The Linux Kernel, the operating system core itself.
Security Fix(es):
A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB, becomes actual again for the new hw AmpereOne. Spectre-BHB is similar to Spectre v2, except that malicious code uses the shared branch history (stored in the CPU Branch History Buffer, or BHB) to influence mispredicted branches within the victim's hardware context. Once that occurs, speculation caused by the mispredicted branches can cause cache allocation. This issue leads to obtaining information that should not be accessible.(CVE-2023-3006)
An issue was discovered in drivers/media/dvb-core/dvbfrontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASKRUNNING. In dvbfrontendgetevent, waiteventinterruptible is called; the condition is dvbfrontendtestevent(fepriv,events). In dvbfrontendtestevent, down(&fepriv->sem) is called. However, waitevent_interruptible would put the process to sleep, and down(&fepriv->sem) may block the process.(CVE-2023-31084)
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbconsetfont, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.(CVE-2023-3161)
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.(CVE-2023-3212)
* DISPUTED * An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4groupdesc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the block device while it is mounted by the filesystem" access.(CVE-2023-34256)
An issue was discovered in flsetgeneveopt in net/sched/clsflower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCAFLOWERKEYENCOPTS_GENEVE packets. This may result in denial of service or privilege escalation.(CVE-2023-35788)
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.(CVE-2023-35823)
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c.(CVE-2023-35824)
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesasusb3remove in drivers/usb/gadget/udc/renesas_usb3.c.(CVE-2023-35828)
{ "severity": "High" }
{ "src": [ "kernel-5.10.0-136.39.0.116.oe2203sp1.src.rpm" ], "x86_64": [ "bpftool-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "kernel-source-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "kernel-devel-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "python3-perf-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "kernel-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "python3-perf-debuginfo-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "kernel-tools-devel-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "kernel-debuginfo-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "bpftool-debuginfo-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "kernel-tools-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "kernel-debugsource-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "kernel-tools-debuginfo-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "perf-debuginfo-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "kernel-headers-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm", "perf-5.10.0-136.39.0.116.oe2203sp1.x86_64.rpm" ], "aarch64": [ "python3-perf-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "kernel-devel-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "kernel-tools-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "perf-debuginfo-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "kernel-debuginfo-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "kernel-tools-devel-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "perf-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "bpftool-debuginfo-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "bpftool-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "kernel-debugsource-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "kernel-source-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "kernel-headers-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "python3-perf-debuginfo-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "kernel-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm", "kernel-tools-debuginfo-5.10.0-136.39.0.116.oe2203sp1.aarch64.rpm" ] }