data-in-insn_rw_emulate_bits.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38481
- Description:
comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large
- CVE: https://linux.oracle.com/cve/CVE-2025-38481.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38481-comedi-fail-COMEDI_INSNLIST-ioctl-if-n_insns-is-too-large.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38482
- Description:
comedi: das6402: Fix bit shift out of bounds
- CVE: https://linux.oracle.com/cve/CVE-2025-38482.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38482-comedi-das6402-fix-bit-shift-out-of-bounds.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38608
- Description:
bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
- CVE: https://linux.oracle.com/cve/CVE-2025-38608.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38608-bpf-ktls-fix-data-corruption-when-using-bpf_msg_pop_data-in-ktls.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38612
- Description:
staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc()
- CVE: https://linux.oracle.com/cve/CVE-2025-38612.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38612-staging-fbtft-fix-potential-memory-leak-in-fbtft_framebuffer_alloc.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38639
- Description:
netfilter: xt_nfacct: don't assume acct name is null-terminated
- CVE: https://linux.oracle.com/cve/CVE-2025-38639.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38639-netfilter-xt_nfacct-don-t-assume-acct-name-is-null-terminated.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38663
- Description:
nilfs2: reject invalid file types when reading inodes
- CVE: https://linux.oracle.com/cve/CVE-2025-38663.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38663-nilfs2-reject-invalid-file-types-when-reading-inodes.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38671
- Description:
i2c: qup: jump out of the loop in case of timeout
- CVE: https://linux.oracle.com/cve/CVE-2025-38671.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38671-i2c-qup-jump-out-of-the-loop-in-case-of-timeout.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38687
- Description:
comedi: fix race between polling and detaching
- CVE: https://linux.oracle.com/cve/CVE-2025-38687.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38687-comedi-fix-race-between-polling-and-detaching.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38389
- Description:
drm/i915/gt: Fix timeline left held on VMA alloc error
- CVE: https://linux.oracle.com/cve/CVE-2025-38389.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38389-drm-i915-gt-fix-timeline-left-held-on-vma-alloc-error.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2024-49935
- Description:
ACPI: PAD: fix crash in exit_round_robin()
- CVE: https://linux.oracle.com/cve/CVE-2024-49935.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2024-49935-acpi-pad-fix-crash-in-exit-round-robin.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2024-49935
- Description:
ACPI: PAD: fix crash in exit_round_robin()
- CVE: https://linux.oracle.com/cve/CVE-2024-49935.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2024-49935-acpi-pad-fix-crash-in-exit-round-robin-kpatch.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38467
- Description:
drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
- CVE: https://linux.oracle.com/cve/CVE-2025-38467.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38467-drm-exynos-exynos7-drm-decon-add-vblank-check-in-irq-handling.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38515
- Description:
drm/sched: Increment job count before swapping tail spsc queue
- CVE: https://linux.oracle.com/cve/CVE-2025-38515.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38515-drm-sched-increment-job-count-before-swapping-tail-spsc-queue.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38513
- Description:
wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()
- CVE: https://linux.oracle.com/cve/CVE-2025-38513.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38513-wifi-zd1211rw-fix-potential-null-pointer-dereference-in-zd-mac-tx-to-dev.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38542
- Description:
net: appletalk: Fix device refcount leak in atrtr_create()
- CVE: https://linux.oracle.com/cve/CVE-2025-38542.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38542-net-appletalk-fix-device-refcount-leak-in-atrtr-create.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38538
- Description:
dmaengine: nbpfaxi: Fix memory corruption in probe()
- CVE: https://linux.oracle.com/cve/CVE-2025-38538.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38538-dmaengine-nbpfaxi-fix-memory-corruption-in-probe.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38530
- Description:
comedi: pcl812: Fix bit shift out of bounds
- CVE: https://linux.oracle.com/cve/CVE-2025-38530.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38530-comedi-pcl812-fix-bit-shift-out-of-bounds.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38529
