blob: 37c514e613cfd7bd657f116208aa7ecb1479d24b [file] [log] [blame]
CVEs fixed in 4.11:
CVE-2017-7477: 4d6fa57b4dab0d77f4d8e9d9c73d1e63f6fe8fee macsec: avoid heap overflow in skb_to_sgvec
CVE-2017-7645: e6838a29ecb484c97e4efef9429643b9851fba6e nfsd: check for oversized NFSv2/v3 arguments
CVE-2017-7895: 13bf9fbff0e5e099e2b6f003a0ab8ae145436309 nfsd: stricter decoding of write-like NFSv2/v3 ops
CVEs fixed in 4.11.1:
CVE-2017-10662: c7f765b5d6bda480ae1aa2bf5734c9613d851f5f f2fs: sanity check segment count
CVE-2017-9150: ced12308e58cc95002404b584fdc756a233581ab bpf: don't let ldimm64 leak map addresses on unprivileged
CVEs fixed in 4.11.3:
CVE-2017-1000363: 28c7411cdbc41396dceff7e1b37dbb659f7bdfb2 char: lp: fix possible integer overflow in lp_setup()
CVE-2017-18360: 3a82455292c2b817031db57f6954f8b7e7b1dd38 USB: serial: io_ti: fix div-by-zero in set_termios
CVE-2017-7487: b13b3f39851681b3e7f0f4ea2fcea4a0e47f4f0a ipx: call ipxitf_put() in ioctl error path
CVE-2017-8797: 06cc61e8f9edb5d50156622c0940b32e8cca0f3a nfsd: fix undefined behavior in nfsd4_layout_verify
CVEs fixed in 4.11.4:
CVE-2017-18221: f814bf465578b4bf2d4ae1329e8f35d89c040d2d mlock: fix mlock count can not decrease in race condition
CVE-2017-8890: db8ebc6da8cfd1057dc94e69fbd7a8c5ff34cef6 dccp/tcp: do not inherit mc_list from parent
CVE-2017-9074: 9909e4e4ff16e3f66b4e33e118621d7fe92fc6d4 ipv6: Prevent overrun when parsing v6 header options
CVE-2017-9075: 703a20827411c3906b644713bc4462d4b3fb6a5f sctp: do not inherit ipv6_{mc|ac|fl}_list from parent
CVE-2017-9076: 8e929937f8813fb209a2d733ee1367db80b6f622 ipv6/dccp: do not inherit ipv6_mc_list from parent
CVE-2017-9077: 8e929937f8813fb209a2d733ee1367db80b6f622 ipv6/dccp: do not inherit ipv6_mc_list from parent
CVE-2017-9211: f5eef8d2458bb569ca521b3c2b0a19af62536745 crypto: skcipher - Add missing API setkey checks
CVE-2017-9242: 827624c3d1cfd1b569ec2c6593a6a50ab65c72bb ipv6: fix out of bound writes in __ip6_append_data()
CVEs fixed in 4.11.5:
CVE-2017-1000380: 9018818b2410fcaf51042f1c0315cc4498c6c6e9 ALSA: timer: Fix race between read and ioctl
CVE-2017-15274: 5def69023aec63f6d2facb39fde6f4cdf9c12710 KEYS: fix dereferencing NULL payload with nonzero length
CVE-2017-7346: 6a6a4857199fb593b2e14621304546977a5acff3 drm/vmwgfx: limit the number of mip levels in vmw_gb_surface_define_ioctl()
CVE-2017-9605: 3bc7a4a5643e79a819ac56132826480d5102d48c drm/vmwgfx: Make sure backup_handle is always valid
CVEs fixed in 4.11.7:
CVE-2017-1000364: 27f9070614aa5f05dc00e06bc288ac9e0ca7d430 mm: larger stack guard gap, between vmas
CVE-2017-1000379: 27f9070614aa5f05dc00e06bc288ac9e0ca7d430 mm: larger stack guard gap, between vmas
CVEs fixed in 4.11.8:
CVE-2017-1000365: fed07e89078ddfbdddb2c54f340a934e94bee2b2 fs/exec.c: account for argv/envp pointers
CVE-2017-10911: b919d2dc590952b2985e43d03b2724b84e5dc2a0 xen-blkback: don't leak stack data via response ring
CVE-2017-7482: 575cd7d4cec3ad0aa13c9d156fbcc3979db6f3ae rxrpc: Fix several cases where a padded len isn't checked in ticket decode
CVE-2017-7518: 3af2b32a50c23af81403e6fed880f18e9ae0cb30 KVM: x86: fix singlestepping over syscall
CVEs fixed in 4.11.10:
CVE-2017-10810: a2746d8b78fa470f43de7b3a472f8854fb8fa423 drm/virtio: don't leak bo on drm_gem_object_init failure
CVE-2017-12146: 89488f31939230feadf0f2324ed2920888b616de driver core: platform: fix race condition with driver_override
CVEs fixed in 4.11.11:
CVE-2017-11176: c353aee3bcd93a7529e5f971ab4dee21762c1baa mqueue: fix a use-after-free in sys_mq_notify()
CVEs fixed in 4.11.12:
CVE-2017-1000370: 9b1bbf6ea9b2b596ba271bec23b93c48181ad896 binfmt_elf: use ELF_ET_DYN_BASE only for PIE
CVE-2017-1000371: 9b1bbf6ea9b2b596ba271bec23b93c48181ad896 binfmt_elf: use ELF_ET_DYN_BASE only for PIE
CVE-2017-11089: 61d3f24df74b44a00f4662a679446d0ed1f5fdf5 cfg80211: Define nla_policy for NL80211_ATTR_LOCAL_MESH_POWER_MODE
CVE-2017-7541: 0dc4be778d53ba5ffc2ef434f7c6eabdf509e802 brcmfmac: fix possible buffer overflow in brcmf_cfg80211_mgmt_tx()
CVE-2018-14634: 2ee500dcfdcb688aceb06ea164541a5e99aecfac exec: Limit arg stack to at most 75% of _STK_LIM
CVE-2019-9457: 2ee500dcfdcb688aceb06ea164541a5e99aecfac exec: Limit arg stack to at most 75% of _STK_LIM
Outstanding CVEs:
CVE-2005-3660: (unk)
CVE-2007-3719: (unk)
CVE-2008-2544: (unk)
CVE-2008-4609: (unk)
CVE-2010-4563: (unk)
CVE-2010-5321: (unk)
CVE-2011-4916: (unk)
CVE-2011-4917: (unk)
CVE-2012-4542: (unk)
CVE-2013-7445: (unk)
CVE-2015-2877: (unk)
CVE-2016-10723: (unk) mm, oom: remove sleep from under oom_lock
CVE-2016-8660: (unk)
CVE-2017-0605: (unk) tracing: Use strlcpy() instead of strcpy() in __trace_find_cmdline()
CVE-2017-0627: (unk) media: uvcvideo: Prevent heap overflow when accessing mapped controls
CVE-2017-0786: (unk) brcmfmac: add length check in brcmf_cfg80211_escan_handler()
CVE-2017-0861: (unk) ALSA: pcm: prevent UAF in snd_pcm_info
CVE-2017-1000: (unk) udp: consistently apply ufo or fragmentation
CVE-2017-1000111: (unk) packet: fix tp_reserve race in packet_set_ring
CVE-2017-1000112: (unk) udp: consistently apply ufo or fragmentation
CVE-2017-1000251: (unk) Bluetooth: Properly check L2CAP config option output buffer length
CVE-2017-1000252: (unk) KVM: VMX: Do not BUG() on out-of-bounds guest IRQ
CVE-2017-1000255: (unk) powerpc/64s: Use emergency stack for kernel TM Bad Thing program checks
CVE-2017-1000405: (unk) mm, thp: Do not make page table dirty unconditionally in touch_p[mu]d()
CVE-2017-1000407: (unk) KVM: VMX: remove I/O port 0x80 bypass on Intel hosts
CVE-2017-1000410: (unk) Bluetooth: Prevent stack info leak from the EFS element.
CVE-2017-10663: (unk) f2fs: sanity check checkpoint segno and blkoff
CVE-2017-11472: (unk) ACPICA: Namespace: fix operand cache leak
CVE-2017-11473: (unk) x86/acpi: Prevent out of bound access caused by broken ACPI tables
CVE-2017-11600: (unk) xfrm: policy: check policy direction value
CVE-2017-12134: (unk) xen: fix bio vec merging
CVE-2017-12153: (unk) nl80211: check for the required netlink attributes presence
CVE-2017-12154: (unk) kvm: nVMX: Don't allow L2 to access the hardware CR8
CVE-2017-12188: (unk) KVM: nVMX: update last_nonleaf_level when initializing nested EPT
CVE-2017-12190: (unk) fix unbalanced page refcounting in bio_map_user_iov
CVE-2017-12192: (unk) KEYS: prevent KEYCTL_READ on negative key
CVE-2017-12193: (unk) assoc_array: Fix a buggy node-splitting case
CVE-2017-12762: (unk) isdn/i4l: fix buffer overflow
CVE-2017-13080: (unk) mac80211: accept key reinstall without changing anything
CVE-2017-13166: (unk) media: v4l2-ioctl.c: use check_fmt for enum/g/s/try_fmt
CVE-2017-13168: (unk) scsi: sg: mitigate read/write abuse
CVE-2017-13216: (unk) staging: android: ashmem: fix a race condition in ASHMEM_SET_SIZE ioctl
CVE-2017-13305: (unk) KEYS: encrypted: fix buffer overread in valid_master_desc()
CVE-2017-13693: (unk)
CVE-2017-13694: (unk)
CVE-2017-13695: (unk) ACPICA: acpi: acpica: fix acpi operand cache leak in nseval.c
CVE-2017-14051: (unk) scsi: qla2xxx: Fix an integer overflow in sysfs code
CVE-2017-14106: (unk) tcp: initialize rcv_mss to TCP_MIN_MSS instead of 0
CVE-2017-14140: (unk) Sanitize 'move_pages()' permission checks
CVE-2017-14156: (unk) video: fbdev: aty: do not leak uninitialized padding in clk to userspace
CVE-2017-14340: (unk) xfs: XFS_IS_REALTIME_INODE() should be false if no rt device present
CVE-2017-14489: (unk) scsi: scsi_transport_iscsi: fix the issue that iscsi_if_rx doesn't parse nlmsg properly
CVE-2017-14497: (unk) packet: Don't write vnet header beyond end of buffer
CVE-2017-14991: (unk) scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE
CVE-2017-15115: (unk) sctp: do not peel off an assoc from one netns to another one
CVE-2017-15126: (unk) userfaultfd: non-cooperative: fix fork use after free
CVE-2017-15127: (unk) userfaultfd: hugetlbfs: remove superfluous page unlock in VM_SHARED case
CVE-2017-15128: (unk) userfaultfd: hugetlbfs: prevent UFFDIO_COPY to fill beyond the end of i_size
CVE-2017-15129: (unk) net: Fix double free and memory corruption in get_net_ns_by_id()
CVE-2017-15265: (unk) ALSA: seq: Fix use-after-free at creating a port
CVE-2017-15299: (unk) KEYS: don't let add_key() update an uninstantiated key
CVE-2017-15306: (unk) KVM: PPC: Fix oops when checking KVM_CAP_PPC_HTM
CVE-2017-15537: (unk) x86/fpu: Don't let userspace set bogus xcomp_bv
CVE-2017-15649: (unk) packet: in packet_do_bind, test fanout with bind_lock held
CVE-2017-15951: (unk) KEYS: Fix race between updating and finding a negative key
CVE-2017-16525: (unk) USB: serial: console: fix use-after-free after failed setup
CVE-2017-16526: (unk) uwb: properly check kthread_run return value
CVE-2017-16527: (unk) ALSA: usb-audio: Kill stray URB at exiting
CVE-2017-16528: (unk) ALSA: seq: Cancel pending autoload work at unbinding device
CVE-2017-16529: (unk) ALSA: usb-audio: Check out-of-bounds access by corrupted buffer descriptor
CVE-2017-16530: (unk) USB: uas: fix bug in handling of alternate settings
CVE-2017-16531: (unk) USB: fix out-of-bounds in usb_set_configuration
CVE-2017-16532: (unk) usb: usbtest: fix NULL pointer dereference
CVE-2017-16533: (unk) HID: usbhid: fix out-of-bounds bug
CVE-2017-16534: (unk) USB: core: harden cdc_parse_cdc_header
CVE-2017-16535: (unk) USB: core: fix out-of-bounds access bug in usb_get_bos_descriptor()
CVE-2017-16536: (unk) [media] cx231xx-cards: fix NULL-deref on missing association descriptor
CVE-2017-16537: (unk) media: imon: Fix null-ptr-deref in imon_probe
CVE-2017-16538: (unk) media: dvb-usb-v2: lmedm04: Improve logic checking of warm start
CVE-2017-16643: (unk) Input: gtco - fix potential out-of-bound access
CVE-2017-16644: (unk) media: hdpvr: Fix an error handling path in hdpvr_probe()
CVE-2017-16645: (unk) Input: ims-psu - check if CDC union descriptor is sane
CVE-2017-16646: (unk) media: dib0700: fix invalid dvb_detach argument
CVE-2017-16647: (unk) net: usb: asix: fill null-ptr-deref in asix_suspend
CVE-2017-16648: (unk) dvb_frontend: don't use-after-free the frontend struct
CVE-2017-16649: (unk) net: cdc_ether: fix divide by 0 on bad descriptors
CVE-2017-16650: (unk) net: qmi_wwan: fix divide by 0 on bad descriptors
CVE-2017-16911: (unk) usbip: prevent vhci_hcd driver from leaking a socket pointer address
CVE-2017-16912: (unk) usbip: fix stub_rx: get_pipe() to validate endpoint number
