Update 9Jun22 [ci skip]
diff --git a/CHANGES.md b/CHANGES.md index e945541..d85a715 100644 --- a/CHANGES.md +++ b/CHANGES.md
@@ -1,19 +1,41 @@ # **Linux Kernel CVE Changes** -## Last Update - 05Jun22 09:52 +## Last Update - 09Jun22 16:24 ### **New CVEs Added:** -[CVE-2022-1966](cves/CVE-2022-1966) -[CVE-2022-1972](cves/CVE-2022-1972) +[CVE-2022-1973](cves/CVE-2022-1973) +[CVE-2022-1974](cves/CVE-2022-1974) +[CVE-2022-1975](cves/CVE-2022-1975) +[CVE-2022-1998](cves/CVE-2022-1998) +[CVE-2022-20132](cves/CVE-2022-20132) +[CVE-2022-20141](cves/CVE-2022-20141) +[CVE-2022-20148](cves/CVE-2022-20148) +[CVE-2022-20153](cves/CVE-2022-20153) +[CVE-2022-20154](cves/CVE-2022-20154) +[CVE-2022-20166](cves/CVE-2022-20166) +[CVE-2022-32296](cves/CVE-2022-32296) + + +### **New Versions Checked:** + +[4.14.282](streams/4.14) +[4.19.246](streams/4.19) +[4.9.317](streams/4.9) +[5.10.121](streams/5.10) +[5.15.46](streams/5.15) +[5.17.14](streams/5.17) +[5.19-rc1](streams/5.19-rc1) +[5.4.197](streams/5.4) ### **Updated CVEs:** -[CVE-2022-1419](cves/CVE-2022-1419) -[CVE-2022-1462](cves/CVE-2022-1462) -[CVE-2022-1652](cves/CVE-2022-1652) -[CVE-2022-1786](cves/CVE-2022-1786) -[CVE-2022-1789](cves/CVE-2022-1789) -[CVE-2022-1943](cves/CVE-2022-1943) +[CVE-2022-0494](cves/CVE-2022-0494) +[CVE-2022-1012](cves/CVE-2022-1012) +[CVE-2022-1852](cves/CVE-2022-1852) +[CVE-2022-1966](cves/CVE-2022-1966) +[CVE-2022-1972](cves/CVE-2022-1972) +[CVE-2022-1678](cves/CVE-2022-1678) +[CVE-2022-1882](cves/CVE-2022-1882)
diff --git a/data/3.12/3.12_CVEs.txt b/data/3.12/3.12_CVEs.txt index 4b42250..19a1bc5 100644 --- a/data/3.12/3.12_CVEs.txt +++ b/data/3.12/3.12_CVEs.txt
@@ -1142,7 +1142,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -1173,3 +1183,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/3.12/3.12_security.txt b/data/3.12/3.12_security.txt index 391d80f..81e4be1 100644 --- a/data/3.12/3.12_security.txt +++ b/data/3.12/3.12_security.txt
@@ -1280,7 +1280,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1311,3 +1321,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/3.14/3.14_CVEs.txt b/data/3.14/3.14_CVEs.txt index 324afe6..f688a18 100644 --- a/data/3.14/3.14_CVEs.txt +++ b/data/3.14/3.14_CVEs.txt
@@ -1108,7 +1108,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -1139,3 +1149,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/3.14/3.14_security.txt b/data/3.14/3.14_security.txt index 3bf6c4d..2940471 100644 --- a/data/3.14/3.14_security.txt +++ b/data/3.14/3.14_security.txt
@@ -1242,7 +1242,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1273,3 +1283,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/3.16/3.16_CVEs.txt b/data/3.16/3.16_CVEs.txt index 04d3cbe..911548c 100644 --- a/data/3.16/3.16_CVEs.txt +++ b/data/3.16/3.16_CVEs.txt
@@ -1089,7 +1089,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -1120,3 +1130,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/3.16/3.16_security.txt b/data/3.16/3.16_security.txt index cc02d9c..2ca6446 100644 --- a/data/3.16/3.16_security.txt +++ b/data/3.16/3.16_security.txt
@@ -1195,7 +1195,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1226,3 +1236,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/3.18/3.18_CVEs.txt b/data/3.18/3.18_CVEs.txt index f30de8a..1086ad3 100644 --- a/data/3.18/3.18_CVEs.txt +++ b/data/3.18/3.18_CVEs.txt
@@ -1073,7 +1073,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -1104,3 +1114,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/3.18/3.18_security.txt b/data/3.18/3.18_security.txt index 7ef8879..c438fa6 100644 --- a/data/3.18/3.18_security.txt +++ b/data/3.18/3.18_security.txt
@@ -1307,7 +1307,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1338,3 +1348,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/3.2/3.2_CVEs.txt b/data/3.2/3.2_CVEs.txt index c345106..df2af4b 100644 --- a/data/3.2/3.2_CVEs.txt +++ b/data/3.2/3.2_CVEs.txt
@@ -1128,7 +1128,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -1158,3 +1168,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/3.2/3.2_security.txt b/data/3.2/3.2_security.txt index 905db46..1c968e2 100644 --- a/data/3.2/3.2_security.txt +++ b/data/3.2/3.2_security.txt
@@ -1284,7 +1284,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1314,3 +1324,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.1/4.1_CVEs.txt b/data/4.1/4.1_CVEs.txt index 8376457..e032f40 100644 --- a/data/4.1/4.1_CVEs.txt +++ b/data/4.1/4.1_CVEs.txt