- Description:
comedi: aio_iiro_16: Fix bit shift out of bounds
- CVE: https://linux.oracle.com/cve/CVE-2025-38529.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38529-comedi-aio-iiro-16-fix-bit-shift-out-of-bounds.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38483
- Description:
comedi: das16m1: Fix bit shift out of bounds
- CVE: https://linux.oracle.com/cve/CVE-2025-38483.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38483-comedi-das16m1-fix-bit-shift-out-of-bounds.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38193
- Description:
net_sched: sch_sfq: reject invalid perturb period
- CVE: https://linux.oracle.com/cve/CVE-2025-38193.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38193-net-sched-sch-sfq-reject-invalid-perturb-period-5.4.17-2011.7.4.el8uek.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38553
- Description:
net/sched: Restrict conditions for adding duplicating netems to qdisc tree
- CVE: https://linux.oracle.com/cve/CVE-2025-38553.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38553-net-sched-restrict-conditions-for-adding-duplicating-netems-to-qdisc-tree-5.4.17-2136.322.1.el8uek.patch
- From: 5.4.17-2136.322.1.el8uek
- CVE-2025-38617
- Description:
net/packet: fix a race in packet_set_ring() and packet_notifier()
- CVE: https://linux.oracle.com/cve/CVE-2025-38617.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38617-net-packet-fix-a-race-in-packet-set-ring-and-packet-notifier-5.4.17-2102.204.4.4.el8uek.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38701
- Description:
ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr
- CVE: https://linux.oracle.com/cve/CVE-2025-38701.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38701-ext4-do-not-bug-when-inline-data-fl-lacks-system-data-xattr-5.4.17-2136.319.1.4.el8uek.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38211
- Description:
RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
- CVE: https://linux.oracle.com/cve/CVE-2025-38211.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38211-rdma-iwcm-fix-use-after-free-of-work-objects-after-cm-id-destruction.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38387
- Description:
[PATCH] RDMA/mlx5: Fix memory leak in error flow for subscribe event routine
- CVE: https://linux.oracle.com/cve/CVE-2025-38387.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38387-RDMA-mlx5-Fix-memory-leak-in-error-flow-for-subscribe-event-routine.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38387
- Description:
RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert
- CVE: https://linux.oracle.com/cve/CVE-2025-38387.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38387-rdma-mlx5-initialize-obj-event-obj-sub-list-before-xa-insert.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38395
- Description:
The patch needs adaptation and CONFIG_REGULATOR_GPIO isn't enabled on UEK6 x86.
- CVE:
- Patch: skipped/CVE-2025-38395.patch
- From:
- CVE-2025-38375
- Description:
virtio-net: ensure the received length does not exceed allocated size
- CVE: https://linux.oracle.com/cve/CVE-2025-38375.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38375-virtio-net-ensure-the-received-length-does-not-exceed-allocated-size-5.4.17-2136.319.1.4.el8uek.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38572
- Description:
ipv6: reject malicious packets in ipv6_gso_segment()
- CVE: https://linux.oracle.com/cve/CVE-2025-38572.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38572-ipv6-reject-malicious-packets-in-ipv6-gso-segment-5.4.17-2136.307.3.6.el8uek.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2024-26958
- Description:
[PATCH] nfs: fix UAF in direct writes
- CVE: https://linux.oracle.com/cve/CVE-2024-26958.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2024-26958-nfs-fix-UAF-in-direct-writes.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2024-26958
- Description:
[PATCH] nfs: fix UAF in direct writes
- CVE: https://linux.oracle.com/cve/CVE-2024-26958.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2024-26958-nfs-fix-UAF-in-direct-writes-kpatch.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38102
- Description:
VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify
- CVE: https://linux.oracle.com/cve/CVE-2025-38102.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38102-vmci-fix-race-between-vmci-host-setup-notify-and-vmci-ctx-unset-notify.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38715
- Description:
hfs: fix slab-out-of-bounds in hfs_bnode_read()
- CVE: https://linux.oracle.com/cve/CVE-2025-38715.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38715-hfs-fix-high-memory-mapping-in-hfs_bnode_read.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38715
- Description:
hfs: fix slab-out-of-bounds in hfs_bnode_read()
- CVE: https://linux.oracle.com/cve/CVE-2025-38715.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38715-hfs-fix-slab-out-of-bounds-in-hfs-bnode-read.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39737
- Description:
mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup()
- CVE: https://linux.oracle.com/cve/CVE-2025-39737.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39737-mm-kmemleak-avoid-soft-lockup-in-kmemleak-do-cleanup.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39736
- Description:
mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock
- CVE: https://linux.oracle.com/cve/CVE-2025-39736.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39736-mm-kmemleak-avoid-deadlock-by-moving-pr-warn-outside-kmemleak-lock.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39808
- Description:
HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version()
- CVE: https://linux.oracle.com/cve/CVE-2025-39808.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39808-hid-hid-ntrig-fix-unable-to-handle-page-fault-in-ntrig-report-version.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38630
- Description:
fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref
- CVE: https://linux.oracle.com/cve/CVE-2025-38630.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38630-fbdev-imxfb-check-fb-add-videomode-to-prevent-null-ptr-deref.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38578
- Description:
f2fs: fix to avoid UAF in f2fs_sync_inode_meta()
- CVE: https://linux.oracle.com/cve/CVE-2025-38578.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38578-f2fs-fix-to-avoid-uaf-in-f2fs-sync-inode-meta.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38577
- Description:
f2fs: fix to avoid panic in f2fs_evict_inode
- CVE: https://linux.oracle.com/cve/CVE-2025-38577.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38577-f2fs-fix-to-avoid-panic-in-f2fs-evict-inode.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39756
- Description:
fs: Prevent file descriptor table allocations exceeding INT_MAX
- CVE: https://linux.oracle.com/cve/CVE-2025-39756.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39756-fs-prevent-file-descriptor-table-allocations-exceeding-int-max.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38721
- Description:
netfilter: ctnetlink: fix refcount leak on table dump
- CVE: https://linux.oracle.com/cve/CVE-2025-38721.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38721-netfilter-ctnetlink-fix-refcount-leak-on-table-dump.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38708
- Description:
drbd: add missing kref_get in handle_write_conflicts
- CVE: https://linux.oracle.com/cve/CVE-2025-38708.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38708-drbd-add-missing-kref-get-in-handle-write-conflicts.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39749
- Description:
rcu: Protect ->defer_qs_iw_pending from data race
- CVE: https://linux.oracle.com/cve/CVE-2025-39749.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39749-rcu-protect-defer-qs-iw-pending-from-data-race.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39724
- Description:
serial: 8250: fix panic due to PSLVERR
- CVE: https://linux.oracle.com/cve/CVE-2025-39724.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39724-serial-8250-fix-panic-due-to-pslverr.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39782
- Description:
jbd2: prevent softlockup in jbd2_log_do_checkpoint()
- CVE: https://linux.oracle.com/cve/CVE-2025-39782.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39782-jbd2-prevent-softlockup-in-jbd2-log-do-checkpoint.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38347
- Description:
f2fs: fix to do sanity check on ino and xnid
- CVE: https://linux.oracle.com/cve/CVE-2025-38347.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38347-f2fs-fix-to-do-sanity-check-on-ino-and-xnid.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39714
- Description:
media: usbtv: Lock resolution while streaming
- CVE: https://linux.oracle.com/cve/CVE-2025-39714.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39714-media-usbtv-lock-resolution-while-streaming.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39710
- Description:
media: venus: Add a check for packet size after reading from shared memory
- CVE: https://linux.oracle.com/cve/CVE-2025-39710.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39710-media-venus-add-a-check-for-packet-size-after-reading-from-shared-memory.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38539
- Description:
tracing: Add down_write(trace_event_sem) when adding trace event
- CVE: https://linux.oracle.com/cve/CVE-2025-38539.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38539-tracing-add-down-write-trace-event-sem-when-adding-trace-event.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39787
- Description:
soc: qcom: mdt_loader: Ensure we don't read past the ELF header
- CVE: https://linux.oracle.com/cve/CVE-2025-39787.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39787-soc-qcom-mdt-loader-ensure-we-don-t-read-past-the-elf-header.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39787
- Description:
soc: qcom: mdt_loader: Deal with zero e_shentsize