CVE-2017-16913: (unk) usbip: fix stub_rx: harden CMD_SUBMIT path to handle malicious input
CVE-2017-16914: (unk) usbip: fix stub_send_ret_submit() vulnerability to null transfer_buffer
CVE-2017-16939: (unk) ipsec: Fix aborted xfrm policy dump crash
CVE-2017-16994: (unk) mm/pagewalk.c: report holes in hugetlb ranges
CVE-2017-16995: (unk) bpf: fix incorrect sign extension in check_alu_op()
CVE-2017-17052: (unk) fork: fix incorrect fput of ->exe_file causing use-after-free
CVE-2017-17053: (unk) x86/mm: Fix use-after-free of ldt_struct
CVE-2017-17448: (unk) netfilter: nfnetlink_cthelper: Add missing permission checks
CVE-2017-17449: (unk) netlink: Add netns check on taps
CVE-2017-17450: (unk) netfilter: xt_osf: Add missing permission checks
CVE-2017-17558: (unk) USB: core: prevent malicious bNumInterfaces overflow
CVE-2017-17712: (unk) net: ipv4: fix for a race condition in raw_sendmsg
CVE-2017-17741: (unk) KVM: Fix stack-out-of-bounds read in write_mmio
CVE-2017-17805: (unk) crypto: salsa20 - fix blkcipher_walk API usage
CVE-2017-17806: (unk) crypto: hmac - require that the underlying hash algorithm is unkeyed
CVE-2017-17807: (unk) KEYS: add missing permission check for request_key() destination
CVE-2017-17862: (unk) bpf: fix branch pruning logic
CVE-2017-17863: (unk) bpf: fix integer overflows
CVE-2017-17975: (unk) media: usbtv: prevent double free in error case
CVE-2017-18075: (unk) crypto: pcrypt - fix freeing pcrypt instances
CVE-2017-18079: (unk) Input: i8042 - fix crash at boot time
CVE-2017-18193: (unk) f2fs: fix a bug caused by NULL extent tree
CVE-2017-18202: (unk) mm, oom_reaper: gather each vma to prevent leaking TLB entry
CVE-2017-18203: (unk) dm: fix race between dm_get_from_kobject() and __dm_destroy()
CVE-2017-18204: (unk) ocfs2: should wait dio before inode lock in ocfs2_setattr()
CVE-2017-18208: (unk) mm/madvise.c: fix madvise() infinite loop under special circumstances
CVE-2017-18216: (unk) ocfs2: subsystem.su_mutex is required while accessing the item->ci_parent
CVE-2017-18218: (unk) net: hns: Fix a skb used after free bug
CVE-2017-18222: (unk) net: hns: fix ethtool_get_strings overflow in hns driver
CVE-2017-18224: (unk) ocfs2: ip_alloc_sem should be taken in ocfs2_get_block()
CVE-2017-18232: (unk) scsi: libsas: direct call probe and destruct
CVE-2017-18241: (unk) f2fs: fix a panic caused by NULL flush_cmd_control
CVE-2017-18249: (unk) f2fs: fix race condition in between free nid allocator/initializer
CVE-2017-18261: (unk) clocksource/drivers/arm_arch_timer: Avoid infinite recursion when ftrace is enabled
CVE-2017-18270: (unk) KEYS: prevent creating a different user's keyrings
CVE-2017-18344: (unk) posix-timer: Properly check sigevent->sigev_notify
CVE-2017-18379: (unk) nvmet-fc: ensure target queue id within range.
CVE-2017-18549: (unk) scsi: aacraid: Don't copy uninitialized stack memory to userspace
CVE-2017-18550: (unk) scsi: aacraid: Don't copy uninitialized stack memory to userspace
CVE-2017-18551: (unk) i2c: core-smbus: prevent stack corruption on read I2C_BLOCK_DATA
CVE-2017-18595: (unk) tracing: Fix possible double free on failure of allocating trace buffer
CVE-2017-5715: (unk) x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]
CVE-2017-5753: (unk) x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]
CVE-2017-5754: (unk) x86/cpufeatures: Add Intel feature bits for Speculation Control
CVE-2017-7533: (unk) dentry name snapshots
CVE-2017-7542: (unk) ipv6: avoid overflow of offset in ip6_find_1stfragopt
CVE-2017-7558: (unk) sctp: Avoid out-of-bounds reads from address storage
CVE-2017-8824: (unk) dccp: CVE-2017-8824: use-after-free in DCCP code
CVE-2017-8831: (unk) [media] saa7164: fix double fetch PCIe access condition
CVE-2017-9059: (unk) NFSv4: Fix callback server shutdown
CVE-2017-9984: (unk) ALSA: msnd: Optimize / harden DSP and MIDI loops
CVE-2017-9985: (unk) ALSA: msnd: Optimize / harden DSP and MIDI loops
CVE-2017-9986: (unk) sound: Retire OSS
CVE-2018-1000004: (unk) ALSA: seq: Make ioctls race-free
CVE-2018-1000026: (unk) bnx2x: disable GSO where gso_size is too big for hardware
CVE-2018-1000028: (unk) nfsd: auth: Fix gid sorting when rootsquash enabled
CVE-2018-1000199: (unk) perf/hwbp: Simplify the perf-hwbp code, fix documentation
CVE-2018-1000204: (unk) scsi: sg: allocate with __GFP_ZERO in sg_build_indirect()
CVE-2018-10021: (unk) scsi: libsas: defer ata device eh commands to libata
CVE-2018-10087: (unk) kernel/exit.c: avoid undefined behaviour when calling wait4()
CVE-2018-10124: (unk) kernel/signal.c: avoid undefined behaviour in kill_something_info
CVE-2018-10322: (unk) xfs: enhance dinode verifier
CVE-2018-10323: (unk) xfs: set format back to extents if xfs_bmap_extents_to_btree
CVE-2018-1065: (unk) netfilter: add back stackpointer size checks
CVE-2018-10675: (unk) mm/mempolicy: fix use after free when calling get_mempolicy
CVE-2018-1068: (unk) netfilter: ebtables: CONFIG_COMPAT: don't trust userland offsets
CVE-2018-10853: (unk) kvm: x86: use correct privilege level for sgdt/sidt/fxsave/fxrstor access
CVE-2018-1087: (unk) kvm/x86: fix icebp instruction handling
CVE-2018-10876: (unk) ext4: only look at the bg_flags field if it is valid
CVE-2018-10877: (unk) ext4: verify the depth of extent tree in ext4_find_extent()
CVE-2018-10878: (unk) ext4: always check block group bounds in ext4_init_block_bitmap()
CVE-2018-10879: (unk) ext4: make sure bitmaps and the inode table don't overlap with bg descriptors
CVE-2018-10880: (unk) ext4: never move the system.data xattr out of the inode body
CVE-2018-10881: (unk) ext4: clear i_data in ext4_inode_info when removing inline data
CVE-2018-10882: (unk) ext4: add more inode number paranoia checks
CVE-2018-10883: (unk) jbd2: don't mark block as modified if the handle is out of credits
CVE-2018-10902: (unk) ALSA: rawmidi: Change resized buffers atomically
CVE-2018-1092: (unk) ext4: fail ext4_iget for root directory if unallocated
CVE-2018-1093: (unk) ext4: add validity checks for bitmap block numbers
CVE-2018-10938: (unk) Cipso: cipso_v4_optptr enter infinite loop
CVE-2018-10940: (unk) cdrom: information leak in cdrom_ioctl_media_changed()
CVE-2018-1108: (unk) random: fix crng_ready() test
CVE-2018-1118: (unk) vhost: fix info leak due to uninitialized memory
CVE-2018-1120: (unk) proc: do not access cmdline nor environ from file-backed areas
CVE-2018-1121: (unk)
CVE-2018-1128: (unk) libceph: add authorizer challenge
CVE-2018-1129: (unk) libceph: implement CEPHX_V2 calculation mode
CVE-2018-1130: (unk) dccp: check sk for closed state in dccp_sendmsg()
CVE-2018-11506: (unk) sr: pass down correctly sized SCSI sense buffer
CVE-2018-12126: (unk) s390/speculation: Support 'mitigations=' cmdline option
CVE-2018-12127: (unk) s390/speculation: Support 'mitigations=' cmdline option
CVE-2018-12130: (unk) s390/speculation: Support 'mitigations=' cmdline option
CVE-2018-12207: (unk) kvm: x86, powerpc: do not allow clearing largepages debugfs entry
CVE-2018-12232: (unk) socket: close race condition between sock_close() and sockfs_setattr()
CVE-2018-12233: (unk) jfs: Fix inconsistency between memory allocation and ea_buf->max_size
CVE-2018-12896: (unk) posix-timers: Sanitize overrun handling
CVE-2018-12928: (unk)
CVE-2018-12929: (unk)
CVE-2018-12930: (unk)
CVE-2018-12931: (unk)
CVE-2018-13053: (unk) alarmtimer: Prevent overflow for relative nanosleep
CVE-2018-13093: (unk) xfs: validate cached inodes are free when allocated
CVE-2018-13094: (unk) xfs: don't call xfs_da_shrink_inode with NULL bp
CVE-2018-13095: (unk) xfs: More robust inode extent count validation
CVE-2018-13096: (unk) f2fs: fix to do sanity check with node footer and iblocks
CVE-2018-13097: (unk) f2fs: fix to do sanity check with user_block_count
CVE-2018-13098: (unk) f2fs: fix to do sanity check with extra_attr feature
CVE-2018-13099: (unk) f2fs: fix to do sanity check with reserved blkaddr of inline inode
CVE-2018-13100: (unk) f2fs: fix to do sanity check with secs_per_zone
CVE-2018-13405: (unk) Fix up non-directory creation in SGID directories
CVE-2018-13406: (unk) video: uvesafb: Fix integer overflow in allocation
CVE-2018-14609: (unk) btrfs: relocation: Only remove reloc rb_trees if reloc control has been initialized
CVE-2018-14610: (unk) btrfs: Check that each block group has corresponding chunk at mount time
CVE-2018-14611: (unk) btrfs: validate type when reading a chunk
CVE-2018-14612: (unk) btrfs: tree-checker: Detect invalid and empty essential trees
CVE-2018-14613: (unk) btrfs: tree-checker: Verify block_group_item
CVE-2018-14614: (unk) f2fs: fix to do sanity check with cp_pack_start_sum
CVE-2018-14616: (unk) f2fs: fix to do sanity check with block address in main area v2
CVE-2018-14617: (unk) hfsplus: fix NULL dereference in hfsplus_lookup()
CVE-2018-14625: (unk) vhost/vsock: fix use-after-free in network stack callers
CVE-2018-14633: (unk) scsi: target: iscsi: Use hex2bin instead of a re-implementation
CVE-2018-14734: (unk) infiniband: fix a possible use-after-free bug
CVE-2018-15471: (unk) xen-netback: fix input validation in xenvif_set_hash_mapping()
CVE-2018-15572: (unk) x86/speculation: Protect against userspace-userspace spectreRSB
CVE-2018-16276: (unk) USB: yurex: fix out-of-bounds uaccess in read handler
CVE-2018-16658: (unk) cdrom: Fix info leak/OOB read in cdrom_ioctl_drive_status
CVE-2018-16862: (unk) mm: cleancache: fix corruption on missed inode invalidation
CVE-2018-16871: (unk) nfsd: COPY and CLONE operations require the saved filehandle to be set
CVE-2018-16884: (unk) sunrpc: use-after-free in svc_process_common()
CVE-2018-17182: (unk) mm: get rid of vmacache_flush_all() entirely
CVE-2018-17972: (unk) proc: restrict kernel stack dumps to root
CVE-2018-17977: (unk)
CVE-2018-18021: (unk) arm64: KVM: Tighten guest core register access from userspace
CVE-2018-18281: (unk) mremap: properly flush TLB before releasing the page
CVE-2018-18386: (unk) n_tty: fix EXTPROC vs ICANON interaction with TIOCINQ (aka FIONREAD)
CVE-2018-18397: (unk) userfaultfd: use ENOENT instead of EFAULT if the atomic copy user fails
CVE-2018-18559: (unk) net/packet: fix a race in packet_bind() and packet_notifier()
CVE-2018-18690: (unk) xfs: don't fail when converting shortform attr to long form during ATTR_REPLACE
CVE-2018-18710: (unk) cdrom: fix improper type cast, which can leat to information leak.
CVE-2018-19407: (unk) KVM: X86: Fix scan ioapic use-before-initialization
CVE-2018-19824: (unk) ALSA: usb-audio: Fix UAF decrement if card has no live interfaces in card.c
CVE-2018-19985: (unk) USB: hso: Fix OOB memory access in hso_probe/hso_get_config_data
CVE-2018-20169: (unk) USB: check usb_get_extra_descriptor for proper size
CVE-2018-20449: (unk) printk: hash addresses printed with %p
CVE-2018-20509: (unk) binder: refactor binder ref inc/dec for thread safety
CVE-2018-20510: (unk) binder: replace "%p" with "%pK"
CVE-2018-20511: (unk) net/appletalk: fix minor pointer leak to userspace in SIOCFINDIPDDPRT
CVE-2018-20836: (unk) scsi: libsas: fix a race condition when smp task timeout
CVE-2018-20854: (unk) phy: ocelot-serdes: fix out-of-bounds read
CVE-2018-20855: (unk) IB/mlx5: Fix leaking stack memory to userspace
CVE-2018-20856: (unk) block: blk_init_allocated_queue() set q->fq as NULL in the fail case
CVE-2018-20961: (unk) USB: gadget: f_midi: fixing a possible double-free in f_midi
CVE-2018-20976: (unk) xfs: clear sb->s_fs_info on mount failure
CVE-2018-21008: (unk) rsi: add fix for crash during assertions
CVE-2018-25020: (unk) bpf: fix truncated jump targets on heavy expansions
CVE-2018-3620: (unk) x86/microcode: Allow late microcode loading with SMT disabled
CVE-2018-3639: (unk) x86/nospec: Simplify alternative_msr_write()
CVE-2018-3646: (unk) x86/microcode: Allow late microcode loading with SMT disabled
CVE-2018-3693: (unk) ext4: fix spectre gadget in ext4_mb_regular_allocator()
CVE-2018-5332: (unk) RDS: Heap OOB write in rds_message_alloc_sgs()
CVE-2018-5333: (unk) RDS: null pointer dereference in rds_atomic_free_op
CVE-2018-5344: (unk) loop: fix concurrent lo_open/lo_release
CVE-2018-5390: (unk) tcp: free batches of packets in tcp_prune_ofo_queue()
CVE-2018-5391: (unk) ip: discard IPv4 datagrams with overlapping segments.
CVE-2018-5750: (unk) ACPI: sbshc: remove raw pointer from printk() message
CVE-2018-5803: (unk) sctp: verify size of a new chunk in _sctp_make_chunk()
CVE-2018-5814: (unk) usbip: usbip_host: fix NULL-ptr deref and use-after-free errors
CVE-2018-5848: (unk) wil6210: missing length check in wmi_set_ie
CVE-2018-5953: (unk) printk: hash addresses printed with %p
CVE-2018-5995: (unk) printk: hash addresses printed with %p
CVE-2018-6412: (unk) fbdev: Fixing arbitrary kernel leak in case FBIOGETCMAP_SPARC in sbusfb_ioctl_helper().
CVE-2018-6554: (unk) staging: irda: remove the irda network stack and drivers
CVE-2018-6555: (unk) staging: irda: remove the irda network stack and drivers
CVE-2018-6927: (unk) futex: Prevent overflow by strengthen input validation
CVE-2018-7191: (unk) tun: call dev_get_valid_name() before register_netdevice()
CVE-2018-7273: (unk) printk: hash addresses printed with %p
CVE-2018-7492: (unk) rds: Fix NULL pointer dereference in __rds_rdma_map
CVE-2018-7566: (unk) ALSA: seq: Fix racy pool initializations
CVE-2018-7740: (unk) hugetlbfs: check for pgoff value overflow
CVE-2018-7754: (unk) printk: hash addresses printed with %p
CVE-2018-7755: (unk) floppy: Do not copy a kernel pointer to user memory in FDGETPRM ioctl
CVE-2018-7757: (unk) scsi: libsas: fix memory leak in sas_smp_get_phy_events()
CVE-2018-7995: (unk) x86/MCE: Serialize sysfs changes
CVE-2018-8043: (unk) net: phy: mdio-bcm-unimac: fix potential NULL dereference in unimac_mdio_probe()
CVE-2018-8087: (unk) mac80211_hwsim: fix possible memory leak in hwsim_new_radio_nl()
CVE-2018-8781: (unk) drm: udl: Properly check framebuffer mmap offsets
CVE-2018-8822: (unk) staging: ncpfs: memory corruption in ncp_read_kernel()
CVE-2018-8897: (unk) x86/entry/64: Don't use IST entry for #BP stack
CVE-2018-9363: (unk) Bluetooth: hidp: buffer overflow in hidp_process_report
CVE-2018-9385: (unk) ARM: amba: Don't read past the end of sysfs "driver_override" buffer
CVE-2018-9415: (unk) ARM: amba: Fix race condition with driver_override
CVE-2018-9465: (unk) binder: fix proc->files use-after-free
CVE-2018-9516: (unk) HID: debug: check length before copy_to_user()
CVE-2018-9517: (unk) l2tp: pass tunnel pointer to ->session_create()
CVE-2018-9518: (unk) NFC: llcp: Limit size of SDP URI
CVE-2018-9568: (unk) net: Set sk_prot_creator when cloning sockets to the right proto
CVE-2019-0136: (unk) mac80211: drop robust management frames from unknown TA
CVE-2019-0145: (unk) i40e: add num_vectors checker in iwarp handler
CVE-2019-0146: (unk) i40e: add num_vectors checker in iwarp handler
CVE-2019-0147: (unk) i40e: add num_vectors checker in iwarp handler
CVE-2019-0148: (unk) i40e: Wrong truncation from u16 to u8
CVE-2019-0154: (unk) drm/i915: Lower RM timeout to avoid DSI hard hangs
CVE-2019-0155: (unk) drm/i915: Rename gen7 cmdparser tables
CVE-2019-10124: (unk) mm: hwpoison: fix thp split handing in soft_offline_in_use_page()
CVE-2019-10126: (unk) mwifiex: Fix heap overflow in mwifiex_uap_parse_tail_ies()
CVE-2019-10142: (unk) drivers/virt/fsl_hypervisor.c: prevent integer overflow in ioctl
CVE-2019-10207: (unk) Bluetooth: hci_uart: check for missing tty operations
CVE-2019-10220: (unk) Convert filldir[64]() from __put_user() to unsafe_put_user()
CVE-2019-10638: (unk) inet: switch IP ID generator to siphash
CVE-2019-10639: (unk) netns: provide pure entropy for net_hash_mix()
CVE-2019-11085: (unk) drm/i915/gvt: Fix mmap range check
CVE-2019-11091: (unk) s390/speculation: Support 'mitigations=' cmdline option
CVE-2019-11135: (unk) x86/msr: Add the IA32_TSX_CTRL MSR
CVE-2019-11191: (unk) x86: Deprecate a.out support
CVE-2019-1125: (unk) x86/speculation: Prepare entry code for Spectre v1 swapgs mitigations
CVE-2019-11477: (unk) tcp: limit payload size of sacked skbs
CVE-2019-11478: (unk) tcp: tcp_fragment() should apply sane memory limits
CVE-2019-11479: (unk) tcp: add tcp_min_snd_mss sysctl
CVE-2019-11486: (unk) tty: mark Siemens R3964 line discipline as BROKEN
CVE-2019-11487: (unk) fs: prevent page refcount overflow in pipe_buf_get
CVE-2019-11599: (unk) coredump: fix race condition between mmget_not_zero()/get_task_mm() and core dumping
CVE-2019-11810: (unk) scsi: megaraid_sas: return error when create DMA pool failed
CVE-2019-11815: (unk) net: rds: force to destroy connection if t_sock is NULL in rds_tcp_kill_sock().
CVE-2019-11833: (unk) ext4: zero out the unused memory region in the extent tree block
CVE-2019-11884: (unk) Bluetooth: hidp: fix buffer overflow
CVE-2019-12378: (unk) ipv6_sockglue: Fix a missing-check bug in ip6_ra_control()
CVE-2019-12379: (unk) consolemap: Fix a memory leaking bug in drivers/tty/vt/consolemap.c
CVE-2019-12380: (unk) efi/x86/Add missing error handling to old_memmap 1:1 mapping code
CVE-2019-12381: (unk) ip_sockglue: Fix missing-check bug in ip_ra_control()
CVE-2019-12382: (unk) drm/edid: Fix a missing-check bug in drm_load_edid_firmware()
CVE-2019-12455: (unk) clk-sunxi: fix a missing-check bug in sunxi_divs_clk_setup()
CVE-2019-12456: (unk)
CVE-2019-12614: (unk) powerpc/pseries/dlpar: Fix a missing check in dlpar_parse_cc_property()
CVE-2019-12615: (unk) mdesc: fix a missing-check bug in get_vdev_port_node_info()
CVE-2019-12818: (unk) net: nfc: Fix NULL dereference on nfc_llcp_build_tlv fails
CVE-2019-12819: (unk) mdio_bus: Fix use-after-free on device_register fails
CVE-2019-12881: (unk) drm/i915/userptr: reject zero user_size
CVE-2019-13272: (unk) ptrace: Fix ->ptracer_cred handling for PTRACE_TRACEME
CVE-2019-13631: (unk) Input: gtco - bounds check collection indent level
CVE-2019-13648: (unk) powerpc/tm: Fix oops on sigreturn on systems without TM
CVE-2019-14283: (unk) floppy: fix out-of-bounds read in copy_buffer
CVE-2019-14284: (unk) floppy: fix div-by-zero in setup_format_params
CVE-2019-14615: (unk) drm/i915/gen9: Clear residual context state on context switch
CVE-2019-14763: (unk) usb: dwc3: gadget: never call ->complete() from ->ep_queue()
CVE-2019-14814: (unk) mwifiex: Fix three heap overflow at parsing element in cfg80211_ap_settings
CVE-2019-14815: (unk) mwifiex: Fix three heap overflow at parsing element in cfg80211_ap_settings
CVE-2019-14816: (unk) mwifiex: Fix three heap overflow at parsing element in cfg80211_ap_settings
CVE-2019-14821: (unk) KVM: coalesced_mmio: add bounds checking
CVE-2019-14835: (unk) vhost: make sure log_num < in_num
CVE-2019-14895: (unk) mwifiex: fix possible heap overflow in mwifiex_process_country_ie()
CVE-2019-14896: (unk) libertas: Fix two buffer overflows at parsing bss descriptor
CVE-2019-14897: (unk) libertas: Fix two buffer overflows at parsing bss descriptor
CVE-2019-14901: (unk) mwifiex: Fix heap overflow in mmwifiex_process_tdls_action_frame()
CVE-2019-15090: (unk) scsi: qedi: remove memset/memcpy to nfunc and use func instead
CVE-2019-15098: (unk) ath6kl: fix a NULL-ptr-deref bug in ath6kl_usb_alloc_urb_from_pipe()
CVE-2019-15117: (unk) ALSA: usb-audio: Fix an OOB bug in parse_audio_mixer_unit
CVE-2019-15118: (unk) ALSA: usb-audio: Fix a stack buffer overflow bug in check_input_term
CVE-2019-15211: (unk) media: radio-raremono: change devm_k*alloc to k*alloc
CVE-2019-15212: (unk) USB: rio500: refuse more than one device at a time
CVE-2019-15214: (unk) ALSA: core: Fix card races between register and disconnect
CVE-2019-15215: (unk) media: cpia2_usb: first wake up, then free in disconnect
CVE-2019-15216: (unk) USB: yurex: Fix protection fault after device removal
CVE-2019-15217: (unk) media: usb:zr364xx:Fix KASAN:null-ptr-deref Read in zr364xx_vidioc_querycap
CVE-2019-15218: (unk) media: usb: siano: Fix general protection fault in smsusb
CVE-2019-15219: (unk) USB: sisusbvga: fix oops in error path of sisusb_probe
CVE-2019-15220: (unk) p54usb: Fix race between disconnect and firmware loading
CVE-2019-15221: (unk) ALSA: line6: Fix write on zero-sized buffer
CVE-2019-15222: (unk) ALSA: usb-audio: Fix gpf in snd_usb_pipe_sanity_check
CVE-2019-15223: (unk) ALSA: line6: Assure canceling delayed work at disconnection
CVE-2019-15239: (unk)
CVE-2019-15290: (unk)
CVE-2019-15291: (unk) media: b2c2-flexcop-usb: add sanity checking
CVE-2019-15292: (unk) appletalk: Fix use-after-free in atalk_proc_exit
CVE-2019-15505: (unk) media: technisat-usb2: break out of loop at end of buffer
CVE-2019-15538: (unk) xfs: fix missing ILOCK unlock when xfs_setattr_nonsize fails due to EDQUOT
CVE-2019-15666: (unk) xfrm: policy: Fix out-of-bound array accesses in __xfrm_policy_unlink