@@ -1029,7 +1029,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -1061,3 +1071,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.1/4.1_security.txt b/data/4.1/4.1_security.txt index ed80729..299c5e2 100644 --- a/data/4.1/4.1_security.txt +++ b/data/4.1/4.1_security.txt
@@ -1125,7 +1125,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1157,3 +1167,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.10/4.10_CVEs.txt b/data/4.10/4.10_CVEs.txt index 7d3f8b9..b84a638 100644 --- a/data/4.10/4.10_CVEs.txt +++ b/data/4.10/4.10_CVEs.txt
@@ -920,7 +920,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -952,3 +962,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.10/4.10_security.txt b/data/4.10/4.10_security.txt index 0fd137b..748df37 100644 --- a/data/4.10/4.10_security.txt +++ b/data/4.10/4.10_security.txt
@@ -954,7 +954,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -986,3 +996,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.11/4.11_CVEs.txt b/data/4.11/4.11_CVEs.txt index cb6ca46..a040cb3 100644 --- a/data/4.11/4.11_CVEs.txt +++ b/data/4.11/4.11_CVEs.txt
@@ -890,7 +890,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -923,3 +933,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.11/4.11_security.txt b/data/4.11/4.11_security.txt index 9ec3f2e..144218a 100644 --- a/data/4.11/4.11_security.txt +++ b/data/4.11/4.11_security.txt
@@ -912,7 +912,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -945,3 +955,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.12/4.12_CVEs.txt b/data/4.12/4.12_CVEs.txt index ec689ac..8c38f65 100644 --- a/data/4.12/4.12_CVEs.txt +++ b/data/4.12/4.12_CVEs.txt
@@ -869,7 +869,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -902,3 +912,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.12/4.12_security.txt b/data/4.12/4.12_security.txt index 00dec5f..a975319 100644 --- a/data/4.12/4.12_security.txt +++ b/data/4.12/4.12_security.txt
@@ -895,7 +895,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -928,3 +938,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.13/4.13_CVEs.txt b/data/4.13/4.13_CVEs.txt index f6b6e52..0ef5749 100644 --- a/data/4.13/4.13_CVEs.txt +++ b/data/4.13/4.13_CVEs.txt
@@ -852,7 +852,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -885,3 +895,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.13/4.13_security.txt b/data/4.13/4.13_security.txt index 96e50ba..e16606c 100644 --- a/data/4.13/4.13_security.txt +++ b/data/4.13/4.13_security.txt
@@ -880,7 +880,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -913,3 +923,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.14/4.14_CVEs.txt b/data/4.14/4.14_CVEs.txt index 539df8f..1c3ae5a 100644 --- a/data/4.14/4.14_CVEs.txt +++ b/data/4.14/4.14_CVEs.txt
@@ -769,7 +769,7 @@ CVE-2022-0480: Fix not seen in stream CVE-2022-0487: Fixed with 4.14.266 CVE-2022-0492: Fixed with 4.14.266 -CVE-2022-0494: Fix not seen in stream +CVE-2022-0494: Fixed with 4.14.282 CVE-2022-0500: Fix not seen in stream CVE-2022-0617: Fixed with 4.14.265 CVE-2022-0644: Fixed with 4.14.253 @@ -780,7 +780,7 @@ CVE-2022-0995: Fix not seen in stream CVE-2022-0998: Fix not seen in stream CVE-2022-1011: Fixed with 4.14.276 -CVE-2022-1012: Fix not seen in stream +CVE-2022-1012: Fixed with 4.14.282 CVE-2022-1015: Fix not seen in stream CVE-2022-1016: Fixed with 4.14.274 CVE-2022-1043: Fix not seen in stream @@ -817,7 +817,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fixed with 4.14.278 +CVE-2022-1975: Fixed with 4.14.278 +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fixed with 4.14.258 +CVE-2022-20141: Fixed with 4.14.247 +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fixed with 4.14.261 +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fixed with 4.14.264 CVE-2022-23036: Fixed with 4.14.271 CVE-2022-23037: Fixed with 4.14.271 @@ -851,3 +861,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fixed with 4.14.276 +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.14/4.14_security.txt b/data/4.14/4.14_security.txt index e41379d..349bad7 100644 --- a/data/4.14/4.14_security.txt +++ b/data/4.14/4.14_security.txt