- CVE: https://linux.oracle.com/cve/CVE-2025-39787.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39787-soc-qcom-mdt-loader-deal-with-zero-e-shentsize.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39709
- Description:
media: venus: protect against spurious interrupts during probe
- CVE: https://linux.oracle.com/cve/CVE-2025-39709.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39709-media-venus-protect-against-spurious-interrupts-during-probe.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38677
- Description:
f2fs: fix to avoid out-of-boundary access in dnode page
- CVE: https://linux.oracle.com/cve/CVE-2025-38677.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38677-f2fs-fix-to-avoid-out-of-boundary-access-in-dnode-page.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-37798
- Description:
codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()
- CVE: https://linux.oracle.com/cve/CVE-2025-37798.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-37798-codel-remove-sch-q-qlen-check-before-qdisc-tree-reduce-backlog.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39676
- Description:
scsi: qla4xxx: Prevent a potential error pointer dereference
- CVE: https://linux.oracle.com/cve/CVE-2025-39676.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39676-scsi-qla4xxx-prevent-a-potential-error-pointer-dereference.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39813
- Description:
ftrace: Fix potential warning in trace_printk_seq during ftrace_dump
- CVE: https://linux.oracle.com/cve/CVE-2025-39813.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39813-ftrace-fix-potential-warning-in-trace-printk-seq-during-ftrace-dump.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39812
- Description:
sctp: initialize more fields in sctp_v6_from_sk()
- CVE: https://linux.oracle.com/cve/CVE-2025-39812.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39812-sctp-initialize-more-fields-in-sctp-v6-from-sk.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39973
- Description:
i40e: add validation for ring_len param
- CVE: https://linux.oracle.com/cve/CVE-2025-39973.html
- Patch: oel8-uek6/5.4.17-2136.349.3.1.el8uek/CVE-2025-39973-i40e-add-validation-for-ring-len-param.patch
- From: 5.4.17-2136.349.3.1.el8uek
- CVE-2025-39864
- Description:
wifi: cfg80211: fix use-after-free in cmp_bss()
- CVE: https://linux.oracle.com/cve/CVE-2025-39864.html
- Patch: oel8-uek6/5.4.17-2136.349.3.1.el8uek/CVE-2025-39864-wifi-cfg80211-fix-use-after-free-in-cmp-bss.patch
- From: 5.4.17-2136.349.3.1.el8uek
- CVE-2025-39853
- Description:
i40e: Fix potential invalid access when MAC list is empty
- CVE: https://linux.oracle.com/cve/CVE-2025-39853.html
- Patch: oel8-uek6/5.4.17-2136.349.3.1.el8uek/CVE-2025-39853-i40e-fix-potential-invalid-access-when-mac-list-is-empty.patch
- From: 5.4.17-2136.349.3.1.el8uek
- CVE-2025-39847
- Description:
ppp: fix memory leak in pad_compress_skb
- CVE: https://linux.oracle.com/cve/CVE-2025-39847.html
- Patch: oel8-uek6/5.4.17-2136.349.3.1.el8uek/CVE-2025-39847-ppp-fix-memory-leak-in-pad-compress-skb.patch
- From: 5.4.17-2136.349.3.1.el8uek
- CVE-2025-39891
- Description:
wifi: mwifiex: Initialize the chan_stats array to zero
- CVE: https://linux.oracle.com/cve/CVE-2025-39891.html
- Patch: oel8-uek6/5.4.17-2136.349.3.1.el8uek/CVE-2025-39891-wifi-mwifiex-initialize-the-chan-stats-array-to-zero.patch
- From: 5.4.17-2136.349.3.1.el8uek
- CVE-2025-39898
- Description:
e1000e: fix heap overflow in e1000_set_eeprom
- CVE: https://linux.oracle.com/cve/CVE-2025-39898.html
- Patch: oel8-uek6/5.4.17-2136.349.3.1.el8uek/CVE-2025-39898-e1000e-fix-heap-overflow-in-e1000-set-eeprom.patch
- From: 5.4.17-2136.349.3.1.el8uek
- CVE-2025-39902
- Description:
mm/slub: avoid accessing metadata when pointer is invalid in object_err()
- CVE: https://linux.oracle.com/cve/CVE-2025-39902.html
- Patch: oel8-uek6/5.4.17-2136.349.3.1.el8uek/CVE-2025-39902-mm-slub-avoid-accessing-metadata-when-pointer-is-invalid-in-object-err.patch
- From: 5.4.17-2136.349.3.1.el8uek
- CVE-2025-37968
- Description:
iio: light: opt3001: fix deadlock due to concurrent flag access
- CVE: https://linux.oracle.com/cve/CVE-2025-37968.html
- Patch: oel8-uek6/5.4.17-2136.349.3.1.el8uek/CVE-2025-37968-iio-light-opt3001-fix-deadlock-due-to-concurrent-flag-access.patch
- From: 5.4.17-2136.349.3.1.el8uek
- CVE-2025-39841
- Description:
scsi: lpfc: Fix buffer free/clear order in deferred receive path
- CVE: https://linux.oracle.com/cve/CVE-2025-39841.html
- Patch: oel8-uek6/5.4.17-2136.349.3.1.el8uek/CVE-2025-39841-scsi-lpfc-fix-buffer-free-clear-order-in-deferred-receive-path-5.4.17-2036.104.4.el8uek.patch
- From: 5.4.17-2136.349.3.1.el8uek
- CVE-2025-40019
- Description:
crypto: essiv - Check ssize for decryption and in-place encryption
- CVE: https://linux.oracle.com/cve/CVE-2025-40019.html
- Patch: oel8-uek6/5.4.17-2136.349.3.2.el8uek/CVE-2025-40019-crypto-essiv-check-ssize-for-decryption-and-in-place-encryption.patch
- From: 5.4.17-2136.349.3.2.el8uek
- CVE-2025-22058
- Description:
udp: Fix memory accounting leak.
