CLSA-2024-1705494763

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2024-1705494763.json
JSON Data
https://api.test.osv.dev/v1/vulns/CLSA-2024-1705494763
Upstream
Published
2024-01-17T12:32:48Z
Modified
2026-05-27T11:34:06.310443716Z
Summary
kernel: Fix of 13 CVEs
Details
  • Bluetooth: L2CAP: Fix use-after-free in l2capsockready_cb {CVE-2023-40283}
  • ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet {CVE-2023-6932}
  • smb: client: fix OOB in smbCalcSize() {CVE-2023-6606}
  • net/sched: sch_hfsc: Ensure inner classes have fsc curve {CVE-2023-4623}
  • net/sched: cls_fw: Fix improper refcount update leads to use-after-free {CVE-2023-3776}
  • vcscreen: move load of struct vcdata pointer in vcs_read() to avoid UAF {CVE-2023-3567}
  • relayfs: fix out-of-bounds access in relayfileread {CVE-2023-3268}
  • btrfs: unset reloc control if transaction commit fails in preparetorelocate() {CVE-2023-3111}
  • xirc2pscs: Fix use after free bug in xirc2psdetach {CVE-2023-1670}
  • Bluetooth: L2CAP: Fix u8 overflow {CVE-2022-45934}
  • Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM {CVE-2022-42896}
  • tcp: Fix data races around icsk->icskafops. {CVE-2022-3566}
  • ipv6: use prandom_u32() for ID generation {CVE-2021-45485}
References

Affected packages

TuxCare:CentOS:6 / kernel-abi-whitelists

Package

Name
kernel-abi-whitelists
Purl
pkg:rpm/tuxcare/kernel-abi-whitelists?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.32-754.35.8.el6.tuxcare.els14

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2024-1705494763.json"

TuxCare:CentOS:6 / kernel-doc

Package

Name
kernel-doc
Purl
pkg:rpm/tuxcare/kernel-doc?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.32-754.35.8.el6.tuxcare.els14

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2024-1705494763.json"

TuxCare:CentOS:6 / kernel-firmware

Package

Name
kernel-firmware
Purl
pkg:rpm/tuxcare/kernel-firmware?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.32-754.35.8.el6.tuxcare.els14

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2024-1705494763.json"