@@ -980,6 +980,7 @@ CVEs fixed in 4.14.247: CVE-2021-40490: 9569234645f102025aaf0fc83d3dcbf1b8cbf2dc ext4: fix race writing to an inline_data file while its xattrs are changing CVE-2021-42252: b1b55e4073d3da6119ecc41636a2994b67a2be37 soc: aspeed: lpc-ctrl: Fix boundary check for mmap + CVE-2022-20141: 78967749984cf3614de346c90f3e259ff8272735 igmp: Add ip_mc_list lock in ip_check_mc_rcu CVEs fixed in 4.14.248: CVE-2021-20320: daf48f68fca9040b542282a5cd17397af316dd89 s390/bpf: Fix optimizing out zero-extensions @@ -1028,6 +1029,7 @@ CVEs fixed in 4.14.258: CVE-2021-39685: e7c8afee149134b438df153b09af7fd928a8bc24 USB: gadget: detect too-big endpoint 0 requests CVE-2021-39698: a36e1978c6cb6282fadd5d62d4b3e7808cf0597b wait: add wake_up_pollfree() + CVE-2022-20132: 43cc4686b15d7d3a2b65b125393ea3f3d477e7d1 HID: add hid_is_usb() function to make it simpler for USB detection CVEs fixed in 4.14.259: CVE-2021-28711: 5ac3b68b79c9e964dd6f3cf80ff825518e502b79 xen/blkfront: harden blkfront against event channel storms @@ -1043,6 +1045,7 @@ CVEs fixed in 4.14.261: CVE-2021-44733: 3d556a28bbfe34a80b014db49908b0f1bcb1ae80 tee: handle lookup of shm with reference count 0 + CVE-2022-20154: 8873140f95d4977bf37e4cf0d5c5e3f6e34cdd3e sctp: use call_rcu to free endpoint CVEs fixed in 4.14.262: CVE-2021-4155: 2af625c89bf4a41c8a0bc818d8cf30a291f216ca xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate @@ -1122,6 +1125,8 @@ CVE-2022-1419: d2b8e8fbac9f175388d2808ade90d86402642b01 drm/vgem: Close use-after-free race in vgem_gem_create CVE-2022-1734: ced30680fb1c7c1daae39a9384d23cd1a022585f nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs CVE-2022-1836: b7fa84ae1171a3c5ea5d710899080a6e63cfe084 floppy: disable FDRAWCMD by default + CVE-2022-1974: 6f0ac4cd0377ab4e0b49b8f6efd37057c21336a9 nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: c33b2afffe8ae90e0bd4790e0505edd92addf14c NFC: netlink: fix sleep in atomic bug when firmware download timeout CVE-2022-29581: 0511cdd41a03ab396602dded4e778c5edcd8dcd1 net/sched: cls_u32: fix netns refcount changes in u32_change() CVEs fixed in 4.14.279: @@ -1131,6 +1136,10 @@ CVE-2022-0854: aaf166f37eb6bb55d81c3e40a2a460c8875c8813 swiotlb: rework "fix info leak with DMA_FROM_DEVICE" CVE-2022-1729: dee63319e2d1abd5d37a89de046ccf32ca8a8451 perf: Fix sys_perf_event_open() race against self +CVEs fixed in 4.14.282: + CVE-2022-0494: 4f3ea768c56e8dce55ae538f18b37420366c5c22 block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern + CVE-2022-1012: 40d20f3186ddd9b6b94598f4ef3d07644b0fa43c secure_seq: use the 64 bits of the siphash for port offset calculation + Outstanding CVEs: CVE-2005-3660: (unk) CVE-2007-3719: (unk) @@ -1266,13 +1275,11 @@ CVE-2022-0382: (unk) net ticp:fix a kernel-infoleak in __tipc_sendmsg() CVE-2022-0400: (unk) CVE-2022-0480: (unk) memcg: enable accounting for file lock caches - CVE-2022-0494: (unk) block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern CVE-2022-0500: (unk) bpf: Introduce MEM_RDONLY flag CVE-2022-0742: (unk) ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report() CVE-2022-0812: (unk) xprtrdma: fix incorrect header size calculations CVE-2022-0995: (unk) watch_queue: Fix filter limit check CVE-2022-0998: (unk) vdpa: clean up get_config_size ret value handling - CVE-2022-1012: (unk) secure_seq: use the 64 bits of the siphash for port offset calculation CVE-2022-1015: (unk) netfilter: nf_tables: validate registers coming from userspace. CVE-2022-1043: (unk) io_uring: fix xa_alloc_cycle() error return value check CVE-2022-1055: (unk) net: sched: fix use-after-free in tc_new_tfilter() @@ -1296,7 +1303,12 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23222: (unk) bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL CVE-2022-25265: (unk) CVE-2022-25636: (unk) netfilter: nf_tables_offload: incorrect flow offload action array size @@ -1307,3 +1319,4 @@ CVE-2022-29156: (unk) RDMA/rtrs-clt: Fix possible double free in error case CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.15/4.15_CVEs.txt b/data/4.15/4.15_CVEs.txt index c0ba479..c6c2dea 100644 --- a/data/4.15/4.15_CVEs.txt +++ b/data/4.15/4.15_CVEs.txt
@@ -767,7 +767,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -801,3 +811,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.15/4.15_security.txt b/data/4.15/4.15_security.txt index f176045..3b596b7 100644 --- a/data/4.15/4.15_security.txt +++ b/data/4.15/4.15_security.txt
@@ -799,7 +799,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -833,3 +843,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.16/4.16_CVEs.txt b/data/4.16/4.16_CVEs.txt index 22737bb..d43383f 100644 --- a/data/4.16/4.16_CVEs.txt +++ b/data/4.16/4.16_CVEs.txt
