CVE-2022-49440
- EPSS 0.26%
- Veröffentlicht 26.02.2025 07:01:20
- Zuletzt bearbeitet 22.10.2025 17:25:49
In the Linux kernel, the following vulnerability has been resolved: powerpc/rtas: Keep MSR[RI] set when calling RTAS RTAS runs in real mode (MSR[DR] and MSR[IR] unset) and in 32-bit big endian mode (MSR[SF,LE] unset). The change in MSR is done in ...
CVE-2022-49443
- EPSS 0.18%
- Veröffentlicht 26.02.2025 07:01:20
- Zuletzt bearbeitet 01.10.2025 20:16:19
In the Linux kernel, the following vulnerability has been resolved: list: fix a data-race around ep->rdllist ep_poll() first calls ep_events_available() with no lock held and checks if ep->rdllist is empty by list_empty_careful(), which reads rdlli...
CVE-2022-49444
- EPSS 0.29%
- Veröffentlicht 26.02.2025 07:01:20
- Zuletzt bearbeitet 21.10.2025 17:26:10
In the Linux kernel, the following vulnerability has been resolved: module: fix [e_shstrndx].sh_size=0 OOB access It is trivial to craft a module to trigger OOB access in this line: if (info->secstrings[strhdr->sh_size - 1] != '\0') { BUG: unabl...
CVE-2022-49445
- EPSS 0.26%
- Veröffentlicht 26.02.2025 07:01:20
- Zuletzt bearbeitet 01.10.2025 20:16:19
In the Linux kernel, the following vulnerability has been resolved: pinctrl: renesas: core: Fix possible null-ptr-deref in sh_pfc_map_resources() It will cause null-ptr-deref when using 'res', if platform_get_resource() returns NULL, so move using ...
CVE-2022-49428
- EPSS 0.26%
- Veröffentlicht 26.02.2025 07:01:19
- Zuletzt bearbeitet 22.10.2025 17:27:38
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on inline_dots inode As Wenqing reported in bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=215765 It will cause a kernel panic with steps: - m...
CVE-2022-49430
- EPSS 0.26%
- Veröffentlicht 26.02.2025 07:01:19
- Zuletzt bearbeitet 22.10.2025 17:27:21
In the Linux kernel, the following vulnerability has been resolved: Input: gpio-keys - cancel delayed work only in case of GPIO gpio_keys module can either accept gpios or interrupts. The module initializes delayed work in case of gpios only and is...
CVE-2022-49420
- EPSS 0.23%
- Veröffentlicht 26.02.2025 07:01:18
- Zuletzt bearbeitet 21.10.2025 12:13:56
In the Linux kernel, the following vulnerability has been resolved: net: annotate races around sk->sk_bound_dev_if UDP sendmsg() is lockless, and reads sk->sk_bound_dev_if while this field can be changed by another thread. Adds minimal annotations...
CVE-2022-49398
- EPSS 0.26%
- Veröffentlicht 26.02.2025 07:01:16
- Zuletzt bearbeitet 21.10.2025 12:15:09
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Replace list_for_each_entry_safe() if using giveback The list_for_each_entry_safe() macro saves the current item (n) and the item after (n+1), so that n can be s...
CVE-2022-49401
- EPSS 0.26%
- Veröffentlicht 26.02.2025 07:01:16
- Zuletzt bearbeitet 22.09.2025 19:57:51
In the Linux kernel, the following vulnerability has been resolved: mm/page_owner: use strscpy() instead of strlcpy() current->comm[] is not a string (no guarantee for a zero byte in it). strlcpy(s1, s2, l) is calling strlen(s2), potentially causi...
CVE-2022-49390
- EPSS 0.27%
- Veröffentlicht 26.02.2025 07:01:15
- Zuletzt bearbeitet 25.03.2025 13:48:09
In the Linux kernel, the following vulnerability has been resolved: macsec: fix UAF bug for real_dev Create a new macsec device but not get reference to real_dev. That can not ensure that real_dev is freed after macsec. That will trigger the UAF bu...