CVE-2019-15807: (unk) scsi: libsas: delete sas port if expander discover failed
CVE-2019-15902: (unk)
CVE-2019-15916: (unk) net-sysfs: Fix mem leak in netdev_register_kobject
CVE-2019-15917: (unk) Bluetooth: hci_ldisc: Postpone HCI_UART_PROTO_READY bit set in hci_uart_set_proto()
CVE-2019-15921: (unk) genetlink: Fix a memory leak on error path
CVE-2019-15924: (unk) fm10k: Fix a potential NULL pointer dereference
CVE-2019-15926: (unk) ath6kl: add some bounds checking
CVE-2019-15927: (unk) ALSA: usb-audio: Avoid access before bLength check in build_audio_procunit()
CVE-2019-16230: (unk) drm/amdkfd: fix a potential NULL pointer dereference (v2)
CVE-2019-16231: (unk) fjes: Handle workqueue allocation failure
CVE-2019-16232: (unk) libertas: fix a potential NULL pointer dereference
CVE-2019-16233: (unk) scsi: qla2xxx: fix a potential NULL pointer dereference
CVE-2019-16234: (unk) iwlwifi: pcie: fix rb_allocator workqueue allocation
CVE-2019-16413: (unk) 9p: use inode->i_lock to protect i_size_write() under 32-bit
CVE-2019-16746: (unk) nl80211: validate beacon head
CVE-2019-16921: (unk) RDMA/hns: Fix init resp when alloc ucontext
CVE-2019-16995: (unk) net: hsr: fix memory leak in hsr_dev_finalize()
CVE-2019-17052: (unk) ax25: enforce CAP_NET_RAW for raw sockets
CVE-2019-17053: (unk) ieee802154: enforce CAP_NET_RAW for raw sockets
CVE-2019-17054: (unk) appletalk: enforce CAP_NET_RAW for raw sockets
CVE-2019-17055: (unk) mISDN: enforce CAP_NET_RAW for raw sockets
CVE-2019-17056: (unk) nfc: enforce CAP_NET_RAW for raw sockets
CVE-2019-17075: (unk) RDMA/cxgb4: Do not dma memory off of the stack
CVE-2019-17133: (unk) cfg80211: wext: avoid copying malformed SSIDs
CVE-2019-17351: (unk) xen: let alloc_xenballooned_pages() fail if not enough memory free
CVE-2019-17666: (unk) rtlwifi: Fix potential overflow on P2P code
CVE-2019-18282: (unk) net/flow_dissector: switch to siphash
CVE-2019-18660: (unk) powerpc/book3s64: Fix link stack flush on context switch
CVE-2019-18675: (unk) mmap: introduce sane default mmap limits
CVE-2019-18680: (unk)
CVE-2019-18683: (unk) media: vivid: Fix wrong locking that causes race conditions on streaming stop
CVE-2019-18806: (unk) net: qlogic: Fix memory leak in ql_alloc_large_buffers
CVE-2019-18808: (unk) crypto: ccp - Release all allocated memory if sha type is invalid
CVE-2019-18809: (unk) media: usb: fix memory leak in af9005_identify_state
CVE-2019-18885: (unk) btrfs: merge btrfs_find_device and find_device
CVE-2019-19036: (unk) btrfs: Detect unbalanced tree with empty leaf before crashing btree operations
CVE-2019-19039: (unk) btrfs: Don't submit any btree write bio if the fs has errors
CVE-2019-19049: (unk) of: unittest: fix memory leak in unittest_data_add
CVE-2019-19052: (unk) can: gs_usb: gs_can_open(): prevent memory leak
CVE-2019-19054: (unk) media: rc: prevent memory leak in cx23888_ir_probe
CVE-2019-19056: (unk) mwifiex: pcie: Fix memory leak in mwifiex_pcie_alloc_cmdrsp_buf
CVE-2019-19057: (unk) mwifiex: pcie: Fix memory leak in mwifiex_pcie_init_evt_ring
CVE-2019-19058: (unk) iwlwifi: dbg_ini: fix memory leak in alloc_sgtable
CVE-2019-19060: (unk) iio: imu: adis16400: release allocated memory on failure
CVE-2019-19061: (unk) iio: imu: adis16400: fix memory leak
CVE-2019-19062: (unk) crypto: user - fix memory leak in crypto_report
CVE-2019-19063: (unk) rtlwifi: prevent memory leak in rtl_usb_probe
CVE-2019-19066: (unk) scsi: bfa: release allocated memory in case of error
CVE-2019-19067: (unk) drm/amdgpu: fix multiple memory leaks in acp_hw_init
CVE-2019-19068: (unk) rtl8xxxu: prevent leaking urb
CVE-2019-19073: (unk) ath9k_htc: release allocated buffer if timed out
CVE-2019-19074: (unk) ath9k: release allocated buffer if timed out
CVE-2019-19227: (unk) appletalk: Fix potential NULL pointer dereference in unregister_snap_client
CVE-2019-19241: (unk) io_uring: async workers should inherit the user creds
CVE-2019-19319: (unk) ext4: protect journal inode's blocks using block_validity
CVE-2019-19332: (unk) KVM: x86: fix out-of-bounds write in KVM_GET_EMULATED_CPUID (CVE-2019-19332)
CVE-2019-19377: (unk) btrfs: Don't submit any btree write bio if the fs has errors
CVE-2019-19378: (unk)
CVE-2019-19447: (unk) ext4: work around deleting a file with i_nlink == 0 safely
CVE-2019-19448: (unk) btrfs: only search for left_info if there is no right_info in try_merge_free_space
CVE-2019-19449: (unk) f2fs: fix to do sanity check on segment/section count
CVE-2019-19462: (unk) kernel/relay.c: handle alloc_percpu returning NULL in relay_open
CVE-2019-19523: (unk) USB: adutux: fix use-after-free on disconnect
CVE-2019-19524: (unk) Input: ff-memless - kill timer in destroy()
CVE-2019-19525: (unk) ieee802154: atusb: fix use-after-free at disconnect
CVE-2019-19527: (unk) HID: hiddev: do cleanup in failure of opening a device
CVE-2019-19528: (unk) USB: iowarrior: fix use-after-free on disconnect
CVE-2019-19530: (unk) usb: cdc-acm: make sure a refcount is taken early enough
CVE-2019-19531: (unk) usb: yurex: Fix use-after-free in yurex_delete
CVE-2019-19532: (unk) HID: Fix assumption that devices have inputs
CVE-2019-19533: (unk) media: ttusb-dec: Fix info-leak in ttusb_dec_send_command()
CVE-2019-19534: (unk) can: peak_usb: fix slab info leak
CVE-2019-19535: (unk) can: peak_usb: pcan_usb_fd: Fix info-leaks to USB devices
CVE-2019-19536: (unk) can: peak_usb: pcan_usb_pro: Fix info-leaks to USB devices
CVE-2019-19537: (unk) USB: core: Fix races in character device registration and deregistraion
CVE-2019-19543: (unk) media: serial_ir: Fix use-after-free in serial_ir_init_module
CVE-2019-19768: (unk) blktrace: Protect q->blk_trace with RCU
CVE-2019-19770: (unk) blktrace: fix debugfs use after free
CVE-2019-19813: (unk) btrfs: inode: Verify inode mode to avoid NULL pointer dereference
CVE-2019-19814: (unk)
CVE-2019-19815: (unk) f2fs: support swap file w/ DIO
CVE-2019-19816: (unk) btrfs: inode: Verify inode mode to avoid NULL pointer dereference
CVE-2019-19922: (unk) sched/fair: Fix low cpu usage with high throttling by removing expiration of cpu-local slices
CVE-2019-19927: (unk) drm/ttm: fix incrementing the page pointer for huge pages
CVE-2019-19965: (unk) scsi: libsas: stop discovering if oob mode is disconnected
CVE-2019-19966: (unk) media: cpia2: Fix use-after-free in cpia2_exit
CVE-2019-1999: (unk) binder: fix race between munmap() and direct reclaim
CVE-2019-20054: (unk) fs/proc/proc_sysctl.c: fix NULL pointer dereference in put_links
CVE-2019-20095: (unk) mwifiex: Fix mem leak in mwifiex_tm_cmd
CVE-2019-20096: (unk) dccp: Fix memleak in __feat_register_sp
CVE-2019-2024: (unk) media: em28xx: Fix use-after-free when disconnecting
CVE-2019-2025: (unk) binder: fix race that allows malicious free of live buffer
CVE-2019-20636: (unk) Input: add safety guards to input_set_keycode()
CVE-2019-20794: (unk)
CVE-2019-20806: (unk) media: tw5864: Fix possible NULL pointer dereference in tw5864_handle_frame
CVE-2019-20810: (unk) media: go7007: fix a miss of snd_card_free
CVE-2019-20811: (unk) net-sysfs: call dev_hold if kobject_init_and_add success
CVE-2019-20812: (unk) af_packet: set defaule value for tmo
CVE-2019-20908: (unk) efi: Restrict efivar_ssdt_load when the kernel is locked down
CVE-2019-20934: (unk) sched/fair: Don't free p->numa_faults with concurrent readers
CVE-2019-2101: (unk) media: uvcvideo: Fix 'type' check leading to overflow
CVE-2019-2181: (unk) binder: check for overflow when alloc for security context
CVE-2019-2182: (unk) arm64: Enforce BBM for huge IO/VMAP mappings
CVE-2019-2213: (unk) binder: fix possible UAF when freeing buffer
CVE-2019-2215: (unk) ANDROID: binder: remove waitqueue when thread exits.
CVE-2019-3016: (unk) x86/kvm: Be careful not to clear KVM_VCPU_FLUSH_TLB bit
CVE-2019-3459: (unk) Bluetooth: Verify that l2cap_get_conf_opt provides large enough buffer
CVE-2019-3460: (unk) Bluetooth: Check L2CAP option sizes returned from l2cap_get_conf_opt
CVE-2019-3701: (unk) can: gw: ensure DLC boundaries after CAN frame modification
CVE-2019-3846: (unk) mwifiex: Fix possible buffer overflows at parsing bss descriptor
CVE-2019-3874: (unk) sctp: implement memory accounting on tx path
CVE-2019-3882: (unk) vfio/type1: Limit DMA mappings per container
CVE-2019-3892: (unk) coredump: fix race condition between mmget_not_zero()/get_task_mm() and core dumping
CVE-2019-3900: (unk) vhost_net: fix possible infinite loop
CVE-2019-5108: (unk) mac80211: Do not send Layer 2 Update frame before authorization
CVE-2019-5489: (unk) Change mincore() to count "mapped" pages rather than "cached" pages
CVE-2019-6133: (unk) fork: record start_time late
CVE-2019-6974: (unk) kvm: fix kvm_ioctl_create_device() reference counting (CVE-2019-6974)
CVE-2019-7221: (unk) KVM: nVMX: unconditionally cancel preemption timer in free_nested (CVE-2019-7221)
CVE-2019-7222: (unk) KVM: x86: work around leak of uninitialized stack contents (CVE-2019-7222)
CVE-2019-7308: (unk) bpf: fix sanitation of alu op with pointer / scalar type from different paths
CVE-2019-8912: (unk) net: crypto set sk to NULL when af_alg_release.
CVE-2019-8980: (unk) exec: Fix mem leak in kernel_read_file
CVE-2019-9213: (unk) mm: enforce min addr even if capable() in expand_downwards()
CVE-2019-9245: (unk) f2fs: sanity check of xattr entry size
CVE-2019-9444: (unk) printk: hash addresses printed with %p
CVE-2019-9445: (unk) f2fs: check if file namelen exceeds max value
CVE-2019-9453: (unk) f2fs: fix to avoid accessing xattr across the boundary
CVE-2019-9454: (unk) i2c: core-smbus: prevent stack corruption on read I2C_BLOCK_DATA
CVE-2019-9455: (unk) media: videobuf2-v4l2: drop WARN_ON in vb2_warn_zero_bytesused()
CVE-2019-9456: (unk) usb: usbmon: Read text within supplied buffer size
CVE-2019-9458: (unk) media: v4l: event: Prevent freeing event subscriptions while accessed
CVE-2019-9466: (unk) brcmfmac: add subtype check for event handling in data path
CVE-2019-9500: (unk) brcmfmac: assure SSID length from firmware is limited
CVE-2019-9503: (unk) brcmfmac: add subtype check for event handling in data path
CVE-2019-9506: (unk) Bluetooth: Fix faulty expression for minimum encryption key size check
CVE-2020-0009: (unk) staging: android: ashmem: Disallow ashmem memory from being remapped
CVE-2020-0030: (unk) ANDROID: binder: synchronize_rcu() when using POLLFREE.
CVE-2020-0067: (unk) f2fs: fix to avoid memory leakage in f2fs_listxattr
CVE-2020-0255: (unk) selinux: properly handle multiple messages in selinux_netlink_send()
CVE-2020-0305: (unk) chardev: Avoid potential use-after-free in 'chrdev_open()'
CVE-2020-0347: (unk)
CVE-2020-0404: (unk) media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors
CVE-2020-0427: (unk) pinctrl: devicetree: Avoid taking direct reference to device name string
CVE-2020-0429: (unk) l2tp: fix race between l2tp_session_delete() and l2tp_tunnel_closeall()
CVE-2020-0431: (unk) HID: hid-input: clear unmapped usages
CVE-2020-0432: (unk) staging: most: net: fix buffer overflow
CVE-2020-0433: (unk) blk-mq: sync the update nr_hw_queues with blk_mq_queue_tag_busy_iter
CVE-2020-0435: (unk) f2fs: fix to do sanity check with i_extra_isize
CVE-2020-0444: (unk) audit: fix error handling in audit_data_to_entry()
CVE-2020-0465: (unk) HID: core: Sanitize event code and type when mapping input
CVE-2020-0466: (unk) do_epoll_ctl(): clean the failure exits up a bit
CVE-2020-0543: (unk) x86/cpu: Add 'table' argument to cpu_matches()
CVE-2020-10135: (unk) Bluetooth: Consolidate encryption handling in hci_encrypt_cfm
CVE-2020-10690: (unk) ptp: fix the race between the release of ptp_clock and cdev
CVE-2020-10708: (unk)
CVE-2020-10711: (unk) netlabel: cope with NULL catmap
CVE-2020-10720: (unk) net-gro: fix use-after-free read in napi_gro_frags()
CVE-2020-10732: (unk) fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info()
CVE-2020-10751: (unk) selinux: properly handle multiple messages in selinux_netlink_send()
CVE-2020-10757: (unk) mm: Fix mremap not considering huge pmd devmap
CVE-2020-10766: (unk) x86/speculation: Prevent rogue cross-process SSBD shutdown
CVE-2020-10767: (unk) x86/speculation: Avoid force-disabling IBPB based on STIBP and enhanced IBRS.
CVE-2020-10768: (unk) x86/speculation: PR_SPEC_FORCE_DISABLE enforcement for indirect branches.
CVE-2020-10769: (unk) crypto: authenc - fix parsing key with misaligned rta_len
CVE-2020-10773: (unk) s390/cmm: fix information leak in cmm_timeout_handler()
CVE-2020-10942: (unk) vhost: Check docket sk_family instead of call getname
CVE-2020-11494: (unk) slcan: Don't transmit uninitialized stack data in padding
CVE-2020-11565: (unk) mm: mempolicy: require at least one nodeid for MPOL_PREFERRED
CVE-2020-11608: (unk) media: ov519: add missing endpoint sanity checks
CVE-2020-11609: (unk) media: stv06xx: add missing descriptor sanity checks
CVE-2020-11668: (unk) media: xirlink_cit: add missing descriptor sanity checks
CVE-2020-11669: (unk) powerpc/powernv/idle: Restore AMR/UAMOR/AMOR after idle
CVE-2020-11725: (unk)
CVE-2020-12114: (unk) make struct mountpoint bear the dentry reference to mountpoint, not struct mount
CVE-2020-12351: (unk) Bluetooth: L2CAP: Fix calling sk_filter on non-socket based channel
CVE-2020-12352: (unk) Bluetooth: A2MP: Fix not initializing all members
CVE-2020-12362: (unk) drm/i915/guc: Update to use firmware v49.0.1
CVE-2020-12363: (unk) drm/i915/guc: Update to use firmware v49.0.1
CVE-2020-12364: (unk) drm/i915/guc: Update to use firmware v49.0.1
CVE-2020-12464: (unk) USB: core: Fix free-while-in-use bug in the USB S-Glibrary
CVE-2020-12652: (unk) scsi: mptfusion: Fix double fetch bug in ioctl
CVE-2020-12653: (unk) mwifiex: Fix possible buffer overflows in mwifiex_cmd_append_vsie_tlv()
CVE-2020-12654: (unk) mwifiex: Fix possible buffer overflows in mwifiex_ret_wmm_get_status()
CVE-2020-12655: (unk) xfs: add agf freeblocks verify in xfs_agf_verify
CVE-2020-12656: (unk) sunrpc: check that domain table is empty at module unload.
CVE-2020-12769: (unk) spi: spi-dw: Add lock protect dw_spi rx/tx to prevent concurrent calls
CVE-2020-12770: (unk) scsi: sg: add sg_remove_request in sg_write
CVE-2020-12771: (unk) bcache: fix potential deadlock problem in btree_gc_coalesce
CVE-2020-12826: (unk) signal: Extend exec_id to 64bits
CVE-2020-12888: (unk) vfio-pci: Invalidate mmaps and block MMIO access on disabled memory
CVE-2020-13143: (unk) USB: gadget: fix illegal array access in binding with UDC
CVE-2020-13974: (unk) vt: keyboard: avoid signed integer overflow in k_ascii
CVE-2020-14304: (unk)
CVE-2020-14305: (unk) netfilter: helpers: remove data_len usage for inkernel helpers
CVE-2020-14314: (unk) ext4: fix potential negative array index in do_split()
CVE-2020-14331: (unk) vgacon: Fix for missing check in scrollback handling
CVE-2020-14351: (unk) perf/core: Fix race in the perf_mmap_close() function
CVE-2020-14353: (unk) KEYS: prevent creating a different user's keyrings
CVE-2020-14356: (unk) cgroup: fix cgroup_sk_alloc() for sk_clone_lock()
CVE-2020-14381: (unk) futex: Fix inode life-time issue
CVE-2020-14386: (unk) net/packet: fix overflow in tpacket_rcv
CVE-2020-14390: (unk) fbcon: remove soft scrollback code
CVE-2020-14416: (unk) can, slip: Protect tty->disc_data in write_wakeup and close with RCU
CVE-2020-15393: (unk) usb: usbtest: fix missing kfree(dev->buf) in usbtest_disconnect
CVE-2020-15436: (unk) block: Fix use-after-free in blkdev_get()
CVE-2020-15437: (unk) serial: 8250: fix null-ptr-deref in serial8250_start_tx()
CVE-2020-15780: (unk) ACPI: configfs: Disallow loading ACPI tables when locked down
CVE-2020-15802: (unk)
CVE-2020-16120: (unk) ovl: switch to mounter creds in readdir
CVE-2020-16166: (unk) random32: update the net random state on interrupt and activity
CVE-2020-1749: (unk) net: ipv6_stub: use ip6_dst_lookup_flow instead of ip6_dst_lookup
CVE-2020-24394: (unk) nfsd: apply umask on fs without ACL support
CVE-2020-24502: (unk)
CVE-2020-24503: (unk)
CVE-2020-24586: (unk) mac80211: prevent mixed key and fragment cache attacks
CVE-2020-24587: (unk) mac80211: prevent mixed key and fragment cache attacks
CVE-2020-24588: (unk) cfg80211: mitigate A-MSDU aggregation attacks
CVE-2020-25211: (unk) netfilter: ctnetlink: add a range check for l3/l4 protonum
CVE-2020-25212: (unk) nfs: Fix getxattr kernel panic and memory overflow
CVE-2020-25284: (unk) rbd: require global CAP_SYS_ADMIN for mapping and unmapping
CVE-2020-25285: (unk) mm/hugetlb: fix a race between hugetlb sysctl handlers
CVE-2020-25641: (unk) block: allow for_each_bvec to support zero len bvec
CVE-2020-25643: (unk) hdlc_ppp: add range checks in ppp_cp_parse_cr()
CVE-2020-25645: (unk) geneve: add transport ports in route lookup for geneve
CVE-2020-25656: (unk) vt: keyboard, extend func_buf_lock to readers
CVE-2020-25668: (unk) tty: make FONTX ioctl use the tty pointer they were actually passed
CVE-2020-25669: (unk) Input: sunkbd - avoid use-after-free in teardown paths
CVE-2020-25670: (unk) nfc: fix refcount leak in llcp_sock_bind()
CVE-2020-25671: (unk) nfc: fix refcount leak in llcp_sock_connect()
CVE-2020-25672: (unk) nfc: fix memory leak in llcp_sock_connect()
CVE-2020-25673: (unk) nfc: Avoid endless loops caused by repeated llcp_sock_connect()
CVE-2020-25704: (unk) perf/core: Fix a memory leak in perf_event_parse_addr_filter()
CVE-2020-25705: (unk) icmp: randomize the global rate limiter
CVE-2020-26088: (unk) net/nfc/rawsock.c: add CAP_NET_RAW check.
CVE-2020-26139: (unk) mac80211: do not accept/forward invalid EAPOL frames
CVE-2020-26140: (unk)
CVE-2020-26141: (unk) ath10k: Fix TKIP Michael MIC verification for PCIe
CVE-2020-26142: (unk)
CVE-2020-26143: (unk)
CVE-2020-26145: (unk) ath10k: drop fragments with multicast DA for PCIe
CVE-2020-26147: (unk) mac80211: assure all fragments are encrypted
CVE-2020-26541: (unk) certs: Add EFI_CERT_X509_GUID support for dbx entries
CVE-2020-26555: (unk) Bluetooth: SMP: Fail if remote and local public keys are identical
CVE-2020-26556: (unk)
CVE-2020-26557: (unk)
CVE-2020-26558: (unk) Bluetooth: SMP: Fail if remote and local public keys are identical
CVE-2020-26559: (unk)
CVE-2020-26560: (unk)
CVE-2020-27066: (unk) xfrm: policy: Fix doulbe free in xfrm_policy_timer
CVE-2020-27067: (unk) l2tp: fix l2tp_eth module loading
CVE-2020-27068: (unk) cfg80211: add missing policy for NL80211_ATTR_STATUS_CODE
CVE-2020-2732: (unk) KVM: nVMX: Don't emulate instructions in guest mode
CVE-2020-27418: (unk) vgacon: Fix a UAF in vgacon_invert_region
CVE-2020-27673: (unk) xen/events: add a proper barrier to 2-level uevent unmasking
CVE-2020-27675: (unk) xen/events: avoid removing an event channel while handling it
CVE-2020-27777: (unk) powerpc/rtas: Restrict RTAS requests from userspace
CVE-2020-27784: (unk) usb: gadget: function: printer: fix use-after-free in __lock_acquire
CVE-2020-27786: (unk) ALSA: rawmidi: Fix racy buffer resize under concurrent accesses
CVE-2020-27815: (unk) jfs: Fix array index bounds check in dbAdjTree
CVE-2020-27820: (unk) drm/nouveau: use drm_dev_unplug() during device removal
CVE-2020-27825: (unk) tracing: Fix race in trace_open and buffer resize call
CVE-2020-27835: (unk) IB/hfi1: Ensure correct mm is used at all times
CVE-2020-28097: (unk) vgacon: remove software scrollback support
CVE-2020-28374: (unk) scsi: target: Fix XCOPY NAA identifier lookup
CVE-2020-28915: (unk) fbcon: Fix global-out-of-bounds read in fbcon_get_font()
CVE-2020-28974: (unk) vt: Disable KD_FONT_OP_COPY
CVE-2020-29368: (unk) mm: thp: make the THP mapcount atomic against __split_huge_pmd_locked()
CVE-2020-29370: (unk) mm: slub: add missing TID bump in kmem_cache_alloc_bulk()
CVE-2020-29371: (unk) romfs: fix uninitialized memory leak in romfs_dev_read()
CVE-2020-29374: (unk) gup: document and work around "COW can break either way" issue
CVE-2020-29568: (unk) xen/xenbus: Allow watches discard events before queueing
CVE-2020-29660: (unk) tty: Fix ->session locking
CVE-2020-29661: (unk) tty: Fix ->pgrp locking in tiocspgrp()
CVE-2020-35501: (unk)
CVE-2020-35508: (unk) fork: fix copy_process(CLONE_PARENT) race with the exiting ->real_parent
CVE-2020-35513: (unk) nfsd: fix incorrect umasks
CVE-2020-35519: (unk) net/x25: prevent a couple of overflows
CVE-2020-36158: (unk) mwifiex: Fix possible buffer overflows in mwifiex_cmd_802_11_ad_hoc_start
CVE-2020-36310: (unk) KVM: SVM: avoid infinite loop on NPF from bad address
CVE-2020-36312: (unk) KVM: fix memory leak in kvm_io_bus_unregister_dev()
CVE-2020-36313: (unk) KVM: Fix out of range accesses to memslots
CVE-2020-36322: (unk) fuse: fix bad inode
CVE-2020-36385: (unk) RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy
CVE-2020-36386: (unk) Bluetooth: Fix slab-out-of-bounds read in hci_extended_inquiry_result_evt()
CVE-2020-36516: (unk) ipv4: avoid using shared IP generator for connected sockets
CVE-2020-36557: (unk) vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console
CVE-2020-36558: (unk) vt: vt_ioctl: fix race in VT_RESIZEX
CVE-2020-36691: (unk) netlink: limit recursion depth in policy validation
CVE-2020-36766: (unk) cec-api: prevent leaking memory through hole in structure
CVE-2020-3702: (unk) ath: Use safer key clearing with key cache entries
CVE-2020-4788: (unk) powerpc/64s: flush L1D on kernel entry
CVE-2020-8647: (unk) vgacon: Fix a UAF in vgacon_invert_region
CVE-2020-8648: (unk) vt: selection, close sel_buffer race
CVE-2020-8649: (unk) vgacon: Fix a UAF in vgacon_invert_region
CVE-2020-8694: (unk) powercap: restrict energy meter to root access
CVE-2020-8832: (unk) drm/i915: Record the default hw state after reset upon load
CVE-2020-8834: (unk) KVM: PPC: Book3S HV: Factor fake-suspend handling out of kvmppc_save/restore_tm
CVE-2020-9383: (unk) floppy: check FDC index for errors before assigning it
CVE-2021-0129: (unk) Bluetooth: SMP: Fail if remote and local public keys are identical
CVE-2021-0399: (unk)
CVE-2021-0447: (unk) l2tp: protect sock pointer of struct pppol2tp_session with RCU
CVE-2021-0448: (unk) netfilter: ctnetlink: add a range check for l3/l4 protonum
CVE-2021-0512: (unk) HID: make arrays usage and value to be the same
CVE-2021-0605: (unk) af_key: pfkey_dump needs parameter validation
CVE-2021-0920: (unk) af_unix: fix garbage collect vs MSG_PEEK
CVE-2021-0929: (unk) staging/android/ion: delete dma_buf->kmap/unmap implemenation
CVE-2021-0937: (unk) netfilter: x_tables: fix compat match/target pad out-of-bound write
CVE-2021-0941: (unk) bpf: Remove MTU check in __bpf_skb_max_len
CVE-2021-1048: (unk) fix regression in "epoll: Keep a reference on files added to the check list"
CVE-2021-20292: (unk) drm/ttm/nouveau: don't call tt destroy callback on alloc failure.