- CVE: https://linux.oracle.com/cve/CVE-2025-22058.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-22058-udp-fix-memory-accounting-leak.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40140
- Description:
net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
- CVE: https://linux.oracle.com/cve/CVE-2025-40140.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40140-net-usb-remove-disruptive-netif-wake-queue-in-rtl8150-set-multicast.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40048
- Description:
uio_hv_generic: Let userspace take care of interrupt mask
- CVE: https://linux.oracle.com/cve/CVE-2025-40048.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40048-uio-hv-generic-let-userspace-take-care-of-interrupt-mask.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40030
- Description:
pinctrl: check the return value of pinmux_ops::get_function_name()
- CVE: https://linux.oracle.com/cve/CVE-2025-40030.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40030-pinctrl-check-the-return-value-of-pinmux-ops-get-function-name.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40111
- Description:
drm/vmwgfx: Fix Use-after-free in validation
- CVE: https://linux.oracle.com/cve/CVE-2025-40111.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40111-drm-vmwgfx-fix-use-after-free-in-validation.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40044
- Description:
fs: udf: fix OOB read in lengthAllocDescs handling
- CVE: https://linux.oracle.com/cve/CVE-2025-40044.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40044-fs-udf-fix-oob-read-in-lengthallocdescs-handling.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40197
- Description:
media: mc: Clear minor number before put device
- CVE: https://linux.oracle.com/cve/CVE-2025-40197.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40197-media-mc-clear-minor-number-before-put-device.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40134
- Description:
dm: fix NULL pointer dereference in __dm_suspend()
- CVE: https://linux.oracle.com/cve/CVE-2025-40134.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40134-dm-fix-null-pointer-dereference-in-dm-suspend.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40178
- Description:
pid: Add a judgment for ns null in pid_nr_ns
- CVE: https://linux.oracle.com/cve/CVE-2025-40178.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40178-pid-add-a-judgment-for-ns-null-in-pid-nr-ns.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40240
- Description:
sctp: avoid NULL dereference when chunk data buffer is missing
- CVE: https://linux.oracle.com/cve/CVE-2025-40240.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40240-sctp-avoid-null-dereference-when-chunk-data-buffer-is-missing.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-39923
- Description:
dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees
- CVE: https://linux.oracle.com/cve/CVE-2025-39923.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-39923-dmaengine-qcom-bam-dma-fix-dt-error-handling-for-num-channels-ees.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-39883
- Description:
mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory
- CVE: https://linux.oracle.com/cve/CVE-2025-39883.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-39883-mm-memory-failure-fix-vm-bug-on-page-pagepoisoned-page-when-unpoison-memory.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-39945
- Description:
cnic: Fix use-after-free bugs in cnic_delete_task
- CVE: https://linux.oracle.com/cve/CVE-2025-39945.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-39945-cnic-fix-use-after-free-bugs-in-cnic-delete-task.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40020
- Description:
can: peak_usb: fix shift-out-of-bounds issue
- CVE: https://linux.oracle.com/cve/CVE-2025-40020.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40020-can-peak-usb-fix-shift-out-of-bounds-issue.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40011
- Description:
drm/gma500: Fix null dereference in hdmi teardown
- CVE: https://linux.oracle.com/cve/CVE-2025-40011.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40011-drm-gma500-fix-null-dereference-in-hdmi-teardown.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40081
- Description:
perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
- CVE: https://linux.oracle.com/cve/CVE-2025-40081.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40081-perf-arm-spe-prevent-overflow-in-perf-idx2off.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40125
- Description:
blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx
- CVE: https://linux.oracle.com/cve/CVE-2025-40125.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40125-blk-mq-check-kobject-state-in-sysfs-before-deleting-in-blk-mq-unregister-hctx.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40078
- Description:
bpf: Explicitly check accesses to bpf_sock_addr
- CVE: https://linux.oracle.com/cve/CVE-2025-40078.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40078-bpf-explicitly-check-accesses-to-bpf-sock-addr.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40115
- Description:
scsi: mpt3sas: Fix crash in transport port remove by using ioc_info()
- CVE: https://linux.oracle.com/cve/CVE-2025-40115.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40115-scsi-mpt3sas-fix-crash-in-transport-port-remove-by-using-ioc-info.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40167
- Description:
ext4: detect invalid INLINE_DATA + EXTENTS flag combination
- CVE: https://linux.oracle.com/cve/CVE-2025-40167.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40167-ext4-detect-invalid-inline-data-extents-flag-combination.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40006
- Description:
mm/hugetlb: fix folio is still mapped when deleted
- CVE: https://linux.oracle.com/cve/CVE-2025-40006.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40006-mm-hugetlb-fix-folio-is-still-mapped-when-deleted.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40219
- Description:
PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV
- CVE: https://linux.oracle.com/cve/CVE-2025-40219.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40219-pci-iov-add-pci-rescan-remove-locking-when-enabling-disabling-sr-iov.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-39913
- Description:
tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork.
- CVE: https://linux.oracle.com/cve/CVE-2025-39913.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-39913-tcp-bpf-call-sk-msg-free-when-tcp-bpf-send-verdict-fails-to-allocate-psock-cork.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-39996
- Description:
media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
- CVE: https://linux.oracle.com/cve/CVE-2025-39996.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-39996-media-b2c2-fix-use-after-free-causing-by-irq-check-work-in-flexcop-pci-remove.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-39995
- Description:
media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe
- CVE: https://linux.oracle.com/cve/CVE-2025-39995.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-39995-media-i2c-tc358743-fix-use-after-free-bugs-caused-by-orphan-timer-in-probe.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40055
- Description:
ocfs2: fix double free in user_cluster_connect()
- CVE: https://linux.oracle.com/cve/CVE-2025-40055.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40055-ocfs2-fix-double-free-in-user-cluster-connect.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40035
- Description:
Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
- CVE: https://linux.oracle.com/cve/CVE-2025-40035.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40035-input-uinput-zero-initialize-uinput-ff-upload-compat-to-avoid-info-leak.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40042
- Description:
tracing: Fix race condition in kprobe initialization causing NULL pointer dereference
- CVE: https://linux.oracle.com/cve/CVE-2025-40042.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40042-tracing-fix-race-condition-in-kprobe-initialization-causing-null-pointer-dereference.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40205
- Description:
btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
- CVE: https://linux.oracle.com/cve/CVE-2025-40205.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40205-btrfs-avoid-potential-out-of-bounds-in-btrfs-encode-fh.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40233
- Description:
ocfs2: clear extent cache after moving/defragmenting extents
- CVE: https://linux.oracle.com/cve/CVE-2025-40233.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40233-ocfs2-clear-extent-cache-after-moving-defragmenting-extents.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40198
- Description:
ext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
- CVE: https://linux.oracle.com/cve/CVE-2025-40198.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40198-ext4-avoid-potential-buffer-over-read-in-parse-apply-sb-mount-options.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40198
- Description:
ext4: fix string copying in parse_apply_sb_mount_options()
- CVE: https://linux.oracle.com/cve/CVE-2025-40198.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40198-ext4-fix-string-copying-in-parse-apply-sb-mount-options.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40105
- Description:
vfs: Don't leak disconnected dentries on umount
- CVE: https://linux.oracle.com/cve/CVE-2025-40105.html
- Patch: oel8-uek6/5.4.17-2136.350.3.1.el8uek/CVE-2025-40105-vfs-don-t-leak-disconnected-dentries-on-umount.patch
- From: 5.4.17-2136.350.3.1.el8uek
- CVE-2025-40271
- Description:
fs/proc: fix uaf in proc_readdir_de()
- CVE: https://linux.oracle.com/cve/CVE-2025-40271.html
- Patch: oel8-uek6/5.4.17-2136.350.3.2.el8uek/CVE-2025-40271-fs-proc-fix-uaf-in-proc-readdir-de-2011-0.patch
- From: 5.4.17-2136.350.3.2.el8uek
- CVE-2022-1729
- Description:
perf: Fix sys_perf_event_open() race against self
- CVE: https://access.redhat.com/security/cve/CVE-2022-1729
- Patch: 5.4.17/CVE-2022-1729-perf-Fix-sys-perf-event-open-race-against-itself.patch
- From: 5.4.17-2136.307.3.2.el8uek