@@ -745,7 +745,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -779,3 +789,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.16/4.16_security.txt b/data/4.16/4.16_security.txt index 5d97e3c..38b9175 100644 --- a/data/4.16/4.16_security.txt +++ b/data/4.16/4.16_security.txt
@@ -777,7 +777,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -811,3 +821,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.17/4.17_CVEs.txt b/data/4.17/4.17_CVEs.txt index d183324..bb4f456 100644 --- a/data/4.17/4.17_CVEs.txt +++ b/data/4.17/4.17_CVEs.txt
@@ -725,7 +725,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -759,3 +769,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.17/4.17_security.txt b/data/4.17/4.17_security.txt index 9d0d99b..99c72f6 100644 --- a/data/4.17/4.17_security.txt +++ b/data/4.17/4.17_security.txt
@@ -757,7 +757,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -791,3 +801,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.18/4.18_CVEs.txt b/data/4.18/4.18_CVEs.txt index b890080..19902bd 100644 --- a/data/4.18/4.18_CVEs.txt +++ b/data/4.18/4.18_CVEs.txt
@@ -702,7 +702,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -736,3 +746,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.18/4.18_security.txt b/data/4.18/4.18_security.txt index 5cf2e16..8585790 100644 --- a/data/4.18/4.18_security.txt +++ b/data/4.18/4.18_security.txt
@@ -734,7 +734,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -768,3 +778,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.19/4.19_CVEs.txt b/data/4.19/4.19_CVEs.txt index 3782a1f..f22e9f8 100644 --- a/data/4.19/4.19_CVEs.txt +++ b/data/4.19/4.19_CVEs.txt
@@ -626,7 +626,7 @@ CVE-2022-0480: Fix not seen in stream CVE-2022-0487: Fixed with 4.19.229 CVE-2022-0492: Fixed with 4.19.229 -CVE-2022-0494: Fix not seen in stream +CVE-2022-0494: Fixed with 4.19.246 CVE-2022-0500: Fix not seen in stream CVE-2022-0617: Fixed with 4.19.228 CVE-2022-0644: Fixed with 4.19.214 @@ -637,7 +637,7 @@ CVE-2022-0995: Fix not seen in stream CVE-2022-0998: Fix not seen in stream CVE-2022-1011: Fixed with 4.19.238 -CVE-2022-1012: Fix not seen in stream +CVE-2022-1012: Fixed with 4.19.246 CVE-2022-1015: Fix not seen in stream CVE-2022-1016: Fixed with 4.19.237 CVE-2022-1043: Fix not seen in stream @@ -674,7 +674,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fixed with 4.19.242 +CVE-2022-1975: Fixed with 4.19.242 +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fixed with 4.19.231 +CVE-2022-20132: Fixed with 4.19.221 +CVE-2022-20141: Fixed with 4.19.207 +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fixed with 4.19.224 +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fixed with 4.19.227 CVE-2022-23036: Fixed with 4.19.234 CVE-2022-23037: Fixed with 4.19.234 @@ -709,3 +719,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fixed with 4.19.238 +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.19/4.19_security.txt b/data/4.19/4.19_security.txt index 957c163..c3e133a 100644 --- a/data/4.19/4.19_security.txt +++ b/data/4.19/4.19_security.txt
@@ -780,6 +780,7 @@ CVE-2021-35477: 91cdb5b36234e6af69d6280f1510e4453707a2b8 bpf: Introduce BPF nospec instruction for mitigating Spectre v4 CVE-2021-40490: c481607ba522e31e6ed01efefc19cc1d0e0a46fa ext4: fix race writing to an inline_data file while its xattrs are changing CVE-2021-42252: 9c8891b638319ddba9cfa330247922cd960c95b0 soc: aspeed: lpc-ctrl: Fix boundary check for mmap + CVE-2022-20141: 4768973dffed4d0126854514335ed4fe87bec1ab igmp: Add ip_mc_list lock in ip_check_mc_rcu CVEs fixed in 4.19.208: CVE-2021-20320: ddf58efd05b5d16d86ea4638675e8bd397320930 s390/bpf: Fix optimizing out zero-extensions @@ -833,6 +834,7 @@ CVE-2021-39685: 13e45e7a262dd96e8161823314679543048709b9 USB: gadget: detect too-big endpoint 0 requests CVE-2021-39698: 8dd7c46a59756bdc29cb9783338b899cd3fb4b83 wait: add wake_up_pollfree() CVE-2021-39713: ae214e04b95ff64a4b0e9aab6742520bfde6ff0c net: sched: use Qdisc rcu API instead of relying on rtnl lock + CVE-2022-20132: b1efa723b986a84f84a95b6907cffe3a357338c9 HID: add hid_is_usb() function to make it simpler for USB detection CVEs fixed in 4.19.222: CVE-2021-28711: 269d7124bcfad2558d2329d0fe603ca20b20d3f4 xen/blkfront: harden blkfront against event channel storms @@ -848,6 +850,7 @@ CVEs fixed in 4.19.224: CVE-2021-44733: b4a661b4212b8fac8853ec3b68e4a909dccc88a1 tee: handle lookup of shm with reference count 