RHSA-2024:2394HighCVSS 7.8

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
April 30, 2024
Last Modified
July 10, 2026

🔗 CVE IDs covered (339)

CVE-2022-49322CVE-2023-4133CVE-2023-42754CVE-2023-53094CVE-2023-53258CVE-2023-53536CVE-2023-53993CVE-2025-38053CVE-2023-52581CVE-2023-53544CVE-2023-53611CVE-2023-53673CVE-2023-54184CVE-2023-54283CVE-2023-54324CVE-2022-50346CVE-2023-52529CVE-2023-52580CVE-2023-53019CVE-2023-53256CVE-2023-53559CVE-2023-53628CVE-2023-54070CVE-2023-53016CVE-2023-53164CVE-2023-53784CVE-2023-54274CVE-2024-26609 · pendingCVE-2024-26671CVE-2023-6040CVE-2023-6931CVE-2023-39193CVE-2023-52470CVE-2023-52985CVE-2023-53140CVE-2023-53810CVE-2023-54096CVE-2023-54154CVE-2024-26583CVE-2022-50673CVE-2023-53210CVE-2023-53317CVE-2023-53351CVE-2023-53546CVE-2023-54170CVE-2023-52434CVE-2023-53248CVE-2023-53476CVE-2023-53545CVE-2023-53664CVE-2023-53842CVE-2023-53647CVE-2023-53990CVE-2023-54201CVE-2023-54289CVE-2023-52448CVE-2022-49350CVE-2023-53343CVE-2023-53465CVE-2023-53857CVE-2023-25775CVE-2023-53193CVE-2023-53646CVE-2023-53666CVE-2023-53995CVE-2023-54003CVE-2024-1085CVE-2023-6932CVE-2023-53321CVE-2023-53384CVE-2023-54303CVE-2022-49940CVE-2022-50080CVE-2023-52578CVE-2023-53844CVE-2023-53649CVE-2023-54030CVE-2020-26555CVE-2022-50485CVE-2023-52628CVE-2023-52939CVE-2023-53513CVE-2023-54014CVE-2023-54031CVE-2023-54160CVE-2023-53148CVE-2023-53473CVE-2023-53525CVE-2024-26585CVE-2023-53208CVE-2023-53581CVE-2023-53652CVE-2023-53665CVE-2023-54048CVE-2023-54254CVE-2023-54296CVE-2023-6622CVE-2023-45863CVE-2023-52620CVE-2023-53288CVE-2023-53487CVE-2023-54033CVE-2022-50447CVE-2023-53246CVE-2023-53550CVE-2023-53621CVE-2023-53655CVE-2023-53819CVE-2023-53547CVE-2023-54091CVE-2023-39194CVE-2023-52984CVE-2023-53228CVE-2023-53415CVE-2023-54302CVE-2022-49011CVE-2022-49754CVE-2022-49977CVE-2022-50642CVE-2023-52469CVE-2023-53017CVE-2023-53180CVE-2023-53496CVE-2022-50286CVE-2022-50313CVE-2023-53235CVE-2023-53304CVE-2023-53751CVE-2023-53863CVE-2023-54090CVE-2024-1086CVE-2023-52881CVE-2023-52934CVE-2023-53527CVE-2023-53761CVE-2023-54221CVE-2023-52478CVE-2023-53365CVE-2023-53570CVE-2023-54197CVE-2024-26830CVE-2022-38096CVE-2022-48947CVE-2023-53152CVE-2023-54260CVE-2024-26586CVE-2023-53539CVE-2023-53791CVE-2023-53847CVE-2023-54251CVE-2024-0565CVE-2023-53726CVE-2022-49744CVE-2023-53285CVE-2023-53663CVE-2023-54135CVE-2023-54148CVE-2023-54326CVE-2024-26649CVE-2023-6121CVE-2023-53352CVE-2023-53394CVE-2023-53479CVE-2023-54141CVE-2023-46862CVE-2023-52832CVE-2023-53237CVE-2023-53530CVE-2023-53577CVE-2023-54028CVE-2023-54173CVE-2023-52489CVE-2023-53181CVE-2023-54100CVE-2023-54166CVE-2023-54155CVE-2021-47579CVE-2022-50736CVE-2022-50777CVE-2023-3567CVE-2023-52973CVE-2023-53380CVE-2023-53860CVE-2023-54026CVE-2023-6176CVE-2023-52476CVE-2023-52486CVE-2023-53297CVE-2023-53354CVE-2023-53371CVE-2023-53471CVE-2023-53585CVE-2022-50637CVE-2023-37453CVE-2023-52574CVE-2023-53553CVE-2023-54022CVE-2023-54052CVE-2023-54064CVE-2023-54120CVE-2023-53018CVE-2023-42756CVE-2023-52522CVE-2023-53586CVE-2023-53813CVE-2023-53843CVE-2023-54292CVE-2023-51780CVE-2023-53442CVE-2023-53661CVE-2023-54169CVE-2023-54229CVE-2024-0841CVE-2023-54316CVE-2023-6531CVE-2023-39198CVE-2023-52999CVE-2024-26584CVE-2023-53047CVE-2023-54312CVE-2024-26602CVE-2022-0480CVE-2023-53052CVE-2023-53204CVE-2023-53209CVE-2023-53580CVE-2023-53645CVE-2024-26633CVE-2022-50638CVE-2023-28866CVE-2023-54038CVE-2022-48632CVE-2022-50845CVE-2023-52976CVE-2023-53151CVE-2023-53444CVE-2023-54008CVE-2023-54021CVE-2023-54072CVE-2023-6915CVE-2023-53263CVE-2023-53722CVE-2023-54156CVE-2023-54179CVE-2023-54186CVE-2022-45934CVE-2023-53992CVE-2023-54076CVE-2023-54106CVE-2023-53149CVE-2023-53421CVE-2023-53490CVE-2023-53280CVE-2023-53335CVE-2023-53657CVE-2023-54242CVE-2023-31083CVE-2023-51779CVE-2023-53370CVE-2023-53709CVE-2023-53823CVE-2024-25744CVE-2022-49721CVE-2023-53252CVE-2023-53290CVE-2023-53338CVE-2023-53451CVE-2023-53462CVE-2023-54235CVE-2023-54263CVE-2023-24023CVE-2023-53192CVE-2023-53270CVE-2023-53293 · pendingCVE-2023-53322CVE-2023-53552CVE-2023-53563CVE-2023-53821CVE-2022-50116CVE-2022-50202CVE-2022-50318CVE-2023-6546CVE-2023-52450CVE-2023-52940CVE-2023-53806CVE-2023-54137CVE-2023-53134CVE-2023-28464CVE-2023-53711CVE-2023-54035CVE-2023-54214CVE-2024-26582CVE-2022-50453CVE-2023-52597CVE-2023-53184CVE-2023-53696CVE-2023-53730CVE-2023-54060CVE-2023-54062CVE-2022-50780CVE-2023-53004CVE-2023-53833CVE-2022-50374CVE-2023-53150CVE-2023-53275CVE-2022-50277CVE-2022-50377 · pendingCVE-2023-52817CVE-2023-53046CVE-2023-53202CVE-2023-53743CVE-2024-26593CVE-2022-50879CVE-2023-53612CVE-2023-53999CVE-2023-54016CVE-2023-53501CVE-2023-53660CVE-2023-54261CVE-2023-39189CVE-2023-51043CVE-2023-53309CVE-2023-53632CVE-2023-53848CVE-2023-54069CVE-2023-54215CVE-2022-50782CVE-2023-52610CVE-2023-53057CVE-2023-53097CVE-2023-53221CVE-2023-53615CVE-2023-53677CVE-2023-53795CVE-2023-53441CVE-2023-53713CVE-2023-53762CVE-2023-54006CVE-2023-54145

📋 Description

CVE-2020-26555 — kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack CVE-2021-47579 — kernel: ovl: fix warning in ovl_create_real() CVE-2022-0480 — kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion CVE-2022-38096 — kernel: vmwgfx: NULL pointer dereference in vmw_cmd_dx_define_query CVE-2022-45934 — kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c CVE-2022-48632 — kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() CVE-2022-48947 — kernel: Bluetooth: L2CAP: Fix u8 overflow CVE-2022-49011 — kernel: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() CVE-2022-49322 — kernel: tracing: Fix sleeping function called from invalid context on RT kernel CVE-2022-49350 — kernel: net: mdio: unexport _init-annotated mdio_bus_init() CVE-2022-49721 — kernel: arm64: ftrace: consistently handle PLTs. CVE-2022-49744 — kernel: mm/uffd: fix pte marker when fork() without fork event CVE-2022-49754 — kernel: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() CVE-2022-49940 — kernel: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() CVE-2022-49977 — kernel: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead CVE-2022-50080 — kernel: tee: add overflow check in register_shm_helper() CVE-2022-50116 — kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path CVE-2022-50202 — kernel: PM: hibernate: defer device probing when resuming from hibernation CVE-2022-50277 — kernel: ext4: don't allow journal inode to have encrypt flag CVE-2022-50286 — kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline CVE-2022-50313 — kernel: erofs: fix order >= MAX_ORDER warning due to crafted negative i_size CVE-2022-50318 — kernel: perf/x86/intel/uncore: Fix reference count leak in hswep_has_limit_sbox() CVE-2022-50346 — kernel: ext4: init quota for 'old.inode' in 'ext4_rename' CVE-2022-50374 — kernel: Bluetooth: hci{ldisc,serdev}: check percpu_init_rwsem() failure CVE-2022-50377 — kernel: ext4: check and assert if marking an no_delete evicting inode dirty CVE-2022-50447 — kernel: Bluetooth: hci_conn: Fix crash on hci_create_cis_sync CVE-2022-50453 — kernel: gpiolib: cdev: fix NULL-pointer dereferences CVE-2022-50485 — kernel: ext4: add EXT4_IGET_BAD flag to prevent unexpected bad inode CVE-2022-50637 — kernel: cpufreq: qcom-hw: Fix memory leak in qcom_cpufreq_hw_read_lut() CVE-2022-50638 — kernel: ext4: fix bug_on in __es_tree_search caused by bad boot loader inode CVE-2022-50642 — kernel: platform/chrome: cros_ec_typec: zero out stale pointers CVE-2022-50673 — kernel: ext4: fix use-after-free in ext4_orphan_cleanup CVE-2022-50736 — kernel: Linux kernel: Privilege escalation via out-of-bounds write in RDMA/siw CVE-2022-50777 — kernel: Kernel: Denial of Service due to reference count leak CVE-2022-50780 — kernel: net: fix UAF issue in nfqnl_nf_hook_drop() when ops_init() failed CVE-2022-50782 — kernel: ext4: fix bug_on in __es_tree_search caused by bad quota inode CVE-2022-50845 — kernel: Linux kernel (ext4): Denial of Service due to inode leak via failed extended attribute creation CVE-2022-50879 — kernel: objtool: Fix SEGFAULT CVE-2023-3567 — kernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to race CVE-2023-4133 — kernel: cxgb4: use-after-free in ch_flower_stats_cb() CVE-2023-6040 — kernel: netfilter: nf_tables: out-of-bounds access in nf_tables_newtable() CVE-2023-6121 — kernel: NVMe: info leak due to out-of-bounds read in nvmet_ctrl_find_get CVE-2023-6176 — kernel: local dos vulnerability in scatterwalk_copychunks CVE-2023-6531 — kernel: GC's deletion of an SKB races with unix_stream_read_generic() leading to UAF CVE-2023-6546 — kernel: GSM multiplexing race condition leads to privilege escalation CVE-2023-6622 — kernel: null pointer dereference vulnerability in nft_dynset_init() CVE-2023-6915 — kernel: Null Pointer Dereference vulnerability in ida_free in lib/idr.c CVE-2023-6931 — kernel: Out of boundary write in perf_read_group() as result of overflow a perf_event's read_size CVE-2023-6932 — kernel: use-after-free in IPv4 IGMP CVE-2023-24023 — kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses CVE-2023-25775 — kernel: irdma: Improper access control CVE-2023-28464 — Kernel: double free in hci_conn_cleanup of the bluetooth subsystem CVE-2023-28866 — kernel: Bluetooth: HCI: global out-of-bounds access in net/bluetooth/hci_sync.c CVE-2023-31083 — kernel: race condition between HCIUARTSETPROTO and HCIUARTGETPROTO in hci_uart_tty_ioctl CVE-2023-37453 — kernel: usb: out-of-bounds read in read_descriptors CVE-2023-39189 — kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one() CVE-2023-39193 — kernel: netfilter: xtables sctp out-of-bounds read in match_flags() CVE-2023-39194 — kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match() CVE-2023-39198 — kernel: QXL: race condition leading to use-after-free in qxl_mode_dumb_create() CVE-2023-42754 — kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach() CVE-2023-42756 — kernel: netfilter: race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP CVE-2023-45863 — kernel: lib/kobject.c vulnerable to fill_kobj_path out-of-bounds write CVE-2023-46862 — kernel: NULL pointer dereference vulnerability in io_uring_show_fdinfo CVE-2023-51043 — kernel: use-after-free during a race condition between a nonblocking atomic commit and a driver unload in drivers/gpu/drm/drm_atomic.c CVE-2023-51779 — kernel: bluetooth: bt_sock_ioctl race condition leads to use-after-free in bt_sock_recvmsg CVE-2023-51780 — kernel: use-after-free in net/atm/ioctl.c CVE-2023-52434 — kernel: smb: client: fix potential OOBs in smb2_parse_contexts() CVE-2023-52448 — kernel: gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump CVE-2023-52450 — kernel: intel: Fix NULL pointer dereference issue in upi_fill_topology() CVE-2023-52469 — kernel: use-after-free in kv_parse_power_table CVE-2023-52470 — kernel: null-ptr-deref in alloc_workqueue CVE-2023-52476 — kernel: perf/x86/lbr: Filter vsyscall addresses CVE-2023-52478 — kernel: HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect CVE-2023-52486 — kernel: drm: Don't unref the same fb many times by mistake due to deadlock handling CVE-2023-52489 — kernel: mm/sparsemem: fix race in accessing memory_section->usage CVE-2023-52522 — kernel: net: fix possible store tearing in neigh_periodic_work() CVE-2023-52529 — kernel: HID: sony: Fix a potential memory leak in sony_probe() CVE-2023-52574 — kernel: team: NULL pointer dereference when team device type is changed CVE-2023-52578 — kernel: net: bridge: data races indata-races in br_handle_frame_finish() CVE-2023-52580 — kernel: net/core: kernel crash in ETH_P_1588 flow dissector CVE-2023-52581 — kernel: netfilter: nf_tables: memory leak when more than 255 elements expired CVE-2023-52597 — kernel: KVM: s390: fix setting of fpc register CVE-2023-52610 — kernel: net/sched: act_ct: fix skb leak and crash on ooo frags CVE-2023-52620 — kernel: netfilter: nf_tables: disallow timeout for anonymous sets CVE-2023-52628 — kernel: netfilter: nftables: exthdr: fix 4-byte stack OOB write CVE-2023-52817 — kernel: drm/amdgpu: Fix a null pointer access when the smc_rreg pointer is NULL CVE-2023-52832 — kernel: wifi: mac80211: don't return unset power in ieee80211_get_tx_power() CVE-2023-52881 — kernel: TCP-spoofed ghost ACKs and leak leak initial sequence number CVE-2023-52934 — kernel: mm/MADV_COLLAPSE: catch !none !huge !bad pmd lookups CVE-2023-52939 — kernel: mm: memcg: fix NULL pointer in mem_cgroup_track_foreign_dirty_slowpath() CVE-2023-52940 — kernel: mm: multi-gen LRU: fix crash during cgroup migration CVE-2023-52973 — kernel: vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF CVE-2023-52976 — kernel: efi: fix potential NULL deref in efi_mem_reserve_persistent CVE-2023-52984 — kernel: net: phy: dp83822: Fix null pointer access on DP83825/DP83826 devices CVE-2023-52985 — kernel: arm64: dts: imx8mm-verdin: Do not power down eth-phy CVE-2023-52999 — kernel: net: fix UaF in netns ops registration error path CVE-2023-53004 — kernel: ovl: fix tmpfile leak CVE-2023-53016 — kernel: Bluetooth: Fix possible deadlock in rfcomm_sk_state_change CVE-2023-53017 — kernel: Bluetooth: hci_sync: fix memory leak in hci_update_adv_data() CVE-2023-53018 — kernel: Bluetooth: hci_conn: Fix memory leaks CVE-2023-53019 — kernel: net: mdio: validate parameter addr in mdiobus_get_phy() CVE-2023-53046 — kernel: Bluetooth: Fix race condition in hci_cmd_sync_clear CVE-2023-53047 — kernel: tee: amdtee: fix race condition in amdtee_open_session CVE-2023-53052 — kernel: cifs: fix use-after-free bug in refresh_cache_worker() CVE-2023-53057 — kernel: Bluetooth: HCI: Fix global-out-of-bounds CVE-2023-53094 — kernel: tty: serial: fsl_lpuart: fix race on RX DMA shutdown CVE-2023-53097 — kernel: powerpc/iommu: fix memory leak with using debugfs_lookup() CVE-2023-53134 — kernel: bnxt_en: Avoid order-5 memory allocation for TPA data CVE-2023-53140 — kernel: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier CVE-2023-53148 — kernel: igb: Fix igb_down hung on surprise removal CVE-2023-53149 — kernel: ext4: avoid deadlock in fs reclaim with page writeback CVE-2023-53150 — kernel: scsi: qla2xxx: Pointer may be dereferenced CVE-2023-53151 — kernel: Linux kernel: md/raid10 soft lockup due to unlimited plugged bio CVE-2023-53152 — kernel: drm/amdgpu: fix calltrace warning in amddrm_buddy_fini CVE-2023-53164 — kernel: irqchip/ti-sci: Fix refcount leak in ti_sci_intr_irq_domain_probe CVE-2023-53180 — kernel: wifi: ath12k: Avoid NULL pointer access during management transmit cleanup CVE-2023-53181 — kernel: dma-buf/dma-resv: Stop leaking on krealloc() failure CVE-2023-53184 — kernel: arm64/sme: Set new vector length before reallocating CVE-2023-53192 — kernel: Linux kernel: Out-of-bounds write in VXLAN due to incorrect nexthop hash size leading to denial of service CVE-2023-53193 — kernel: Kernel: Denial of Service in amdgpu driver due to improper interrupt handling CVE-2023-53202 — kernel: PM: domains: fix memory leak with using debugfs_lookup() CVE-2023-53204 — kernel: af_unix: Fix data-races around user->unix_inflight CVE-2023-53208 — kernel: Linux kernel KVM: Denial of Service in nested SVM due to TSC multiplier manipulation CVE-2023-53209 — kernel: wifi: mac80211_hwsim: Fix possible NULL dereference CVE-2023-53210 — kernel: md/raid5-cache: fix null-ptr-deref for r5l_flush_stripe_to_raid() CVE-2023-53221 — kernel: bpf: Fix memleak due to fentry attach failure CVE-2023-53228 — kernel: drm/amdgpu: drop redundant sched job cleanup when cs is aborted CVE-2023-53235 — kernel: drm/tests: helpers: Avoid a driver uaf CVE-2023-53237 — kernel: Linux kernel (amdgpu): Denial of Service via incorrect interrupt handling CVE-2023-53246 — kernel: cifs: fix DFS traversal oops without CONFIG_CIFS_DFS_UPCALL CVE-2023-53248 — kernel: drm/amdgpu: install stub fence into potential unused fence pointers CVE-2023-53252 — kernel: Bluetooth: use RCU for hci_conn_params and iterate safely in hci_sync CVE-2023-53256 — kernel: Linux kernel: Denial of Service in ARM FF-A due to duplicate device names during logical partition registration. CVE-2023-53258 — kernel: drm/amd/display: Fix possible underflow for displays with large vblank CVE-2023-53263 — kernel: drm/nouveau/disp: fix use-after-free in error handling of nouveau_connector_create CVE-2023-53270 — kernel: ext4: fix i_disksize exceeding i_size problem in paritally written case CVE-2023-53275 — kernel: ALSA: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync() CVE-2023-53280 — kernel: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue CVE-2023-53285 — kernel: ext4: add bounds checking in get_max_inline_xattr_value_size() CVE-2023-53288 — kernel: drm/client: Fix memory leak in drm_client_modeset_probe CVE-2023-53290 — kernel: Linux kernel: Denial of Service due to file descriptor leak in BPF sample code CVE-2023-53293 — kernel: Bluetooth: btrtl: check for NULL in btrtl_set_quirks() CVE-2023-53297 — kernel: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp CVE-2023-53304 — kernel: Linux kernel: Denial of Service in netfilter due to improper garbage collection CVE-2023-53309 — kernel: Linux kernel: Denial of Service via integer overflow in radeon_cs_parser_init CVE-2023-53317 — kernel: ext4: fix WARNING in mb_find_extent CVE-2023-53321 — kernel: wifi: mac80211_hwsim: drop short frames CVE-2023-53322 — kernel: scsi: qla2xxx: Wait for io return on terminate rport CVE-2023-53335 — kernel: RDMA/cxgb4: Fix potential null-ptr-deref in pass_establish() CVE-2023-53338 — kernel: lwt: Fix return values of BPF xmit ops CVE-2023-53343 — kernel: icmp6: Fix null-ptr-deref of ip6_null_entry->rt6i_idev in icmp6_dev() CVE-2023-53351 — kernel: Linux kernel: Denial of Service in DRM scheduler due to improper work queue handling CVE-2023-53352 — kernel: drm/ttm: check null pointer before accessing when swapping CVE-2023-53354 — kernel: skbuff: skb_segment, Call zero copy functions before using skbuff frags CVE-2023-53365 — kernel: ip6mr: Fix skb_under_panic in ip6mr_cache_report() CVE-2023-53370 — kernel: drm/amdgpu: fix memory leak in mes self test CVE-2023-53371 — kernel: net/mlx5e: fix memory leak in mlx5e_fs_tt_redirect_any_create CVE-2023-53380 — kernel: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request CVE-2023-53384 — kernel: wifi: mwifiex: avoid possible NULL skb pointer dereference CVE-2023-53394 — kernel: net/mlx5e: xsk: Fix crash on regular rq reactivation CVE-2023-53415 — kernel: USB: dwc3: fix memory leak with using debugfs_lookup() CVE-2023-53421 — kernel: blk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats() CVE-2023-53441 — kernel: bpf: cpumap: Fix memory leak in cpu_map_update_elem CVE-2023-53442 — kernel: ice: Block switchdev mode when ADQ is active and vice versa CVE-2023-53444 — kernel: drm/ttm: fix bulk_move corruption when adding a entry CVE-2023-53451 — kernel: scsi: qla2xxx: Fix potential NULL pointer dereference CVE-2023-53462 — kernel: Linux kernel HSR driver: Denial of Service via uninitialized value access CVE-2023-53465 — kernel: soundwire: qcom: fix storing port config out-of-bounds CVE-2023-53471 — kernel: drm/amdgpu/gfx: disable gfx9 cp_ecc_error_irq only when enabling legacy gfx ras CVE-2023-53473 — kernel: ext4: improve error handling from ext4_dirhash() CVE-2023-53476 — kernel: iw_cxgb4: Fix potential NULL dereference in c4iw_fill_res_cm_id_entry() CVE-2023-53479 — kernel: Linux kernel CXL driver: Use-after-free vulnerability leading to system instability or privilege escalation CVE-2023-53487 — kernel: powerpc/rtas_flash: allow user copy to flash block cache objects CVE-2023-53490 — kernel: mptcp: fix disconnect vs accept race CVE-2023-53496 — kernel: x86/platform/uv: Use alternate source for socket to node data CVE-2023-53501 — kernel: Linux kernel: Denial of Service due to race condition in IOMMU pasid unbinding CVE-2023-53513 — kernel: nbd: fix incomplete validation of ioctl arg CVE-2023-53525 — kernel: RDMA/cma: Allow UD qp_type to join multicast only CVE-2023-53527 — kernel: thunderbolt: Fix memory leak in tb_handle_dp_bandwidth_request() CVE-2023-53530 — kernel: scsi: qla2xxx: Use raw_smp_processor_id() instead of smp_processor_id() CVE-2023-53536 — kernel: blk-crypto: make blk_crypto_evict_key() more robust CVE-2023-53539 — kernel: RDMA/rxe: Fix incomplete state save in rxe_requester CVE-2023-53544 — kernel: cpufreq: davinci: Fix clk use after free CVE-2023-53545 — kernel: drm/amdgpu: unmap and remove csa_va properly CVE-2023-53546 — kernel: net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx CVE-2023-53547 — kernel: drm/amdgpu: Fix sdma v4 sw fini error CVE-2023-53550 — kernel: cpufreq: amd-pstate: fix global sysfs attribute type CVE-2023-53552 — kernel: drm/i915: mark requests for GuC virtual engines to avoid use-after-free CVE-2023-53553 — kernel: HID: hyperv: avoid struct memcpy overrun warning CVE-2023-53559 — kernel: ip_vti: fix potential slab-use-after-free in decode_session6 CVE-2023-53563 — kernel: cpufreq: amd-pstate-ut: Fix kernel panic when loading the driver CVE-2023-53570 — kernel: wifi: nl80211: fix integer overflow in nl80211_parse_mbssid_elems() CVE-2023-53577 — kernel: bpf, cpumap: Make sure kthread is running before map update returns CVE-2023-53580 — kernel: USB: Gadget: core: Help prevent panic during UVC unconfigure CVE-2023-53581 — kernel: net/mlx5e: Check for NOT_READY flag state after locking CVE-2023-53585 — kernel: bpf: reject unhashed sockets in bpf_sk_assign CVE-2023-53586 — kernel: scsi: target: Fix multiple LUN_RESET handling CVE-2023-53611 — kernel: ipmi_si: fix a memleak in try_smi_init() CVE-2023-53612 — kernel: hwmon: (coretemp) Simplify platform device handling CVE-2023-53615 — kernel: scsi: qla2xxx: Fix deletion race condition CVE-2023-53621 — kernel: memcontrol: ensure memcg acquired by id is properly set up CVE-2023-53628 — kernel: drm/amdgpu: drop gfx_v11_0_cp_ecc_error_irq_funcs CVE-2023-53632 — kernel: net/mlx5e: Take RTNL lock when needed before calling xdp_set_features() CVE-2023-53645 — kernel: bpf: Make bpf_refcount_acquire fallible for non-owning refs CVE-2023-53646 — kernel: drm/i915/perf: add sentinel to xehp_oa_b_counters CVE-2023-53647 — kernel: Drivers: hv: vmbus: Don't dereference ACPI root object handle CVE-2023-53649 — kernel: perf trace: Really free the evsel->priv area CVE-2023-53652 — kernel: vdpa: Add features attr to vdpa_nl_policy for nlattr length check CVE-2023-53655 — kernel: rcu: Avoid stack overflow due to __rcu_irq_enter_check_tick() being kprobe-ed CVE-2023-53657 — kernel: ice: Don't tx before switchdev is fully configured CVE-2023-53660 — kernel: bpf, cpumap: Handle skb as well when clean up ptr_ring CVE-2023-53661 — kernel: bnxt: avoid overflow in bnxt_get_nvram_directory() CVE-2023-53663 — kernel: KVM: nSVM: Check instead of asserting on nested TSC scaling support CVE-2023-53664 — kernel: OPP: Fix potential null ptr dereference in dev_pm_opp_get_required_pstate() CVE-2023-53665 — kernel: md: don't dereference mddev after export_rdev() CVE-2023-53666 — kernel: Linux kernel: Denial of Service in ASoC wcd938x codec due to improper error handling CVE-2023-53673 — kernel: Bluetooth: hci_event: call disconnect callback before deleting conn CVE-2023-53677 — kernel: drm/i915: Fix memory leaks in i915 selftests CVE-2023-53696 — kernel: scsi: qla2xxx: Fix memory leak in qla2x00_probe_one() CVE-2023-53709 — kernel: ring-buffer: Handle race between rb_move_tail and rb_check_pages CVE-2023-53711 — kernel: NFS: Fix a potential data corruption CVE-2023-53713 — kernel: arm64: sme: Use STR P to clear FFR context field in streaming SVE mode CVE-2023-53722 — kernel: md: raid1: fix potential OOB in raid1_remove_disk() CVE-2023-53726 — kernel: arm64: csum: Fix OoB access in IP checksum code for negative lengths CVE-2023-53730 — kernel: blk-iocost: use spin_lock_irqsave in adjust_inuse_and_calc_cost CVE-2023-53743 — kernel: Linux kernel: Denial of Service due to PCI resource leak CVE-2023-53751 — kernel: Linux kernel (CIFS): Use-after-free vulnerability allows data integrity compromise and denial of service CVE-2023-53761 — kernel: USB: usbtmc: Fix direction for 0-length ioctl control messages CVE-2023-53762 — kernel: Linux kernel Bluetooth: Denial of Service due to use-after-free in connection handling CVE-2023-53784 — kernel: drm: bridge: dw_hdmi: fix connector access for scdc CVE-2023-53791 — kernel: md: fix warning for holder mismatch from export_rdev() CVE-2023-53795 — kernel: iommufd: IOMMUFD_DESTROY should not increase the refcount CVE-2023-53806 — kernel: drm/amd/display: populate subvp cmd info only for the top pipe CVE-2023-53810 — kernel: blk-mq: release crypto keyslot before reporting I/O complete CVE-2023-53813 — kernel: ext4: fix rbtree traversal bug in ext4_mb_use_preallocated CVE-2023-53819 — kernel: amdgpu: validate offset_in_bo of drm_amdgpu_gem_va CVE-2023-53821 — kernel: ip6_vti: fix slab-use-after-free in decode_session6 CVE-2023-53823 — kernel: block/rq_qos: protect rq_qos apis with a new lock CVE-2023-53833 — kernel: drm/i915: Fix NULL ptr deref by checking new_crtc_state CVE-2023-53842 — kernel: ASoC: codecs: wcd-mbhc-v2: fix resource leaks on component remove CVE-2023-53843 — kernel: net: openvswitch: reject negative ifindex CVE-2023-53844 — kernel: drm/ttm: Don't leak a resource on swapout move error CVE-2023-53847 — kernel: usb-storage: alauda: Fix uninit-value in alauda_check_media() CVE-2023-53848 — kernel: md/raid5-cache: fix a deadlock in r5l_exit_log() CVE-2023-53857 — kernel: bpf: bpf_sk_storage: Fix invalid wait context lockdep report CVE-2023-53860 — kernel: dm: don't attempt to queue IO under RCU protection CVE-2023-53863 — kernel: netlink: do not hard code device address lenth in fdb dumps CVE-2023-53990 — kernel: SMB3: Add missing locks to protect deferred close file list CVE-2023-53992 — kernel: wifi: cfg80211: ocb: don't leave if not joined CVE-2023-53993 — kernel: Kernel: Denial of Service due to memory leak in PCI/DOE CVE-2023-53995 — kernel: Linux kernel: Denial of Service due to memory leak in IP address deletion CVE-2023-53999 — kernel: Linux kernel: Denial of Service due to memory leak in mlx5e driver CVE-2023-54003 — kernel: Linux kernel: RDMA/core GID entry leak causes Denial of Service CVE-2023-54006 — kernel: af_unix: Fix data-race around unix_tot_inflight CVE-2023-54008 — kernel: virtio_vdpa: build affinity masks conditionally CVE-2023-54014 — kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() CVE-2023-54016 — kernel: Linux kernel: Memory leak in ath12k Wi-Fi driver can lead to denial of service CVE-2023-54021 — kernel: ext4: set goal start correctly in ext4_mb_normalize_request CVE-2023-54022 — kernel: Linux kernel ALSA USB audio: Denial of Service due to memory leaks in MIDI 2.0 / UMP device handling CVE-2023-54026 — kernel: opp: Fix use-after-free in lazy_opp_tables after probe deferral CVE-2023-54028 — kernel: Linux kernel: Denial of Service vulnerability in RDMA/rxe component CVE-2023-54030 — kernel: io_uring/net: don't overflow multishot recv CVE-2023-54031 — kernel: vdpa: Add queue index attr to vdpa_nl_policy for nlattr length check CVE-2023-54033 — kernel: kernel: Denial of Service via memory leak in LRU hash maps CVE-2023-54035 — kernel: netfilter: nf_tables: fix underflow in chain reference counter CVE-2023-54038 — kernel: Linux kernel: Denial of Service in Bluetooth HCI connection handling CVE-2023-54048 — kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction CVE-2023-54052 — kernel: Linux kernel Wi-Fi driver: Denial of Service due to missing transmit status CVE-2023-54060 — kernel: iommufd: Set end correctly when doing batch carry CVE-2023-54062 — kernel: ext4: fix invalid free tracking in ext4_xattr_move_to_block() CVE-2023-54064 — kernel: Kernel: Memory leak in IPMI SSIF module leads to Denial of Service CVE-2023-54069 — kernel: ext4: fix BUG in ext4_mb_new_inode_pa() due to overflow CVE-2023-54070 — kernel: Linux kernel igb driver: Denial of Service due to improper SR-IOV cleanup CVE-2023-54072 — kernel: Linux kernel: Denial of service or memory corruption due to a data race in ALSA PCM memory allocation CVE-2023-54076 — kernel: smb: client: fix missed ses refcounting CVE-2023-54090 — kernel: ixgbe: Fix panic during XDP_TX with > 64 CPUs CVE-2023-54091 — kernel: Linux kernel: Denial of Service due to memory leak in drm_client_target_cloned function CVE-2023-54096 — kernel: Linux kernel (soundwire): Memory corruption due to incorrect device enumeration completion CVE-2023-54100 — kernel: scsi: qedi: Fix use after free bug in qedi_remove() CVE-2023-54106 — kernel: Linux kernel: Denial of Service via memory leak in mlx5e_init_rep_rx CVE-2023-54120 — kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread CVE-2023-54135 — kernel: maple_tree: fix potential out-of-bounds access in mas_wr_end_piv() CVE-2023-54137 — kernel: Linux kernel: Information disclosure in VFIO Type1 module via uninitialized stack memory CVE-2023-54141 — kernel: wifi: ath11k: Add missing hw_ops->get_ring_selector() for IPQ5018 CVE-2023-54145 — kernel: Linux kernel: BPF verifier log truncation via crafted user input CVE-2023-54148 — kernel: net/mlx5e: Move representor neigh cleanup to profile cleanup_tx CVE-2023-54154 — kernel: Linux kernel: Denial of Service due to memory leak in target_cmd_counter CVE-2023-54155 — kernel: Linux kernel: Denial of service in network core via incorrect frame size handling CVE-2023-54156 — kernel: sfc: fix crash when reading stats while NIC is resetting CVE-2023-54160 — kernel: firmware: arm_sdei: Fix sleep from invalid context BUG CVE-2023-54166 — kernel: igc: Fix Kernel Panic during ndo_tx_timeout callback CVE-2023-54169 — kernel: net/mlx5e: fix memory leak in mlx5e_ptp_open CVE-2023-54170 — kernel: keys: Fix linking a duplicate key to a keyring's assoc_array CVE-2023-54173 — kernel: bpf: Disable preemption in bpf_event_output CVE-2023-54179 — kernel: scsi: qla2xxx: Array index may go out of bound CVE-2023-54184 — kernel: scsi: target: iscsit: Free cmds before session free CVE-2023-54186 — kernel: usb: typec: altmodes/displayport: fix pin_assignment_show CVE-2023-54197 — kernel: Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" CVE-2023-54201 — kernel: RDMA/efa: Fix wrong resources deallocation order CVE-2023-54214 — kernel: Bluetooth: L2CAP: Fix potential user-after-free CVE-2023-54215 — kernel: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs() CVE-2023-54221 — kernel: clk: imx93: fix memory leak and missing unwind goto in imx93_clocks_probe CVE-2023-54229 — kernel: wifi: fix registration of 6Ghz-only phy without the full channel range CVE-2023-54235 — kernel: PCI/DOE: Fix destroy_work_on_stack() race CVE-2023-54242 — kernel: block, bfq: Fix division by zero error on zero wsum CVE-2023-54251 — kernel: net/sched: taprio: Limit TCA_TAPRIO_ATTR_SCHED_CYCLE_TIME to INT_MAX CVE-2023-54254 — kernel: Kernel: Denial of Service via resource leak in drm/ttm CVE-2023-54260 — kernel: cifs: Fix lost destroy smbd connection when MR allocate failed CVE-2023-54261 — kernel: drm/amdkfd: Add missing gfx11 MQD manager callbacks CVE-2023-54263 — kernel: drm/nouveau/kms/nv50-: init hpd_irq_lock for PIOR DP CVE-2023-54274 — kernel: RDMA/srpt: Add a check for valid 'mad_agent' pointer CVE-2023-54283 — kernel: bpf: Address KCSAN report on bpf_lru_list CVE-2023-54289 — kernel: scsi: qedf: Fix NULL dereference in error handling CVE-2023-54292 — kernel: RDMA/irdma: Fix data race on CQP request done CVE-2023-54296 — kernel: KVM: SVM: Get source vCPUs from source VM for SEV-ES intrahost migration CVE-2023-54302 — kernel: RDMA/irdma: Fix data race on CQP completion stats CVE-2023-54303 — kernel: bpf: Disable preemption in bpf_perf_event_output CVE-2023-54312 — kernel: samples/bpf: Fix buffer overflow in tcp_basertt CVE-2023-54316 — kernel: refscale: Fix uninitalized use of wait_queue_head_t CVE-2023-54324 — kernel: dm: fix a race condition in retrieve_deps CVE-2023-54326 — kernel: misc: pci_endpoint_test: Free IRQs before removing the device CVE-2024-0565 — kernel: CIFS Filesystem Decryption Improper Input Validation Remote Code Execution Vulnerability in function receive_encrypted_standard of client CVE-2024-0841 — kernel: hugetlbfs: Null pointer dereference in hugetlbfs_fill_super function CVE-2024-1085 — kernel: nf_tables: use-after-free vulnerability in the nft_setelem_catchall_deactivate() function CVE-2024-1086 — kernel: nf_tables: use-after-free vulnerability in the nft_verdict_init() function CVE-2024-25744 — kernel: untrusted VMM can trigger int80 syscall handling CVE-2024-26582 — kernel: tls: use-after-free with partial reads and async decrypt CVE-2024-26583 — kernel: tls: race between async notify and socket close CVE-2024-26584 — kernel: tls: handle backlogging of crypto requests CVE-2024-26585 — kernel: tls: race between tx work scheduling and socket close CVE-2024-26586 — kernel: mlxsw: spectrum_acl_tcam: Fix stack corruption CVE-2024-26593 — kernel: i2c: i801: Fix block process call transactions CVE-2024-26602 — kernel: sched/membarrier: reduce the ability to hammer on sys_membarrier CVE-2024-26609 — kernel: netfilter: nf_tables: reject QUEUE/DROP verdict parameters CVE-2024-26633 — kernel: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim() CVE-2024-26649 — kernel: null pointer when load rlc firmware CVE-2024-26671 — kernel: blk-mq: fix IO hang from sbitmap wakeup race CVE-2024-26830 — kernel: i40e: Do not allow untrusted VF to remove administratively set MAC CVE-2025-38053 — kernel: idpf: fix null-ptr-deref in idpf_features_check

🔗 References (75)