CVE-2021-20317: (unk) lib/timerqueue: Rely on rbtree semantics for next timer
CVE-2021-20320: (unk) s390/bpf: Fix optimizing out zero-extensions
CVE-2021-20321: (unk) ovl: fix missing negative dentry check in ovl_rename()
CVE-2021-21781: (unk) ARM: ensure the signal page contains defined contents
CVE-2021-22543: (unk) KVM: do not allow mapping valid but non-reference-counted pages
CVE-2021-22555: (unk) netfilter: x_tables: fix compat match/target pad out-of-bound write
CVE-2021-23133: (unk) net/sctp: fix race condition in sctp_destroy_sock
CVE-2021-26401: (unk) x86/speculation: Use generic retpoline by default on AMD
CVE-2021-26930: (unk) xen-blkback: fix error handling in xen_blkbk_map()
CVE-2021-26931: (unk) xen-blkback: don't "handle" error by BUG()
CVE-2021-26932: (unk) Xen/x86: don't bail early from clear_foreign_p2m_mapping()
CVE-2021-27363: (unk) scsi: iscsi: Restrict sessions and handles to admin capabilities
CVE-2021-27364: (unk) scsi: iscsi: Restrict sessions and handles to admin capabilities
CVE-2021-27365: (unk) scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE
CVE-2021-28038: (unk) Xen/gnttab: handle p2m update errors on a per-slot basis
CVE-2021-28660: (unk) staging: rtl8188eu: prevent ->ssid overflow in rtw_wx_set_scan()
CVE-2021-28688: (unk) xen-blkback: don't leak persistent grants from xen_blkbk_map()
CVE-2021-28711: (unk) xen/blkfront: harden blkfront against event channel storms
CVE-2021-28712: (unk) xen/netfront: harden netfront against event channel storms
CVE-2021-28713: (unk) xen/console: harden hvc_xen against event channel storms
CVE-2021-28714: (unk) xen/netback: fix rx queue stall detection
CVE-2021-28715: (unk) xen/netback: don't queue unlimited number of packages
CVE-2021-28964: (unk) btrfs: fix race when cloning extent buffer during rewind of an old root
CVE-2021-28971: (unk) perf/x86/intel: Fix a crash caused by zero PEBS status
CVE-2021-28972: (unk) PCI: rpadlpar: Fix potential drc_name corruption in store functions
CVE-2021-29154: (unk) bpf, x86: Validate computation of branch displacements for x86-64
CVE-2021-29155: (unk) bpf: Use correct permission flag for mixed signed bounds arithmetic
CVE-2021-29264: (unk) gianfar: fix jumbo packets+napi+rx overrun crash
CVE-2021-29265: (unk) usbip: fix stub_dev usbip_sockfd_store() races leading to gpf
CVE-2021-29647: (unk) net: qrtr: fix a kernel-infoleak in qrtr_recvmsg()
CVE-2021-29650: (unk) netfilter: x_tables: Use correct memory barriers.
CVE-2021-30002: (unk) media: v4l: ioctl: Fix memory leak in video_usercopy
CVE-2021-3178: (unk) nfsd4: readdirplus shouldn't return parent of export
CVE-2021-31916: (unk) dm ioctl: fix out of bounds array access when no devices
CVE-2021-32078: (unk) ARM: footbridge: remove personal server platform
CVE-2021-32399: (unk) bluetooth: eliminate the potential race condition when removing the HCI controller
CVE-2021-33033: (unk) cipso,calipso: resolve a number of problems with the DOI refcounts
CVE-2021-33034: (unk) Bluetooth: verify AMP hci_chan before amp_destroy
CVE-2021-33061: (unk) ixgbe: add improvement for MDD response functionality
CVE-2021-33098: (unk) ixgbe: fix large MTU request from VF
CVE-2021-3348: (unk) nbd: freeze the queue while we're adding connections
CVE-2021-33655: (unk) fbcon: Disallow setting font bigger than screen size
CVE-2021-33656: (unk) vt: drop old FONT ioctls
CVE-2021-33909: (unk) seq_file: disallow extremely large seq buffer allocations
CVE-2021-34556: (unk) bpf: Introduce BPF nospec instruction for mitigating Spectre v4
CVE-2021-34693: (unk) can: bcm: fix infoleak in struct bcm_msg_head
CVE-2021-3483: (unk) firewire: nosy: Fix a use-after-free bug in nosy_ioctl()
CVE-2021-34981: (unk) Bluetooth: cmtp: fix file refcount when cmtp_attach_device fails
CVE-2021-3506: (unk) f2fs: fix to avoid out-of-bounds memory access
CVE-2021-3542: (unk)
CVE-2021-35477: (unk) bpf: Introduce BPF nospec instruction for mitigating Spectre v4
CVE-2021-3564: (unk) Bluetooth: fix the erroneous flush_work() order
CVE-2021-3573: (unk) Bluetooth: use correct lock to prevent UAF of hdev object
CVE-2021-3587: (unk) nfc: fix NULL ptr dereference in llcp_sock_getname() after failed connect
CVE-2021-3609: (unk) can: bcm: delay release of struct bcm_op after synchronize_rcu()
CVE-2021-3612: (unk) Input: joydev - prevent potential read overflow in ioctl
CVE-2021-3640: (unk) Bluetooth: sco: Fix lock_sock() blockage by memcpy_from_msg()
CVE-2021-3653: (unk) KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653)
CVE-2021-3655: (unk) sctp: validate from_addr_param return
CVE-2021-3659: (unk) net: mac802154: Fix general protection fault
CVE-2021-3669: (unk) ipc: replace costly bailout check in sysvipc_find_ipc()
CVE-2021-3679: (unk) tracing: Fix bug in rb_per_cpu_empty() that might cause deadloop.
CVE-2021-3714: (unk)
CVE-2021-3715: (unk) net_sched: cls_route: remove the right filter from hashtable
CVE-2021-37159: (unk) usb: hso: fix error handling code of hso_create_net_device
CVE-2021-3732: (unk) ovl: prevent private clone if bind mount is not allowed
CVE-2021-3752: (unk) Bluetooth: fix use-after-free error in lock_sock_nested()
CVE-2021-3753: (unk) vt_kdsetmode: extend console locking
CVE-2021-37576: (unk) KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow
CVE-2021-3759: (unk) memcg: enable accounting of ipc resources
CVE-2021-3760: (unk) nfc: nci: fix the UAF of rf_conn_info object
CVE-2021-3772: (unk) sctp: use init_tag from inithdr for ABORT chunk
CVE-2021-38160: (unk) virtio_console: Assure used length from device is limited
CVE-2021-38198: (unk) KVM: X86: MMU: Use the correct inherited permissions to get shadow page
CVE-2021-38199: (unk) NFSv4: Initialise connection to the server in nfs4_alloc_client()
CVE-2021-38204: (unk) usb: max-3421: Prevent corruption of freed memory
CVE-2021-38205: (unk) net: xilinx_emaclite: Do not print real IOMEM pointer
CVE-2021-38208: (unk) nfc: fix NULL ptr dereference in llcp_sock_getname() after failed connect
CVE-2021-38300: (unk) bpf, mips: Validate conditional branch offsets
CVE-2021-3847: (unk)
CVE-2021-3864: (unk)
CVE-2021-3892: (unk)
CVE-2021-3894: (unk) sctp: account stream padding length for reconf chunk
CVE-2021-3896: (unk) isdn: cpai: check ctr->cnr to avoid array index out of bound
CVE-2021-39633: (unk) ip_gre: add validation for csum_start
CVE-2021-39634: (unk) epoll: do not insert into poll queues until all sanity checks are done
CVE-2021-39636: (unk) netfilter: x_tables: fix pointer leaks to userspace
CVE-2021-39648: (unk) usb: gadget: configfs: Fix use-after-free issue with udc_name
CVE-2021-39657: (unk) scsi: ufs: Correct the LUN used in eh_device_reset_handler() callback
CVE-2021-39685: (unk) USB: gadget: detect too-big endpoint 0 requests
CVE-2021-39686: (unk) binder: use euid from cred instead of using task
CVE-2021-39698: (unk) wait: add wake_up_pollfree()
CVE-2021-39714: (unk) staging: android: ion: Drop ion_map_kernel interface
CVE-2021-39800: (unk)
CVE-2021-39801: (unk)
CVE-2021-4002: (unk) hugetlbfs: flush TLBs correctly after huge_pmd_unshare
CVE-2021-4023: (unk) io-wq: fix cancellation on create-worker failure
CVE-2021-4037: (unk) xfs: fix up non-directory creation in SGID directories
CVE-2021-40490: (unk) ext4: fix race writing to an inline_data file while its xattrs are changing
CVE-2021-4083: (unk) fget: check that the fd still exists after getting a ref to it
CVE-2021-4149: (unk) btrfs: unlock newly allocated extent buffer after error
CVE-2021-4150: (unk) block: fix incorrect references to disk objects
CVE-2021-4155: (unk) xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate
CVE-2021-4157: (unk) pNFS/flexfiles: fix incorrect size check in decode_nfs_fh()
CVE-2021-4159: (unk) bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()
CVE-2021-41864: (unk) bpf: Fix integer overflow in prealloc_elems_and_freelist()
CVE-2021-4197: (unk) cgroup: Use open-time credentials for process migraton perm checks
CVE-2021-42008: (unk) net: 6pack: fix slab-out-of-bounds in decode_data
CVE-2021-4202: (unk) NFC: reorganize the functions in nci_request
CVE-2021-4203: (unk) af_unix: fix races in sk_peer_pid and sk_peer_cred accesses
CVE-2021-4218: (unk) sysctl: pass kernel pointers to ->proc_handler
CVE-2021-42739: (unk) media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt()
CVE-2021-43389: (unk) isdn: cpai: check ctr->cnr to avoid array index out of bound
CVE-2021-43975: (unk) atlantic: Fix OOB read and write in hw_atl_utils_fw_rpc_wait
CVE-2021-43976: (unk) mwifiex: Fix skb_over_panic in mwifiex_usb_recv()
CVE-2021-44879: (unk) f2fs: fix to do sanity check on inode type during garbage collection
CVE-2021-45095: (unk) phonet: refcount leak in pep_sock_accep
CVE-2021-45469: (unk) f2fs: fix to do sanity check on last xattr entry in __f2fs_setxattr()
CVE-2021-45485: (unk) ipv6: use prandom_u32() for ID generation
CVE-2021-45486: (unk) inet: use bigger hash table for IP ID generation
CVE-2021-45868: (unk) quota: check block number when reading the block in quota file
CVE-2022-0001: (unk) x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE
CVE-2022-0002: (unk) x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE
CVE-2022-0168: (unk) cifs: fix NULL ptr dereference in smb2_ioctl_query_info()
CVE-2022-0322: (unk) sctp: account stream padding length for reconf chunk
CVE-2022-0330: (unk) drm/i915: Flush TLBs before releasing backing store
CVE-2022-0382: (unk) net ticp:fix a kernel-infoleak in __tipc_sendmsg()
CVE-2022-0400: (unk)
CVE-2022-0435: (unk) tipc: improve size validations for received domain records
CVE-2022-0480: (unk) memcg: enable accounting for file lock caches
CVE-2022-0487: (unk) moxart: fix potential use-after-free on remove path
CVE-2022-0492: (unk) cgroup-v1: Require capabilities to set release_agent
CVE-2022-0494: (unk) block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern
CVE-2022-0617: (unk) udf: Fix NULL ptr deref when converting from inline format
CVE-2022-0644: (unk) vfs: check fd has read access in kernel_read_file_from_fd()
CVE-2022-0812: (unk) xprtrdma: fix incorrect header size calculations
CVE-2022-0850: (unk) ext4: fix kernel infoleak via ext4_extent_header
CVE-2022-1011: (unk) fuse: fix pipe buffer lifetime for direct_io
CVE-2022-1012: (unk) secure_seq: use the 64 bits of the siphash for port offset calculation
CVE-2022-1016: (unk) netfilter: nf_tables: initialize registers in nft_do_chain()
CVE-2022-1048: (unk) ALSA: pcm: Fix races among concurrent hw_params and hw_free calls
CVE-2022-1116: (unk)
CVE-2022-1184: (unk) ext4: verify dir block before splitting it
CVE-2022-1195: (unk) hamradio: improve the incomplete fix to avoid NPD
CVE-2022-1198: (unk) drivers: hamradio: 6pack: fix UAF bug caused by mod_timer()
CVE-2022-1199: (unk) ax25: Fix NULL pointer dereference in ax25_kill_by_device
CVE-2022-1204: (unk) ax25: Fix refcount leaks caused by ax25_cb_del()
CVE-2022-1247: (unk)
CVE-2022-1263: (unk) KVM: avoid NULL pointer dereference in kvm_dirty_ring_push
CVE-2022-1280: (unk) drm: avoid circular locks in drm_mode_getconnector
CVE-2022-1353: (unk) af_key: add __GFP_ZERO flag for compose_sadb_supported in function pfkey_register
CVE-2022-1419: (unk) drm/vgem: Close use-after-free race in vgem_gem_create
CVE-2022-1462: (unk) tty: use new tty_insert_flip_string_and_push_buffer() in pty_write()
CVE-2022-1508: (unk) io_uring: reexpand under-reexpanded iters
CVE-2022-1652: (unk) floppy: use a statically allocated error counter
CVE-2022-1679: (unk) ath9k: fix use-after-free in ath9k_hif_usb_rx_cb
CVE-2022-1729: (unk) perf: Fix sys_perf_event_open() race against self
CVE-2022-1734: (unk) nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs
CVE-2022-1786: (unk) io_uring: remove io_identity
CVE-2022-1836: (unk) floppy: disable FDRAWCMD by default
CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier
CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions
CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout
CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection
CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu
CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory
CVE-2022-20158: (unk) net/packet: fix slab-out-of-bounds access in packet_recvmsg()
CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions
CVE-2022-20368: (unk) net/packet: fix slab-out-of-bounds access in packet_recvmsg()
CVE-2022-20369: (unk) media: v4l2-mem2mem: Apply DST_QUEUE_OFF_BASE on MMAP buffers across ioctls
CVE-2022-20422: (unk) arm64: fix oops in concurrently setting insn_emulation sysctls
CVE-2022-20424: (unk) io_uring: remove io_identity
CVE-2022-20565: (unk) HID: core: Correctly handle ReportSize being zero
CVE-2022-20566: (unk) Bluetooth: L2CAP: Fix use-after-free caused by l2cap_chan_put
CVE-2022-20572: (unk) dm verity: set DM_TARGET_IMMUTABLE feature flag
CVE-2022-21123: (unk) x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data
CVE-2022-21125: (unk) x86/speculation/mmio: Reuse SRBDS mitigation for SBDS
CVE-2022-21166: (unk) x86/speculation/mmio: Enable CPU Fill buffer clearing on idle
CVE-2022-21385: (unk) net/rds: fix warn in rds_message_alloc_sgs
CVE-2022-21499: (unk) lockdown: also lock down previous kgdb use
CVE-2022-2153: (unk) KVM: x86: Avoid theoretical NULL pointer dereference in kvm_irq_delivery_to_apic_fast()
CVE-2022-2209: (unk)
CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access()
CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status
CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access()
CVE-2022-23039: (unk) xen/gntalloc: don't use gnttab_query_foreign_access()
CVE-2022-23040: (unk) xen/xenbus: don't let xenbus_grant_ring() remove grants in error case
CVE-2022-23042: (unk) xen/netfront: react properly to failing gnttab_end_foreign_access_ref()
CVE-2022-2318: (unk) net: rose: fix UAF bugs caused by timer handler
CVE-2022-23222: (unk) bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL
CVE-2022-2327: (unk) io_uring: remove any grabbing of context
CVE-2022-2380: (unk) video: fbdev: sm712fb: Fix crash in smtcfb_read()
CVE-2022-23816: (unk) x86/kvm/vmx: Make noinstr clean
CVE-2022-23825: (unk)
CVE-2022-23960: (unk) ARM: report Spectre v2 status through sysfs
CVE-2022-24448: (unk) NFSv4: Handle case where the lookup of a directory fails
CVE-2022-24958: (unk) usb: gadget: don't release an existing dev->buf
CVE-2022-2503: (unk) dm verity: set DM_TARGET_IMMUTABLE feature flag
CVE-2022-25258: (unk) USB: gadget: validate interface OS descriptor requests
CVE-2022-25265: (unk)
CVE-2022-25375: (unk) usb: gadget: rndis: check size of RNDIS_MSG_SET command
CVE-2022-2586: (unk) netfilter: nf_tables: do not allow SET_ID to refer to another table
CVE-2022-2588: (unk) net_sched: cls_route: remove from list when handle is 0
CVE-2022-26365: (unk) xen/blkfront: fix leaking data in shared pages
CVE-2022-26373: (unk) x86/speculation: Add RSB VM Exit protections
CVE-2022-26490: (unk) nfc: st21nfca: Fix potential buffer overflows in EVT_TRANSACTION
CVE-2022-2663: (unk) netfilter: nf_conntrack_irc: Fix forged IP logic
CVE-2022-26966: (unk) sr9700: sanity check for packet length
CVE-2022-27223: (unk) USB: gadget: validate endpoint index for xilinx udc
CVE-2022-27666: (unk) esp: Fix possible buffer overflow in ESP transformation
CVE-2022-27672: (unk) x86/speculation: Identify processors vulnerable to SMT RSB predictions
CVE-2022-28356: (unk) llc: fix netdevice reference leaks in llc_ui_bind()
CVE-2022-28388: (unk) can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path
CVE-2022-28390: (unk) can: ems_usb: ems_usb_start_xmit(): fix double dev_kfree_skb() in error path
CVE-2022-2961: (unk)
CVE-2022-2964: (unk) net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup
CVE-2022-2978: (unk) fs: fix UAF/GPF bug in nilfs_mdt_destroy
CVE-2022-29900: (unk) x86/kvm/vmx: Make noinstr clean
CVE-2022-29901: (unk) x86/kvm/vmx: Make noinstr clean
CVE-2022-2991: (unk) remove the lightnvm subsystem
CVE-2022-3028: (unk) af_key: Do not call xfrm_probe_algs in parallel
CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE
CVE-2022-3061: (unk) video: fbdev: i740fb: Error out if 'pixclock' equals zero
CVE-2022-3111: (unk) power: supply: wm8350-power: Add missing free in free_charger_irq
CVE-2022-3169: (unk) nvme: ensure subsystem reset is single threaded
CVE-2022-3202: (unk) jfs: prevent NULL deref in diFree
CVE-2022-32250: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier
CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
CVE-2022-3239: (unk) media: em28xx: initialize refcount before kref_get
CVE-2022-32981: (unk) powerpc/32: Fix overread/overwrite of thread_struct via ptrace
CVE-2022-3303: (unk) ALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNC
CVE-2022-3344: (unk) KVM: x86: nSVM: harden svm_free_nested against freeing vmcb02 while still in use
CVE-2022-33740: (unk) xen/netfront: fix leaking data in shared pages
CVE-2022-33741: (unk) xen/netfront: force data bouncing when backend is untrusted
CVE-2022-33742: (unk) xen/blkfront: force data bouncing when backend is untrusted
CVE-2022-33744: (unk) xen/arm: Fix race in RB-tree based P2M accounting
CVE-2022-33981: (unk) floppy: disable FDRAWCMD by default
CVE-2022-3424: (unk) misc: sgi-gru: fix use-after-free error in gru_set_context_option, gru_fault and gru_handle_user_call_os
CVE-2022-34918: (unk) netfilter: nf_tables: stricter validation of element data
CVE-2022-3521: (unk) kcm: avoid potential race in kcm_tx_work
CVE-2022-3522: (unk) mm/hugetlb: use hugetlb_pte_stable in migration race check
CVE-2022-3523: (unk) mm/memory.c: fix race when faulting a device private page
CVE-2022-3524: (unk) tcp/udp: Fix memory leak in ipv6_renew_options().
CVE-2022-3533: (unk)
CVE-2022-3534: (unk) libbpf: Fix use-after-free in btf_dump_name_dups
CVE-2022-3542: (unk) bnx2x: fix potential memory leak in bnx2x_tpa_stop()
CVE-2022-3545: (unk) nfp: fix use-after-free in area_cache_get()
CVE-2022-3564: (unk) Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu
CVE-2022-3565: (unk) mISDN: fix use-after-free bugs in l1oip timer handlers
CVE-2022-3566: (unk) tcp: Fix data races around icsk->icsk_af_ops.
CVE-2022-3567: (unk) ipv6: Fix data races around sk->sk_prot.
CVE-2022-3586: (unk) sch_sfb: Don't assume the skb is still around after enqueueing to child
CVE-2022-3594: (unk) r8152: Rate limit overflow messages
CVE-2022-3595: (unk) cifs: fix double-fault crash during ntlmssp
CVE-2022-3606: (unk)
CVE-2022-36123: (unk) x86: Clear .brk area at early boot
CVE-2022-3621: (unk) nilfs2: fix NULL pointer dereference at nilfs_bmap_lookup_at_level()
CVE-2022-3624: (unk) bonding: fix reference count leak in balance-alb mode
CVE-2022-3628: (unk) wifi: brcmfmac: Fix potential buffer overflow in brcmf_fweh_event_worker()
CVE-2022-36280: (unk) drm/vmwgfx: Validate the box size for the snooped cursor
CVE-2022-3629: (unk) vsock: Fix memory leak in vsock_connect()
CVE-2022-3635: (unk) atm: idt77252: fix use-after-free bugs caused by tst_timer
CVE-2022-3636: (unk) net: ethernet: mtk_eth_soc: use after free in __mtk_ppe_check_skb()
CVE-2022-36402: (unk)
CVE-2022-3642: (unk)
CVE-2022-3643: (unk) xen/netback: Ensure protocol headers don't fall in the non-linear area
CVE-2022-3646: (unk) nilfs2: fix leak of nilfs_root in case of writer thread creation failure
CVE-2022-3649: (unk) nilfs2: fix use-after-free bug of struct nilfs_root
CVE-2022-36879: (unk) xfrm: xfrm_policy: fix a possible double xfrm_pols_put() in xfrm_bundle_lookup()
CVE-2022-36946: (unk) netfilter: nf_queue: do not allow packet truncation below transport header offset
CVE-2022-38096: (unk)
CVE-2022-3903: (unk) media: mceusb: Use new usb_control_msg_*() routines
CVE-2022-39188: (unk) mmu_gather: Force tlb-flush VM_PFNMAP vmas
CVE-2022-39842: (unk) video: fbdev: pxa3xx-gcu: Fix integer overflow in pxa3xx_gcu_write
CVE-2022-40307: (unk) efi: capsule-loader: Fix use-after-free in efi_capsule_write
CVE-2022-40768: (unk) scsi: stex: Properly zero out the passthrough command structure
CVE-2022-4095: (unk) staging: rtl8712: fix use after free bugs
CVE-2022-40982: (unk) x86/speculation: Add Gather Data Sampling mitigation
CVE-2022-41218: (unk) media: dvb-core: Fix UAF due to refcount races at releasing
CVE-2022-41222: (unk) mm/mremap: hold the rmap lock in write mode when moving page table entries.
CVE-2022-4129: (unk) l2tp: Serialize access to sk_user_data with sk_callback_lock
CVE-2022-41848: (unk)
CVE-2022-41849: (unk) fbdev: smscufx: Fix use-after-free in ufx_ops_open()
CVE-2022-41850: (unk) HID: roccat: Fix use-after-free in roccat_read()
CVE-2022-41858: (unk) drivers: net: slip: fix NPD bug in sl_tx_timeout()
CVE-2022-4269: (unk) act_mirred: use the backlog for nested calls to mirred ingress
CVE-2022-42703: (unk) mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse
CVE-2022-42895: (unk) Bluetooth: L2CAP: Fix attempting to access uninitialized memory
CVE-2022-42896: (unk) Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM
CVE-2022-43750: (unk) usb: mon: make mmapped memory read only
CVE-2022-44032: (unk) char: pcmcia: remove all the drivers
CVE-2022-44033: (unk) char: pcmcia: remove all the drivers
CVE-2022-44034: (unk) char: pcmcia: remove all the drivers
CVE-2022-4543: (unk)
CVE-2022-45884: (unk)
CVE-2022-45885: (unk)
CVE-2022-45886: (unk) media: dvb-core: Fix use-after-free due on race condition at dvb_net
CVE-2022-45887: (unk) media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb()
CVE-2022-45919: (unk) media: dvb-core: Fix use-after-free due to race condition at dvb_ca_en50221
CVE-2022-45934: (unk) Bluetooth: L2CAP: Fix u8 overflow
CVE-2022-4662: (unk) USB: core: Prevent nested device-reset calls
CVE-2022-4744: (unk) tun: avoid double free in tun_free_netdev
CVE-2022-47520: (unk) wifi: wilc1000: validate pairwise and authentication suite offsets
CVE-2022-47929: (unk) net: sched: disallow noqueue for qdisc classes
CVE-2023-0030: (unk) drm/nouveau/mmu: add more general vmm free/node handling functions
CVE-2023-0047: (unk) mm, oom: do not trigger out_of_memory from the #PF
CVE-2023-0266: (unk) ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF
CVE-2023-0386: (unk) ovl: fail on invalid uid/gid mapping at copy up
CVE-2023-0394: (unk) ipv6: raw: Deduct extension header length in rawv6_push_pending_frames
CVE-2023-0458: (unk) prlimit: do_prlimit needs to have a speculation check
CVE-2023-0459: (unk) uaccess: Add speculation barrier to copy_from_user()
CVE-2023-0590: (unk) net: sched: fix race condition in qdisc_graft()
CVE-2023-0597: (unk) x86/mm: Randomize per-cpu entry area
CVE-2023-0615: (unk) media: vivid: dev->bitmap_cap wasn't freed in all cases
CVE-2023-1073: (unk) HID: check empty report_list in hid_validate_values()
CVE-2023-1074: (unk) sctp: fail if no bound addresses can be used for a given scope
CVE-2023-1076: (unk) tun: tun_chr_open(): correctly initialize socket uid
CVE-2023-1077: (unk) sched/rt: pick_next_rt_entity(): check list_entry
CVE-2023-1095: (unk) netfilter: nf_tables: fix null deref due to zeroed list head
CVE-2023-1118: (unk) media: rc: Fix use-after-free bugs caused by ene_tx_irqsim()
CVE-2023-1206: (unk) tcp: Reduce chance of collisions in inet6_hashfn().
CVE-2023-1249: (unk) coredump: Use the vma snapshot in fill_files_note
CVE-2023-1380: (unk) wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
CVE-2023-1382: (unk) tipc: set con sock in tipc_conn_alloc
CVE-2023-1390: (unk) tipc: fix NULL deref in tipc_link_xmit()
CVE-2023-1513: (unk) kvm: initialize all of the kvm_debugregs structure before sending it to userspace
CVE-2023-1582: (unk) fs/proc: task_mmu.c: don't read mapcount for migration entry
CVE-2023-1611: (unk) btrfs: fix race between quota disable and quota assign ioctls
CVE-2023-1670: (unk) xirc2ps_cs: Fix use after free bug in xirc2ps_detach
CVE-2023-1829: (unk) net/sched: Retire tcindex classifier
CVE-2023-1838: (unk) Fix double fget() in vhost_net_set_backend()
CVE-2023-1855: (unk) hwmon: (xgene) Fix use after free bug in xgene_hwmon_remove due to race condition
CVE-2023-1989: (unk) Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work
CVE-2023-1990: (unk) nfc: st-nci: Fix use after free bug in ndlc_remove due to race condition
CVE-2023-2002: (unk) bluetooth: Perform careful capability checks in hci_sock_ioctl()
CVE-2023-2007: (unk) scsi: dpt_i2o: Remove obsolete driver
CVE-2023-20569: (unk) x86/bugs: Increase the x86 bugs vector size to two u32s
CVE-2023-20588: (unk) x86/CPU/AMD: Do not leak quotient data after a division by 0
CVE-2023-20593: (unk) x86/cpu/amd: Add a Zenbleed fix
CVE-2023-20941: (unk)
CVE-2023-2124: (unk) xfs: verify buffer contents when we skip log replay
CVE-2023-2162: (unk) scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress
CVE-2023-2176: (unk) RDMA/core: Refactor rdma_bind_addr
CVE-2023-2194: (unk) i2c: xgene-slimpro: Fix out-of-bounds bug in xgene_slimpro_i2c_xfer()
CVE-2023-2248: (unk) net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg
CVE-2023-2269: (unk) dm ioctl: fix nested locking in table_clear() to remove deadlock concern
CVE-2023-22995: (unk) usb: dwc3: dwc3-qcom: Add missing platform_device_put() in dwc3_qcom_acpi_register_core
CVE-2023-23039: (unk)
CVE-2023-23454: (unk) net: sched: cbq: dont intepret cls results when asked to drop
CVE-2023-23455: (unk) net: sched: atm: dont intepret cls results when asked to drop
CVE-2023-23559: (unk) wifi: rndis_wlan: Prevent buffer overflow in rndis_query_oid
CVE-2023-2430: (unk) io_uring/msg_ring: fix missing lock on overflow for IOPOLL
CVE-2023-2483: (unk) net: qcom/emac: Fix use after free bug in emac_remove due to race condition
CVE-2023-2513: (unk) ext4: fix use-after-free in ext4_xattr_set_entry
CVE-2023-26545: (unk) net: mpls: fix stale pointer if allocation fails during device rename
CVE-2023-26607: (unk) ntfs: fix out-of-bounds read in ntfs_attr_find()
CVE-2023-28328: (unk) media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()
CVE-2023-2860: (unk) ipv6: sr: fix out-of-bounds read when setting HMAC data.
CVE-2023-28772: (unk) seq_buf: Fix overflow in seq_buf_putmem_hex()
CVE-2023-2985: (unk) fs: hfsplus: fix UAF issue in hfsplus_put_super
CVE-2023-3006: (unk) arm64: Add AMPERE1 to the Spectre-BHB affected list
CVE-2023-3022: (unk) ipv6: Use result arg in fib_lookup_arg consistently
CVE-2023-30456: (unk) KVM: nVMX: add missing consistency checks for CR0 and CR4
CVE-2023-30772: (unk) power: supply: da9150: Fix use after free bug in da9150_charger_remove due to race condition
CVE-2023-3090: (unk) ipvlan:Fix out-of-bounds caused by unclear skb->cb
CVE-2023-31081: (unk)
CVE-2023-31082: (unk)
CVE-2023-31083: (unk) Bluetooth: hci_ldisc: check HCI_UART_PROTO_READY flag in HCIUARTGETPROTO
CVE-2023-31084: (unk) media: dvb-core: Fix kernel WARNING for blocking operation in wait_event*()
CVE-2023-31085: (unk) ubi: Refuse attaching if mtd's erasesize is 0
CVE-2023-3111: (unk) btrfs: unset reloc control if transaction commit fails in prepare_to_relocate()
CVE-2023-3117: (unk) netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE
CVE-2023-3141: (unk) memstick: r592: Fix UAF bug in r592_remove due to race condition
CVE-2023-31436: (unk) net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg
CVE-2023-3159: (unk) firewire: fix potential uaf in outbound_phy_packet_callback()
CVE-2023-3161: (unk) fbcon: Check font dimension limits
CVE-2023-3212: (unk) gfs2: Don't deref jdesc in evict
CVE-2023-32233: (unk) netfilter: nf_tables: deactivate anonymous set from preparation phase
CVE-2023-32269: (unk) netrom: Fix use-after-free caused by accept on already connected socket
CVE-2023-3268: (unk) relayfs: fix out-of-bounds access in relay_file_read
CVE-2023-33203: (unk) net: qcom/emac: Fix use after free bug in emac_remove due to race condition
CVE-2023-33288: (unk) power: supply: bq24190: Fix use after free bug in bq24190_remove due to race condition
CVE-2023-3338: (unk) Remove DECnet support from kernel
CVE-2023-3358: (unk) HID: intel_ish-hid: Add check for ishtp_dma_tx_map
CVE-2023-3390: (unk) netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE
CVE-2023-3397: (unk)
CVE-2023-34255: (unk) xfs: verify buffer contents when we skip log replay
CVE-2023-34256: (unk) ext4: avoid a potential slab-out-of-bounds in ext4_group_desc_csum
CVE-2023-35001: (unk) netfilter: nf_tables: prevent OOB access in nft_byteorder_eval
CVE-2023-3567: (unk) vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF
CVE-2023-35824: (unk) media: dm1105: Fix use after free bug in dm1105_remove due to race condition
CVE-2023-35827: (unk) ravb: Fix use-after-free issue in ravb_tx_timeout_work()
CVE-2023-3611: (unk) net/sched: sch_qfq: account for stab overhead in qfq_enqueue
CVE-2023-3640: (unk)
CVE-2023-37454: (unk)
CVE-2023-3772: (unk) xfrm: add NULL check in xfrm_update_ae_params
CVE-2023-3776: (unk) net/sched: cls_fw: Fix improper refcount update leads to use-after-free
CVE-2023-3863: (unk) net: nfc: Fix use-after-free caused by nfc_llcp_find_local
CVE-2023-39189: (unk) netfilter: nfnetlink_osf: avoid OOB read
CVE-2023-39192: (unk) netfilter: xt_u32: validate user space input
CVE-2023-39193: (unk) netfilter: xt_sctp: validate the flag_info count
CVE-2023-39194: (unk) net: xfrm: Fix xfrm_address_filter OOB read
CVE-2023-39197: (unk) netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one
CVE-2023-39198: (unk) drm/qxl: fix UAF on handle creation
CVE-2023-4010: (unk)
CVE-2023-40283: (unk) Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb
CVE-2023-4128: (unk) net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free
CVE-2023-4132: (unk) media: usb: siano: Fix warning due to null work_func_t function pointer
CVE-2023-4134: (unk) Input: cyttsp4_core - change del_timer_sync() to timer_shutdown_sync()
CVE-2023-4206: (unk) net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free
CVE-2023-4207: (unk) net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free
CVE-2023-4208: (unk) net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free
CVE-2023-42752: (unk) igmp: limit igmpv3_newpack() packet size to IP_MAX_MTU
CVE-2023-42755: (unk) net/sched: Retire rsvp classifier
CVE-2023-4385: (unk) fs: jfs: fix possible NULL pointer dereference in dbFree()
CVE-2023-4387: (unk) net: vmxnet3: fix possible use-after-free bugs in vmxnet3_rq_alloc_rx_buf()
CVE-2023-4459: (unk) net: vmxnet3: fix possible NULL pointer dereference in vmxnet3_rq_cleanup()
CVE-2023-45862: (unk) USB: ene_usb6250: Allocate enough memory for full object
CVE-2023-45863: (unk) kobject: Fix slab-out-of-bounds in fill_kobj_path()
CVE-2023-45871: (unk) igb: set max size RX buffer when store bad packet is enabled
CVE-2023-4610: (unk) Revert "mm: vmscan: make global slab shrink lockless"
CVE-2023-4622: (unk) unix: Convert unix_stream_sendpage() to use MSG_SPLICE_PAGES
CVE-2023-4623: (unk) net/sched: sch_hfsc: Ensure inner classes have fsc curve
CVE-2023-47233: (unk)
CVE-2023-4732: (unk) mm/userfaultfd: fix uffd-wp special cases for fork()
CVE-2023-4881: (unk) netfilter: nftables: exthdr: fix 4-byte stack OOB write
CVE-2023-4921: (unk) net: sched: sch_qfq: Fix UAF in qfq_dequeue()
CVE-2023-50431: (unk)
CVE-2023-51779: (unk) Bluetooth: af_bluetooth: Fix Use-After-Free in bt_sock_recvmsg
CVE-2023-51780: (unk) atm: Fix Use-After-Free in do_vcc_ioctl
CVE-2023-51781: (unk) appletalk: Fix Use-After-Free in atalk_ioctl
CVE-2023-51782: (unk) net/rose: Fix Use-After-Free in rose_ioctl
CVE-2023-5717: (unk) perf: Disallow mis-matched inherited group reads
CVE-2023-6121: (unk) nvmet: nul-terminate the NQNs passed in the connect command
CVE-2023-6356: (unk)
CVE-2023-6535: (unk)
CVE-2023-6536: (unk)
CVE-2023-6546: (unk) tty: n_gsm: fix the UAF caused by race condition in gsm_cleanup_mux
CVE-2023-6560: (unk) io_uring: don't allow discontig pages for IORING_SETUP_NO_MMAP
CVE-2023-6606: (unk) smb: client: fix OOB in smbCalcSize()
CVE-2023-6610: (unk) smb: client: fix potential OOB in smb2_dump_detail()
CVE-2023-6622: (unk) netfilter: nf_tables: bail out on mismatching dynset and set expressions
CVE-2023-6679: (unk) dpll: sanitize possible null pointer dereference in dpll_pin_parent_pin_set()
CVE-2023-6817: (unk) netfilter: nft_set_pipapo: skip inactive elements during set walk
CVE-2023-6931: (unk) perf: Fix perf_event_validate_size()
CVE-2023-6932: (unk) ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet
CVE-2023-7042: (unk)