0 + CVE-2022-20154: af6e6e58f7ebf86b4e7201694b1e4f3a62cbc3ec sctp: use call_rcu to free endpoint CVEs fixed in 4.19.225: CVE-2021-4155: 1c3564fca0e7b8c9e96245a2cb35e198b036ee9a xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate @@ -930,6 +933,8 @@ CVEs fixed in 4.19.242: CVE-2022-1419: df2c1f38939aabb8c6beca108f08b90f050b9ebc drm/vgem: Close use-after-free race in vgem_gem_create CVE-2022-1734: b266f492b2af82269aaaab871ac3949420ae678c nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs + CVE-2022-1974: 7deebb94a311da0e02e621e765c3aef3d5936572 nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: d360fc8df363ecd7892d755d69ffc8c61d699e38 NFC: netlink: fix sleep in atomic bug when firmware download timeout CVEs fixed in 4.19.243: CVE-2022-1048: 9cb6c40a6ebe4a0cfc9d6a181958211682cffea9 ALSA: pcm: Fix races among concurrent hw_params and hw_free calls @@ -938,6 +943,10 @@ CVE-2022-0854: 06cb238b0f7ac1669cb06390704c61794724c191 swiotlb: rework "fix info leak with DMA_FROM_DEVICE" CVE-2022-1729: 6cdd53a49aa7413e53c14ece27d826f0b628b18a perf: Fix sys_perf_event_open() race against self +CVEs fixed in 4.19.246: + CVE-2022-0494: 18243d8479fd77952bdb6340024169d30b173a40 block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern + CVE-2022-1012: 695309c5c71526d32f5539f008bbf20ed2218528 secure_seq: use the 64 bits of the siphash for port offset calculation + Outstanding CVEs: CVE-2005-3660: (unk) CVE-2007-3719: (unk) @@ -1051,13 +1060,11 @@ CVE-2022-0382: (unk) net ticp:fix a kernel-infoleak in __tipc_sendmsg() CVE-2022-0400: (unk) CVE-2022-0480: (unk) memcg: enable accounting for file lock caches - CVE-2022-0494: (unk) block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern CVE-2022-0500: (unk) bpf: Introduce MEM_RDONLY flag CVE-2022-0742: (unk) ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report() CVE-2022-0812: (unk) xprtrdma: fix incorrect header size calculations CVE-2022-0995: (unk) watch_queue: Fix filter limit check CVE-2022-0998: (unk) vdpa: clean up get_config_size ret value handling - CVE-2022-1012: (unk) secure_seq: use the 64 bits of the siphash for port offset calculation CVE-2022-1015: (unk) netfilter: nf_tables: validate registers coming from userspace. CVE-2022-1043: (unk) io_uring: fix xa_alloc_cycle() error return value check CVE-2022-1055: (unk) net: sched: fix use-after-free in tc_new_tfilter() @@ -1081,6 +1088,11 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23222: (unk) bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL CVE-2022-25265: (unk) CVE-2022-25636: (unk) netfilter: nf_tables_offload: incorrect flow offload action array size @@ -1091,3 +1103,4 @@ CVE-2022-29156: (unk) RDMA/rtrs-clt: Fix possible double free in error case CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.20/4.20_CVEs.txt b/data/4.20/4.20_CVEs.txt index 17bb9d4..300f09e 100644 --- a/data/4.20/4.20_CVEs.txt +++ b/data/4.20/4.20_CVEs.txt
@@ -662,7 +662,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -697,3 +707,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.20/4.20_security.txt b/data/4.20/4.20_security.txt index b8989fd..3c1703d 100644 --- a/data/4.20/4.20_security.txt +++ b/data/4.20/4.20_security.txt
@@ -694,7 +694,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -729,3 +739,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.3/4.3_CVEs.txt b/data/4.3/4.3_CVEs.txt index bc2d17c..d8d5d0f 100644 --- a/data/4.3/4.3_CVEs.txt +++ b/data/4.3/4.3_CVEs.txt
@@ -1024,7 +1024,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -1056,3 +1066,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.3/4.3_security.txt b/data/4.3/4.3_security.txt index 4e8ff17..f8414dc 100644 --- a/data/4.3/4.3_security.txt +++ b/data/4.3/4.3_security.txt
@@ -1040,7 +1040,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1072,3 +1082,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.4/4.4_CVEs.txt b/data/4.4/4.4_CVEs.txt index 90b6a42..4594448 100644 --- a/data/4.4/4.4_CVEs.txt +++ b/data/4.4/4.4_CVEs.txt
@@ -1003,7 +1003,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fixed with 4.4.295 +CVE-2022-20141: Fixed with 4.4.284 +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -1035,3 +1045,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.4/4.4_security.txt b/data/4.4/4.4_security.txt index 25e20f1..3d6b805 100644 --- a/data/4.4/4.4_security.txt +++ b/data/4.4/4.4_security.txt
@@ -1188,6 +1188,7 @@ CVEs fixed in 4.4.284: CVE-2020-3702: 4d6b4335838fd89419212e1e486c415ec36fb610 ath: Use safer key clearing with key cache entries CVE-2021-40490: 69d82df68fbc5e368820123200d7b88f6c058350 ext4: fix race writing to an inline_data file while its xattrs are changing + CVE-2022-20141: b24065948ae6c48c9e20891f8cfe9850f1d748be igmp: Add ip_mc_list lock in ip_check_mc_rcu CVEs fixed in 4.4.285: CVE-2021-20320: a738597a79e588bcf9817d4ec12740c99842db3b s390/bpf: Fix optimizing out zero-extensions @@ -1225,6 +1226,7 @@ CVEs fixed in 4.4.295: CVE-2021-39685: 93cd7100fe471c5f76fb942358de4ed70dbcaf35 USB: gadget: detect too-big endpoint 0 requests CVE-2021-39698: d0ceebaae0e406263b83462701b5645e075c1467 wait: add wake_up_pollfree() + CVE-2022-20132: 6a0bc60a84cb5186a84e7501616dacfd9e991b54 HID: add hid_is_usb() function to make it simpler for USB detection CVEs fixed in 4.4.296: CVE-2021-28711: 3e04b9e6aa7d77287e70a400be83060d2b7b2cfe xen/blkfront: harden blkfront against event channel storms @@ -1487,7 +1489,15 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1519,3 +1529,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.5/4.5_CVEs.txt b/data/4.5/4.5_CVEs.txt index c136085..9c15d55 100644 --- a/data/4.5/4.5_CVEs.txt +++ b/data/4.5/4.5_CVEs.txt
@@ -985,7 +985,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -1017,3 +1027,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.5/4.5_security.txt b/data/4.5/4.5_security.txt index 0fa4911..752815d 100644 --- a/data/4.5/4.5_security.txt +++ b/data/4.5/4.5_security.txt
@@ -1001,7 +1001,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1033,3 +1043,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.6/4.6_CVEs.txt b/data/4.6/4.6_CVEs.txt index 23fc8f2..46138b2 100644 --- a/data/4.6/4.6_CVEs.txt +++ b/data/4.6/4.6_CVEs.txt
@@ -955,7 +955,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -987,3 +997,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.6/4.6_security.txt b/data/4.6/4.6_security.txt index 763ceee..93fbb75 100644 --- a/data/4.6/4.6_security.txt +++ b/data/4.6/4.6_security.txt
@@ -973,7 +973,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1005,3 +1015,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.7/4.7_CVEs.txt b/data/4.7/4.7_CVEs.txt index aabd64f..90db659 100644 --- a/data/4.7/4.7_CVEs.txt +++ b/data/4.7/4.7_CVEs.txt
@@ -936,7 +936,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -968,3 +978,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.7/4.7_security.txt b/data/4.7/4.7_security.txt index 0f9302f..98906d1 100644 --- a/data/4.7/4.7_security.txt +++ b/data/4.7/4.7_security.txt
@@ -956,7 +956,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -988,3 +998,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.8/4.8_CVEs.txt b/data/4.8/4.8_CVEs.txt index fb351af..abd7957 100644 --- a/data/4.8/4.8_CVEs.txt +++ b/data/4.8/4.8_CVEs.txt
@@ -940,7 +940,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream CVE-2022-23038: Fix not seen in stream @@ -972,3 +982,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.8/4.8_security.txt b/data/4.8/4.8_security.txt index cabc940..f7f34d1 100644 --- a/data/4.8/4.8_security.txt +++ b/data/4.8/4.8_security.txt
@@ -970,7 +970,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status CVE-2022-23038: (unk) xen/grant-table: add gnttab_try_end_foreign_access() @@ -1002,3 +1012,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/4.9/4.9_CVEs.txt b/data/4.9/4.9_CVEs.txt index bd5f1a1..7c26768 100644 --- a/data/4.9/4.9_CVEs.txt +++ b/data/4.9/4.9_CVEs.txt
@@ -891,7 +891,7 @@ CVE-2022-0480: Fix not seen in stream CVE-2022-0487: Fixed with 4.9.301 CVE-2022-0492: Fixed with 4.9.301 -CVE-2022-0494: Fix not seen in stream +CVE-2022-0494: Fixed with 4.9.317 CVE-2022-0500: Fix not seen in stream CVE-2022-0617: Fixed with 4.9.300 CVE-2022-0644: Fixed with 4.9.288 @@ -939,7 +939,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fixed with 4.9.313 +CVE-2022-1975: Fixed with 4.9.313 +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fixed with 4.9.293 +CVE-2022-20141: Fixed with 4.9.283 +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-23036: Fixed with 4.9.306 CVE-2022-23037: Fixed with 4.9.306 CVE-2022-23038: Fixed with 4.9.306 @@ -971,3 +981,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fixed with 4.9.311 +CVE-2022-32296: Fix not seen in stream
diff --git a/data/4.9/4.9_security.txt b/data/4.9/4.9_security.txt index 98f70e4..332f507 100644 --- a/data/4.9/4.9_security.txt +++ b/data/4.9/4.9_security.txt
@@ -1130,6 +1130,7 @@ CVEs fixed in 4.9.283: CVE-2020-3702: ea3f7df20fc8e0b82ec0e065b0b0d38e55fd7775 ath: Use safer key clearing with key cache entries CVE-2021-40490: 7067b09fe587cbd47544a3047a40c64e4d636fff ext4: fix race writing to an inline_data file while its xattrs are changing + CVE-2022-20141: e9924c4204ede999b0515fd31a370a1e27f676bc igmp: Add ip_mc_list lock in ip_check_mc_rcu CVEs fixed in 4.9.284: CVE-2021-20320: c22cf38428cb910f1996839c917e9238d2e44d4b s390/bpf: Fix optimizing out zero-extensions @@ -1169,6 +1170,7 @@ CVEs fixed in 4.9.293: CVE-2021-39685: d2ca6859ea96c6d4c6ad3d6873a308a004882419 USB: gadget: detect too-big endpoint 0 requests CVE-2021-39698: 0e92a7e47a0411d5208990c83a3d200515e314e8 wait: add wake_up_pollfree() + CVE-2022-20132: 28d8244f3ec961a11bfb4ad83cdc48ff9b8c47a7 HID: add hid_is_usb() function to make it simpler for USB detection CVEs fixed in 4.9.294: CVE-2021-28711: 25898389795bd85d8e1520c0c75c3ad906c17da7 xen/blkfront: harden blkfront against event channel storms @@ -1250,10 +1252,15 @@ CVEs fixed in 4.9.313: CVE-2022-1734: 4721695be941626e4b18b89e0641e36fc385cfd8 nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs CVE-2022-1836: 0dd02ff72c6daf4e7800fb5dd1109fbacdde97dc floppy: disable FDRAWCMD by default + CVE-2022-1974: fa2217b66467917a623993c14d671661ad625fb6 nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: a93ea9595fde438996d7b9322749d4d1921162f7 NFC: netlink: fix sleep in atomic bug when firmware download timeout CVEs fixed in 4.9.316: CVE-2022-1729: a1466528d8ae5d9a3bb29781f0098fa3476e9e1c perf: Fix sys_perf_event_open() race against self +CVEs fixed in 4.9.317: + CVE-2022-0494: d59073bedb7cf752b8cd4027dd0f67cf7ac4330f block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern + Outstanding CVEs: CVE-2005-3660: (unk) CVE-2007-3719: (unk) @@ -1424,7 +1431,6 @@ CVE-2022-0382: (unk) net ticp:fix a kernel-infoleak in __tipc_sendmsg() CVE-2022-0400: (unk) CVE-2022-0480: (unk) memcg: enable accounting for file lock caches - CVE-2022-0494: (unk) block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern CVE-2022-0500: (unk) bpf: Introduce MEM_RDONLY flag CVE-2022-0742: (unk) ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report() CVE-2022-0812: (unk) xprtrdma: fix incorrect header size calculations @@ -1460,7 +1466,13 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23041: (unk) xen/9p: use alloc/free_pages_exact() CVE-2022-23222: (unk) bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL CVE-2022-25265: (unk) @@ -1475,3 +1487,4 @@ CVE-2022-29581: (unk) net/sched: cls_u32: fix netns refcount changes in u32_change() CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.0/5.0_CVEs.txt b/data/5.0/5.0_CVEs.txt index 8b6dec7..6a49f64 100644 --- a/data/5.0/5.0_CVEs.txt +++ b/data/5.0/5.0_CVEs.txt
@@ -642,7 +642,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -677,3 +687,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.0/5.0_security.txt b/data/5.0/5.0_security.txt index 93df621..6ecf35f 100644 --- a/data/5.0/5.0_security.txt +++ b/data/5.0/5.0_security.txt
@@ -690,7 +690,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -725,3 +735,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.1/5.1_CVEs.txt b/data/5.1/5.1_CVEs.txt index b5c636c..4c1c146 100644 --- a/data/5.1/5.1_CVEs.txt +++ b/data/5.1/5.1_CVEs.txt
@@ -609,7 +609,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -644,3 +654,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.1/5.1_security.txt b/data/5.1/5.1_security.txt index 6df38fa..f225f5d 100644 --- a/data/5.1/5.1_security.txt +++ b/data/5.1/5.1_security.txt
@@ -645,7 +645,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -680,3 +690,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.10/5.10_CVEs.txt b/data/5.10/5.10_CVEs.txt index ae59eaf..f993133 100644 --- a/data/5.10/5.10_CVEs.txt +++ b/data/5.10/5.10_CVEs.txt
