- kernel-3.10.0-1062.18.1.el7 (centos7)
- 3.10.0-1127.el7
- 2020-05-05 06:46:10
- CVE CVE-2019-9503, CVSSv2 Score: 5.9
- Description:
[netdrv] brcmfmac: add subtype check for event handling in data path
- Patch: 3.10.0/0007-netdrv-brcmfmac-add-subtype-check-for-event-handling.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2018-19985 CVE-2018-20169, CVSSv2 Score: 6.4
- Description:
[usb] check usb_get_extra_descriptor for proper size
- Patch: 3.10.0/0105-usb-check-usb_get_extra_descriptor-for-proper-size.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2018-19985 CVE-2018-20169, CVSSv2 Score: 6.4
- Description:
[usb] hso: Fix OOB memory access in hso_probe/hso_get_config_data
- Patch: 3.10.0/0106-usb-hso-Fix-OOB-memory-access-in-hso_probe-hso_get_c.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-13233, CVSSv2 Score: 5.1
- Description:
[x86] insn-eval: Fix use-after-free access to LDT entry
- Patch: 3.10.0/0128-x86-insn-eval-Fix-use-after-free-access-to-LDT-entry.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-11884, CVSSv2 Score: 6.8
- Description:
[net] bluetooth: hidp: fix buffer overflow
- Patch: 3.10.0/0135-net-bluetooth-hidp-fix-buffer-overflow.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-10207, CVSSv2 Score: 4.7
- Description:
[bluetooth] Bluetooth: hci_uart: check for missing tty operations
- Patch: 3.10.0/1106-bluetooth-Bluetooth-hci_uart-check-for-missing-tty-o.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-14283, CVSSv2 Score: 5.6
- Description:
[block] floppy: fix out-of-bounds read in copy_buffer
- Patch: 3.10.0/1107-block-floppy-fix-out-of-bounds-read-in-copy_buffer.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-15221, CVSSv2 Score: 4.6
- Description:
[sound] ALSA: line6: Fix write on zero-sized buffer
- Patch: 3.10.0/1590-sound-ALSA-line6-Fix-write-on-zero-sized-buffer.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-15221, CVSSv2 Score: 4.6
- Description:
[sound] ALSA: line6: Fix memory leak at line6_init_pcm() error path
- Patch: 3.10.0/1607-sound-ALSA-line6-Fix-memory-leak-at-line6_init_pcm-e.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2018-7191, CVSSv2 Score: 6.2
- Description:
[net] tun: call dev_get_valid_name() before register_netdevice()
- Patch: 3.10.0/1694-net-tun-call-dev_get_valid_name-before-register_netd.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2018-7191, CVSSv2 Score: 6.2
- Description:
[net] tun: allow positive return values on dev_get_valid_name() call
- Patch: 3.10.0/1695-net-tun-allow-positive-return-values-on-dev_get_vali.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-10638, CVSSv2 Score: 3.7
- Description:
[fs] dcache: allow word-at-a-time name hashing with big-endian CPUs
- Patch: 3.10.0/1696-fs-dcache-allow-word-at-a-time-name-hashing-with-big.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-10638, CVSSv2 Score: 3.7
- Description:
[lib] siphash: add cryptographically secure PRF
- Patch: 3.10.0/1697-lib-siphash-add-cryptographically-secure-PRF.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-10638, CVSSv2 Score: 3.7
- Description:
[net] inet: switch IP ID generator to siphash
- Patch: 3.10.0/1698-net-inet-switch-IP-ID-generator-to-siphash.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2017-17807, CVSSv2 Score: 3.3
- Description:
[security] KEYS: Strip trailing spaces
- Patch: 3.10.0/1721-security-KEYS-Strip-trailing-spaces.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2017-17807, CVSSv2 Score: 3.3
- Description:
[security] KEYS: remove unnecessary get/put of explicit dest_keyring
- Patch: 3.10.0/1722-security-KEYS-remove-unnecessary-get-put-of-explicit.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2017-17807, CVSSv2 Score: 3.3
- Description:
[security] KEYS: add missing permission check for request_key() destination
- Patch: 3.10.0/1723-security-KEYS-add-missing-permission-check-for-reque.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-12382, CVSSv2 Score: 5.5
- Description:
[drm] drm/edid: Fix a missing-check bug in drm_load_edid_firmware()
- Patch: 3.10.0/1963-drm-drm-edid-Fix-a-missing-check-bug-in-drm_load_edi.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-11190, CVSSv2 Score: 4.7
- Description:
binfmt_elf: switch to new creds when switching to new mm
- Patch: 3.10.0/CVE-2019-11190.patch
- From: >4.8
- CVE CVE-2019-3901, CVSSv2 Score: 5.6
- Description:
[kernel] perf/core: Fix perf_event_open() vs. execve() race
- Patch: 3.10.0/2070-kernel-perf-core-Fix-perf_event_open-vs.-execve-race.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-15916, CVSSv2 Score: 5.5
- Description:
[net] sysfs: Fix mem leak in netdev_register_kobject
- Patch: 3.10.0/2160-net-sysfs-Fix-mem-leak-in-netdev_register_kobject.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-16746, CVSSv2 Score: 8.4
- Description:
cfg80211: add and use strongly typed element iteration macros
- Patch: 3.10.0/CVE-2019-16746-0001-cfg80211-add-and-use-strongly-typed-element-iteratio.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-16746, CVSSv2 Score: 8.4
- Description:
ieee80211: fix for_each_element_extid()
- Patch: 3.10.0/CVE-2019-16746-0002-ieee80211-fix-for_each_element_extid.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-16746, CVSSv2 Score: 8.4
- Description:
cfg80211: Use const more consistently in for_each_element macros
- Patch: 3.10.0/CVE-2019-16746-0003-cfg80211-Use-const-more-consistently-in-for_each_ele.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-16746, CVSSv2 Score: 8.4
- Description:
[net] nl80211: validate beacon head
- Patch: 3.10.0/2282-net-nl80211-validate-beacon-head.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2015-9289, CVSSv2 Score: 3.3
- Description:
[media] cx24116: fix a buffer overflow when checking userspace params
- Patch: 3.10.0/2347-media-cx24116-fix-a-buffer-overflow-when-checking-us.patch
- From: kernel-3.10.0-1127.el7
- CVE , CVSSv2 Score:
- Description:
Restrict access to pagemap/kpageflags/kpagecount
- Patch: 3.10.0/proc-restrict-pagemap-access-1062.patch
- From:
- CVE , CVSSv2 Score:
- Description:
- Patch: 3.10.0/kc-sec/ids_kpatch/0001-security-kcs-event-log.patch
- From:
- CVE , CVSSv2 Score:
- Description:
- Patch: 3.10.0/kc-sec/ids_kpatch/0002-security-kcs-intrusion-detection-system.patch
- From:
- CVE , CVSSv2 Score:
- Description:
- Patch: 3.10.0/kc-sec/honeypot/0002-khoney-kallsyms-check-1062.patch
- From: