- kernel-3.10.0-962.3.2.lve1.5.67.el7 (cl7)
- 3.10.0-962.3.2.lve1.5.67.el7
- 2022-04-27 08:25:07
- CVE CVE-2019-10207, CVSSv2 Score: 4.7
- Description:
[bluetooth] Bluetooth: hci_uart: check for missing tty operations
- Patch: 3.10.0/1106-bluetooth-Bluetooth-hci_uart-check-for-missing-tty-o.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-14283, CVSSv2 Score: 5.6
- Description:
[block] floppy: fix out-of-bounds read in copy_buffer
- Patch: 3.10.0/1107-block-floppy-fix-out-of-bounds-read-in-copy_buffer.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-15221, CVSSv2 Score: 4.6
- Description:
[sound] ALSA: line6: Fix write on zero-sized buffer
- Patch: 3.10.0/1590-sound-ALSA-line6-Fix-write-on-zero-sized-buffer.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-15221, CVSSv2 Score: 4.6
- Description:
[sound] ALSA: line6: Fix memory leak at line6_init_pcm() error path
- Patch: 3.10.0/1607-sound-ALSA-line6-Fix-memory-leak-at-line6_init_pcm-e.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-10638, CVSSv2 Score: 3.7
- Description:
[fs] dcache: allow word-at-a-time name hashing with big-endian CPUs
- Patch: 3.10.0/1696-fs-dcache-allow-word-at-a-time-name-hashing-with-big.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-10638, CVSSv2 Score: 3.7
- Description:
[lib] siphash: add cryptographically secure PRF
- Patch: 3.10.0/1697-lib-siphash-add-cryptographically-secure-PRF.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-10638 CVE-2019-10639, CVSSv2 Score: 3.7
- Description:
[net] inet: switch IP ID generator to siphash
- Patch: 3.10.0/1698-net-inet-switch-IP-ID-generator-to-siphash.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-11190, CVSSv2 Score: 4.7
- Description:
binfmt_elf: switch to new creds when switching to new mm
- Patch: 3.10.0/CVE-2019-11190.patch
- From: >4.8
- CVE CVE-2019-3901, CVSSv2 Score: 5.6
- Description:
[kernel] perf/core: Fix perf_event_open() vs. execve() race
- Patch: 3.10.0/2070-kernel-perf-core-Fix-perf_event_open-vs.-execve-race.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-16746, CVSSv2 Score: 8.4
- Description:
cfg80211: add and use strongly typed element iteration macros
- Patch: 3.10.0/CVE-2019-16746-0001-cfg80211-add-and-use-strongly-typed-element-iteratio.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-16746, CVSSv2 Score: 8.4
- Description:
ieee80211: fix for_each_element_extid()
- Patch: 3.10.0/CVE-2019-16746-0002-ieee80211-fix-for_each_element_extid.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-16746, CVSSv2 Score: 8.4
- Description:
cfg80211: Use const more consistently in for_each_element macros
- Patch: 3.10.0/CVE-2019-16746-0003-cfg80211-Use-const-more-consistently-in-for_each_ele.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-5108, CVSSv2 Score: 6.5
- Description:
[net] mac80211: Do not send Layer 2 Update frame before authorization
- Patch: 3.10.0/2275-net-mac80211-Do-not-send-Layer-2-Update-frame-before.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2019-16746, CVSSv2 Score: 8.4
- Description:
[net] nl80211: validate beacon head
- Patch: 3.10.0/2282-net-nl80211-validate-beacon-head.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2020-10711, CVSSv2 Score: 5.9
- Description:
netlabel: cope with NULL catmap
- Patch: 3.10.0/CVE-2020-10711.patch
- From: kernel-3.10.0-1127.8.2.el7
- CVE CVE-2019-19768, CVSSv2 Score: 7.5
- Description:
blktrace: fix dereference after null check
- Patch: 3.10.0/CVE-2019-19768.patch
- From: kernel-3.10.0-1127.8.2.el7
- CVE CVE-2019-15090, CVSSv2 Score: 6.7
- Description:
scsi: qedi: remove memset/memcpy to nfunc and use func instead
- Patch: 3.10.0/1192-scsi-scsi-qedi-remove-memset-memcpy-to-nfunc-and-use.patch
- From: kernel-3.10.0-1127.el7
- CVE CVE-2020-14305, CVSSv2 Score: 8.1
- Description:
kernel: memory corruption in Voice over IP nf_conntrack_h323 module
- Patch: 3.10.0/CVE-2020-14305.patch
- From: >kernel-3.10.0-1127.13.1.el7
- CVE CVE-2020-12888, CVSSv2 Score: 5.3
- Description:
vfio: access to disabled MMIO space of some devices may lead to DoS scenario
- Patch: 3.10.0/cve-2020-12888-862.patch
- From: kernel-3.10.0-1127.13.1.el7
- CVE CVE-2020-12888, CVSSv2 Score: 5.3
- Description:
vfio: access to disabled MMIO space of some devices may lead to DoS scenario
- Patch: 3.10.0/cve-2020-12888-kpatch-1.patch
- From: kernel-3.10.0-1127.13.1.el7
- CVE CVE-2020-10757, CVSSv2 Score: 7.8
- Description:
mm: Fix mremap not considering huge pmd devmap
- Patch: 3.10.0/CVE-2020-10757.patch
- From: 3.10.0-1127.18.2
- CVE CVE-2019-19527, CVSSv2 Score: 4.6
- Description:
HID: hiddev: avoid opening a disconnected device
- Patch: 3.16.0/cve-2019-19527-usb-hid-avoid-opening-disconnected-device.patch
- From: 3.16.81-1
- CVE CVE-2020-12653, CVSSv2 Score: 7.8
- Description:
mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv()
- Patch: 3.10.0/CVE-2020-12653-mwifiex-fix-possible-buffer-overflows-in-mwifiex_cmd-post-514.patch
- From: 3.10.0-1127.18.2
- CVE CVE-2020-12654, CVSSv2 Score: 7.1
- Description:
mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status()
- Patch: 3.10.0/CVE-2020-12654-mwifiex-fix-possible-buffer-overflows-in-mwifiex_ret-post-514.patch
- From: 3.10.0-1127.18.2
- CVE CVE-2019-0136, CVSSv2 Score: 7.4
- Description:
mac80211: drop robust management frames from unknown TA
- Patch: 3.10.0/CVE-2019-0136-mac80211-drop-robust-management-frames-from-unknown-TA.patch
- From: 3.10.0-1127.el7
- CVE CVE-2020-9383, CVSSv2 Score: 7.1
- Description:
floppy: check FDC index for errors before assigning it
- Patch: 3.10.0/CVE-2020-9383-0314-block-floppy-check-floppy-check-FDC-index-for-errors-before-assig.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-20095, CVSSv2 Score: 5.2
- Description:
mwifiex: Fix mem leak in mwifiex_tm_cmd
- Patch: 3.10.0/CVE-2019-20095-0410-wireless-mwifiex-Fix-mem-leak-in-mwifiex_tm_cmd.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-8647 CVE-2020-8649, CVSSv2 Score: 6.1
- Description:
vgacon: Fix a UAF in vgacon_invert_region
- Patch: 3.10.0/CVE-2020-8647-CVE-2020-8649-0363-video-vgacon-Fix-a-UAF-in-vgacon_invert_region.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-1749, CVSSv2 Score: 7.5
- Description:
ipv6: constify ip6_dst_lookup_{flow|tail}() sock arguments
- Patch: 3.10.0/CVE-2020-1749-0250-net-ipv6-constify-ip6_dst_lookup_-flow-tail-sock-arg.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-2732, CVSSv2 Score: 5.8
- Description:
KVM: nVMX: Don't emulate instructions in guest mode
- Patch: 3.10.0/CVE-2020-2732-0267-x86-kvm-nvmx-Don-t-emulate-instructions-in-guest-mod.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-2732, CVSSv2 Score: 5.8
- Description:
KVM: nVMX: Refactor IO bitmap checks into helper function
- Patch: 3.10.0/CVE-2020-2732-0268-x86-kvm-nvmx-Refactor-IO-bitmap-checks-into-helper-f.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-2732, CVSSv2 Score: 5.8
- Description:
KVM: nVMX: Check IO instruction VM-exit conditions
- Patch: 3.10.0/CVE-2020-2732-0269-x86-kvm-nvmx-Check-IO-instruction-VM-exit-conditions.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-2732, CVSSv2 Score: 5.8
- Description:
KVM: VMX: check descriptor table exits on instruction emulation
- Patch: 3.10.0/CVE-2020-2732-0270-x86-kvm-vmx-check-descriptor-table-exits-on-instruct.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-2732, CVSSv2 Score: 5.8
- Description:
KVM: x86: clear stale x86_emulate_ctxt->intercept value
- Patch: 3.10.0/CVE-2020-2732-0271-x86-kvm-x86-clear-state-x86_emulate_ctxt-intercept-v.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-10942, CVSSv2 Score: 5.3
- Description:
vhost: Check docket sk_family instead of call getname
- Patch: 3.10.0/CVE-2020-10942-0728-vhost-vhost-Check-docket-sk_family-instead-of-call-g.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-20636, CVSSv2 Score: 6.7
- Description:
Input: add safety guards to input_set_keycode
- Patch: 3.10.0/CVE-2019-20636-0469-input-Input-add-safety-guards-to-input_set_keycode.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-10690, CVSSv2 Score:
- Description:
- Patch: skipped/CVE-2020-10690.patch
- From:
- CVE CVE-2020-10732, CVSSv2 Score: 3.3
- Description:
fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info
- Patch: 3.10.0/CVE-2020-10732-0756-fs-fs-binfmt_elf.c-allocate-initialized-memory-in-fi.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-12826, CVSSv2 Score: 5.3
- Description:
signal: Extend exec_id to 64bits
- Patch: 3.10.0/CVE-2020-12826-0707-fs-signal-Extend-exec_id-to-64bits-957.27.2.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-12826, CVSSv2 Score: 5.3
- Description:
signal: Extend exec_id to 64bits (adaptation)
- Patch: 3.10.0/CVE-2020-12826-957.27.2-kpatch.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-12770, CVSSv2 Score: 6.7
- Description:
scsi: sg: add sg_remove_request in sg_write
- Patch: 3.10.0/CVE-2020-12770-0757-scsi-scsi-sg-add-sg_remove_request-in-sg_write.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-10742, CVSSv2 Score: 6.0
- Description:
nfs: Correct an nfs page array calculation error
- Patch: 3.10.0/CVE-2020-10742-0462-fs-nfs-Correct-an-nfs-page-array-calculation-error.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-10751, CVSSv2 Score: 6.1
- Description:
selinux: properly handle multiple messages in selinux_netlink_send
- Patch: 3.10.0/CVE-2020-10751-0749-security-selinux-properly-handle-multiple-messages-i.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-18808, CVSSv2 Score: 5.5
- Description:
crypto: ccp - Release all allocated memory
- Patch: 3.10.0/CVE-2019-18808-0600-crypto-ccp-Release-all-allocate-memory-if-sh.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-17055, CVSSv2 Score: 4.0
- Description:
mISDN: enforce CAP_NET_RAW for raw sockets
- Patch: 3.10.0/CVE-2019-17055-0329-isdn-mISDN-enforce-CAP_NET_RAW-for-raw-sockets.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-17053, CVSSv2 Score: 4.0
- Description:
ieee802154: enforce CAP_NET_RAW for raw sockets
- Patch: 3.10.0/CVE-2019-17053-0248-net-ieee802154-enforce-CAP_NET_RAW-for-raw-sockets.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-16994, CVSSv2 Score: 4.7
- Description:
net: sit: fix memory leak in sit_init_net()
- Patch: 3.10.0/CVE-2019-16994-0574-net-sit-fix-memory-leak-in-sit_init_net.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-16233, CVSSv2 Score: 4.1
- Description:
scsi: qla2xxx: fix a potential NULL pointer dereference
- Patch: 3.10.0/CVE-2019-16233-0442-scsi-scsi-qla2xxx-fix-a-potential-NULL-pointer-deref-862.14.4.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-16231, CVSSv2 Score: 4.1
- Description:
fjes: Handle workqueue allocation failure.
- Patch: 3.10.0/CVE-2019-16231-0566-netdrv-fjes-Handle-workqueue-allocation-failure.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-15917, CVSSv2 Score: 7.0
- Description:
Bluetooth: hci_ldisc: Postpone HCI_UART_PROTO_READY bit set in hci_uart_set_proto()
- Patch: 3.10.0/CVE-2019-15917-0273-bluetooth-Bluetooth-hci_ldsc-Postpone-HCI_UART_PROT.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-15807, CVSSv2 Score: 4.7
- Description:
scsi: libsas: delete sas port if expander discover failed
- Patch: 3.10.0/CVE-2019-15807-0468-scsi-scsi-libsas-delete-sas-port-if-expander-discove.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-15217, CVSSv2 Score: 4.6
- Description:
media: usb:zr364xx:Fix KASAN:null-ptr-deref Read in zr364xx_vidioc_querycap
- Patch: 3.10.0/CVE-2019-15217-0621-media-media-usb-zr364xx-Fix-KASAN-null-ptr-deref-Rea.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-20054, CVSSv2 Score: 5.1
- Description:
fs/proc/proc_sysctl.c: Fix a NULL pointer dereference
- Patch: 3.10.0/CVE-2019-20054-0072-fs-fs-proc-proc_sysctl.c-Fix-a-NULL-pointer-derefere.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19534, CVSSv2 Score: 4.6
- Description:
can: peak_usb: fix slab info leak
- Patch: 3.10.0/CVE-2019-19534-0183-netdrv-can-peak_usb-fix-slab-info-leak.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19447, CVSSv2 Score: 7.8
- Description:
ext4: work around deleting a file with i_nlink == 0 safely
- Patch: 3.10.0/CVE-2019-19447-0197-fs-ext4-work-around-deleting-a-file-with-i_nlink-O-s-cl7.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-9454 CVE-2017-18551, CVSSv2 Score: 6.5
- Description:
i2c: core-smbus: prevent stack corruption on read I2C_BLOCK_DATA
- Patch: 3.10.0/CVE-2017-18551-CVE-2019-9454-0413-i2c-i2c-core-smbus-prevent-stack-corruption-on-read-.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19524, CVSSv2 Score: 4.6
- Description:
Input: ff-memless - kill timer in destroy()
- Patch: 3.10.0/CVE-2019-19524-0443-input-Input-ff-memless-kill-timer-in-destroy.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19058, CVSSv2 Score: 4.7
- Description:
iwlwifi: dbg_ini: fix memory leak in alloc_sgtable
- Patch: 3.10.0/CVE-2019-19058-0487-wireless-iwlwifi-dbg_ini-fix-memory-leaks-in-alloc_sg.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19063, CVSSv2 Score: 4.6
- Description:
rtlwifi: prevent memory leak in rtl_usb_probe
- Patch: 3.10.0/CVE-2019-19063-0488-wireless-rtlwifi-prevent-memory-leak-in-rtl_usb_prob.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19062, CVSSv2 Score: 4.7
- Description:
crypto: user - fix memory leak in crypto_report
- Patch: 3.10.0/CVE-2019-19062-0601-crypto-crypto-user-fix-memory-leak-in-crypto_report.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-9458, CVSSv2 Score: 7.0
- Description:
media: v4l: event: Prevent freeing event subscriptions while accessed
- Patch: 3.10.0/CVE-2019-9458-0604-media-media-v4l-event-Prevent-freeing-event-subscrip.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-9458, CVSSv2 Score: 7.0
- Description:
media: v4l: event: Prevent freeing event subscriptions while accessed (adaptation)
- Patch: 3.10.0/CVE-2019-9458-kpatch.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19767, CVSSv2 Score: 5.5
- Description:
ext4: validate the debug_want_extra_isize mount option at parse time
- Patch: 3.10.0/CVE-2019-19767-0608-fs-ext4-validate-the-debug_want_extra_isize-mount-op-cl7.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19767, CVSSv2 Score: 5.5
- Description:
ext4: forbid i_extra_isize not divisible by 4
- Patch: 3.10.0/CVE-2019-19767-0609-fs-ext4-forbid-i_extra_isize-not-divisible-by-4.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19767, CVSSv2 Score: 5.5
- Description:
ext4: fix support for inode sizes > 1024 bytes
- Patch: 3.10.0/CVE-2019-19767-0611-ext4-fix-support-for-inode-sizes-1024-bytes.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19523, CVSSv2 Score: 7.8
- Description:
USB: adutux: fix use-after-free on disconnect
- Patch: 3.10.0/CVE-2019-19523-0622-usb-USB-adutux-fix-use-after-free-on-disconnect-1062.18.1.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19530, CVSSv2 Score: 5.7
- Description:
usb: cdc-acm: make sure a refcount is taken early enough
- Patch: 3.10.0/CVE-2019-19530-0623-usb-usb-cdc-acm-make-sure-a-refcount-is-taken-early-1062.18.1.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2019-19537, CVSSv2 Score: 4.2
- Description:
USB: core: Fix races in character device registration and deregistraion
- Patch: 3.10.0/CVE-2019-19537-0624-usb-USB-core-Fix-races-in-character-device-registrat.patch
- From: kernel-3.10.0-1160.el7
- CVE CVE-2020-12351, CVSSv2 Score: 7.5
- Description:
Bluetooth: L2CAP: Fix calling sk_filter on non-socket based channel
- Patch: 3.10.0/CVE-2020-12351-Bluetooth-L2CAP-Fix-calling-sk_filter-on-non-socket-.patch
- From: 3.10.0-1160.2.2.el7
- CVE CVE-2020-12352, CVSSv2 Score: 5.3
- Description:
Bluetooth: A2MP: Fix not initializing all members
- Patch: 3.10.0/CVE-2020-12352-Bluetooth-A2MP-Fix-not-initializing-all-members.patch
- From: 3.10.0-1160.2.2.el7
- CVE CVE-2019-20811, CVSSv2 Score: 3.3
- Description:
net-sysfs: call dev_hold if kobject_init_and_add success
- Patch: 3.10.0/cve-2019-20811-call-dev_hold-if-kobject_init_and_add-success.patch
- From: kernel-3.10.0-1160.6.1
- CVE CVE-2019-20811, CVSSv2 Score: 3.3
- Description:
net-sysfs: Call dev_hold always in netdev_queue_add_kobject
- Patch: 3.10.0/cve-2019-20811-call-dev_hold-always-in-netdev_queue_add_kobject.patch
- From: kernel-3.10.0-1160.6.1
- CVE CVE-2019-20811, CVSSv2 Score: 3.3
- Description:
net-sysfs: Call dev_hold always in rx_queue_add_kobject
- Patch: 3.10.0/cve-2019-20811-call-dev_hold-always-in-rx_queue_add_kobject.patch
- From: kernel-3.10.0-1160.6.1
- CVE CVE-2020-14331, CVSSv2 Score: 6.6
- Description:
Fix for missing check in vgacon scrollback handling
- Patch: 3.10.0/cve-2020-14331-vgacon-overflow-fix.patch
- From: kernel-3.10.0-1160.6.1
- CVE CVE-2020-27170, CVSSv2 Score:
- Description:
- Patch: skipped/CVE-2020-27170.patch
- From:
- CVE CVE-2020-27171, CVSSv2 Score:
- Description:
- Patch: skipped/CVE-2020-27171.patch
- From:
- CVE CVE-2020-8648, CVSSv2 Score: 7.1
- Description:
vt: selection, close sel_buffer race
- Patch: 3.10.0/CVE-2020-8648-vt-selection-close-sel_buffer-race-lt-957.10.1.patch
- From: 3.10.0-1160.31.1.el7
- CVE CVE-2020-12362, CVSSv2 Score:
- Description:
- Patch: skipped/CVE-2020-12362.patch
- From:
- CVE CVE-2020-12363, CVSSv2 Score:
- Description:
- Patch: skipped/CVE-2020-12363.patch
- From:
- CVE CVE-2020-12364, CVSSv2 Score:
- Description:
- Patch: skipped/CVE-2020-12364.patch
- From:
- CVE CVE-2020-27777, CVSSv2 Score:
- Description:
- Patch: skipped/CVE-2020-27777.patch
- From:
- CVE CVE-2021-29154, CVSSv2 Score: 7.0
- Description:
bpf, x86: Validate computation of branch displacements for x86-64
- Patch: 3.10.0/CVE-2021-29154-bpf-x86-Validate-computation-of-branch-displacements-for-x86-64.patch
- From: 3.10.0-1160.41.1.el7
- CVE CVE-2021-29650, CVSSv2 Score: 5.5
- Description:
netfilter: x_tables: Use correct memory barriers.
- Patch: 3.10.0/CVE-2021-29650-netfilter-x-tables-use-correct-memory-barriers.patch
- From: 3.10.0-1160.41.1.el7
- CVE CVE-2021-32399, CVSSv2 Score: 7.0
- Description:
bluetooth: eliminate the potential race condition when removing the
- Patch: 3.10.0/CVE-2021-32399-bluetooth-eliminate-the-potential-race-condition-when-removing-the.patch
- From: 3.10.0-1160.41.1.el7
- CVE CVE-2021-3715, CVSSv2 Score: 7.8
- Description:
net_sched: cls_route: remove the right filter from hashtable
- Patch: 3.10.0/CVE-2021-3715-net-sched-cls-route-remove-the-right-filter-from-hashtable.patch
- From: 3.10.0-1160.42.2.el7
- CVE CVE-2020-25704, CVSSv2 Score: 6.2
- Description:
perf/core: Fix a memory leak in perf_event_parse_addr_filter()
- Patch: 3.10.0/CVE-2020-25704-perf-core-Fix-a-memory-leak-in-perf_event_parse_addr_filter.patch
- From: 3.10.0-1160.53.1.el7
- CVE CVE-2021-42739, CVSSv2 Score: 6.7
- Description:
firewire: firedtv-avc: potential buffer overflow
- Patch: 3.10.0/CVE-2021-42739-media-firewire-firedtv-avc-potential-buffer-overflow.patch
- From: 3.10.0-1160.53.1.el7
- CVE CVE-2021-42739, CVSSv2 Score: 6.7
- Description:
media: firewire: firedtv-avc: fix a buffer overflow
- Patch: 3.10.0/CVE-2021-42739-media-firewire-firedtv-avc-fix-more-potential-buffer.patch
- From: 3.10.0-1160.53.1.el7
- CVE CVE-2021-42739, CVSSv2 Score: 6.7
- Description:
[media] firewire: don't break long lines
- Patch: 3.10.0/CVE-2021-42739-media-firewire-don-t-break-long-lines.patch
- From: 3.10.0-1160.53.1.el7
- CVE CVE-2021-42739, CVSSv2 Score: 6.7
- Description:
media: firewire: firedtv-avc: fix a buffer overflow
- Patch: 3.10.0/CVE-2021-42739-media-firewire-firedtv-avc-fix-a-buffer-overflow-in-.patch
- From: 3.10.0-1160.53.1.el7
- CVE CVE-2020-36322, CVSSv2 Score: 5.5
- Description:
fuse: fix bad inode
- Patch: 3.10.0/CVE-2020-36322-750669-fuse-fix-bad-inode.patch
- From: 3.10.0-1160.53.1.el7
- CVE CVE-2020-0465, CVSSv2 Score: 6.6
- Description:
HID: core: Sanitize event code and type when mapping input
- Patch: 3.10.0/CVE-2020-0465-HID-core-Sanitize-event-code-and-type-when-mapping-input.patch
- From: 3.10.0-1169.59.1
- CVE CVE-2021-0920, CVSSv2 Score: 6.4
- Description:
af_unix: fix garbage collect vs MSG_PEEK
- Patch: 3.10.0/CVE-2021-0920-af_unix-fix-garbage-collect-vs-MSG_PEEK.patch
- From: 3.10.0-1160.59.1
- CVE CVE-2021-0920, CVSSv2 Score: 6.4
- Description:
af_unix: fix garbage collect vs MSG_PEEK (adaptation)
- Patch: 3.10.0/CVE-2021-0920-kpatch.patch
- From: 4.1.12-124.59.1.2
- CVE CVE-2021-0920, CVSSv2 Score: 6.4
- Description:
af_unix: fix garbage collect vs MSG_PEEK (adaptation)
- Patch: 3.10.0/CVE-2021-0920-kpatch-2.patch
- From: 4.1.12-124.59.1.2
- CVE CVE-2021-3564, CVSSv2 Score: 5.5
- Description:
Bluetooth: fix the erroneous flush_work() order
- Patch: 3.10.0/CVE-2021-3564-Bluetooth-fix-the-erroneous-flush_work-order.patch
- From: 3.10.0-1160.59.1
- CVE CVE-2021-3573, CVSSv2 Score: 7.8
- Description:
Bluetooth: use correct lock to prevent UAF of hdev object
- Patch: 3.10.0/CVE-2021-3573-Bluetooth-use-correct-lock-to-prevent-UAF-of-hdev-object.patch
- From: 3.10.0-1160.59.1
- CVE CVE-2021-3752, CVSSv2 Score: 7.0
- Description:
Bluetooth: fix use-after-free error in lock_sock_nested()
- Patch: 3.10.0/CVE-2021-3752-Bluetooth-fix-use-after-free-error-in-lock_sock_ne.patch
- From: 3.10.0-1160.59.1
- CVE CVE-2021-4155, CVSSv2 Score: 5.5
- Description:
xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like
- Patch: 3.10.0/CVE-2021-4155-xfs-map-unwritten-blocks-in-XFS_IOC_ALLOC-FREESP-just-like.patch
- From: 3.10.0-1160.59.1
- CVE CVE-2022-0330, CVSSv2 Score: 7.0
- Description:
drm/i915: Flush TLBs before releasing backing store
- Patch: 3.10.0/CVE-2022-0330-drm-i915-Flush-TLBs-before-releasing-backing-store-pre-957-kpatch.patch
- From: 3.10.0-1160.59.1
- CVE CVE-2021-4028, CVSSv2 Score: 7.0
- Description:
RDMA/cma: Do not change route.addr.src_addr.ss_family
- Patch: 3.10.0/CVE-2021-4028-RDMA-cma-Do-not-change-route.addr.src_addr.ss_family.patch
- From: 3.10.0-1160.62.1
- CVE CVE-2021-4083, CVSSv2 Score: 7.0
- Description:
fget: check that the fd still exists after getting a ref to it
- Patch: 3.10.0/CVE-2021-4083-2-introduce-__fcheck_files-to-fix-rcu_dereference_chec-cl7.patch
- From: 3.10.0-1160.62.1.el7
- CVE CVE-2021-4083, CVSSv2 Score: 7.0
- Description:
fget: check that the fd still exists after getting a ref to it
- Patch: 3.10.0/CVE-2021-4083-3-fget-check-that-the-fd-still-exists-after-getting-a-.patch
- From: 3.10.0-1160.62.1.el7
- CVE , CVSSv2 Score:
- Description:
Restrict access to pagemap/kpageflags/kpagecount
- Patch: 3.10.0/proc-restrict-pagemap-access.patch
- From:
- CVE , CVSSv2 Score:
- Description:
- Patch: 3.10.0/paravirt-asm-definition.patch
- From:
- CVE CVE-2022-1016, CVSSv2 Score: 5.5
- Description:
Initialize registers to avoid stack leak into userspace.
- Patch: 3.10.0/CVE-2022-1016-lt-1062.patch
- From: >kernel-3.10.0-1160.62.1.el7
- CVE CVE-2022-1015, CVSSv2 Score: 6.6
- Description:
Bail out in case userspace uses unsupported registers.
- Patch: 3.10.0/CVE-2022-1015.patch
- From: >kernel-3.10.0-1160.62.1.el7