@@ -305,12 +305,21 @@ CVE-2022-1786: Fix not seen in stream CVE-2022-1789: Fixed with 5.10.119 CVE-2022-1836: Fixed with 5.10.114 -CVE-2022-1852: Fix not seen in stream +CVE-2022-1852: Fixed with 5.10.120 CVE-2022-1882: Fix unknown CVE-2022-1943: Fix not seen in stream -CVE-2022-1966: Fix not seen in stream -CVE-2022-1972: Fix not seen in stream +CVE-2022-1966: Fixed with 5.10.120 +CVE-2022-1972: Fixed with 5.10.120 +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fixed with 5.10.115 +CVE-2022-1975: Fixed with 5.10.115 +CVE-2022-1998: Fixed with 5.10.97 CVE-2022-20008: Fixed with 5.10.102 +CVE-2022-20132: Fixed with 5.10.85 +CVE-2022-20141: Fixed with 5.10.64 +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fixed with 5.10.107 +CVE-2022-20154: Fixed with 5.10.90 CVE-2022-22942: Fixed with 5.10.95 CVE-2022-23036: Fixed with 5.10.105 CVE-2022-23037: Fixed with 5.10.105 @@ -345,3 +354,4 @@ CVE-2022-29582: Fixed with 5.10.111 CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fixed with 5.10.110 +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.10/5.10_security.txt b/data/5.10/5.10_security.txt index 6654901..e6f3c37 100644 --- a/data/5.10/5.10_security.txt +++ b/data/5.10/5.10_security.txt
@@ -220,6 +220,7 @@ CVEs fixed in 5.10.64: CVE-2021-46283: 36983fc2f87ea3b74a33bf460c9ee7329735b7b5 netfilter: nf_tables: initialize set before expression setup + CVE-2022-20141: ddd7e8b7b84836c584a284b98ca9bd7a348a0558 igmp: Add ip_mc_list lock in ip_check_mc_rcu CVEs fixed in 5.10.65: CVE-2021-20322: 8692f0bb29927d13a871b198adff1d336a8d2d00 ipv6: make exception cache less predictible @@ -285,6 +286,7 @@ CVEs fixed in 5.10.85: CVE-2021-39685: 7193ad3e50e596ac2192531c58ba83b9e6d2444b USB: gadget: detect too-big endpoint 0 requests CVE-2021-39698: 8e04c8397bf98235b1aa41153717de7a05e652a2 wait: add wake_up_pollfree() + CVE-2022-20132: 61144329606cb9518642b7d2e940b21eb3214204 HID: add hid_is_usb() function to make it simpler for USB detection CVEs fixed in 5.10.88: CVE-2021-22600: 7da349f07e457cad135df0920a3f670e423fb5e9 net/packet: rx_owner_map depends on pg_vec @@ -301,6 +303,9 @@ CVE-2021-45469: fffb6581a23add416239dfcf7e7f3980c6b913da f2fs: fix to do sanity check on last xattr entry in __f2fs_setxattr() CVE-2022-1195: 7dd52af1eb5798f590d9d9e1c56ed8f5744ee0ca hamradio: improve the incomplete fix to avoid NPD +CVEs fixed in 5.10.90: + CVE-2022-20154: 769d14abd35e0e153b5149c3e1e989a9d719e3ff sctp: use call_rcu to free endpoint + CVEs fixed in 5.10.91: CVE-2021-4155: 16d8568378f9ee2d1e69216d39961aa72710209f xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate CVE-2021-45095: 4f260ea5537db35d2eeec9bca78a74713078a544 phonet: refcount leak in pep_sock_accep @@ -323,6 +328,7 @@ CVEs fixed in 5.10.97: CVE-2022-0492: 1fc3444cda9a78c65b769e3fa93455e09ff7a0d3 cgroup-v1: Require capabilities to set release_agent CVE-2022-1055: e7be56926397cf9d992be8913f74a76152f8f08d net: sched: fix use-after-free in tc_new_tfilter() + CVE-2022-1998: 7b4741644cf718c422187e74fb07661ef1d68e85 fanotify: Fix stale file descriptor in copy_event_to_user() CVEs fixed in 5.10.100: CVE-2022-0435: 3c7e5943553594f68bbc070683db6bb6f6e9e78e tipc: improve size validations for received domain records @@ -364,6 +370,9 @@ CVE-2022-1011: ab5595b45f732212b3b1974041b43a257153edb7 fuse: fix pipe buffer lifetime for direct_io CVE-2022-1199: e2201ef32f933944ee02e59205adb566bafcdf91 ax25: Fix NULL pointer dereference in ax25_kill_by_device +CVEs fixed in 5.10.107: + CVE-2022-20153: dc1163203ae6e24b86168390fe5b4a3295fcba7f io_uring: return back safer resurrect + CVEs fixed in 5.10.108: CVE-2022-27666: 9248694dac20eda06e22d8503364dc9d03df4e2f esp: Fix possible buffer overflow in ESP transformation @@ -401,6 +410,8 @@ CVEs fixed in 5.10.115: CVE-2022-0494: a439819f4797f0846c7cffa9475f44aef23c541f block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern CVE-2022-1734: 1961c5a688edb53fe3bc25cbda57f47adf12563c nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs + CVE-2022-1974: 8a9e7c64f4a02c4c397e55ba379609168ec7df4a nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: 879b075a9a364a325988d4484b74311edfef82a1 NFC: netlink: fix sleep in atomic bug when firmware download timeout CVEs fixed in 5.10.117: CVE-2022-28893: e68b60ae29de10c7bd7636e227164a8dbe305a82 SUNRPC: Ensure we flush any closed sockets before xs_xprt_free() @@ -413,6 +424,11 @@ CVE-2022-1012: a5c68f457fbf52c5564ca4eea03f84776ef14e41 secure_seq: use the 64 bits of the siphash for port offset calculation CVE-2022-1789: 9b4aa0d80b18b9d19e62dd47d22e274ce92cdc95 KVM: x86/mmu: fix NULL pointer dereference on guest INVPCID +CVEs fixed in 5.10.120: + CVE-2022-1852: 3d8fc6e28f321d753ab727e3c3e740daf36a8fa3 KVM: x86: avoid calling x86 emulator without a decoded instruction + CVE-2022-1966: ea62d169b6e731e0b54abda1d692406f6bc6a696 netfilter: nf_tables: disallow non-stateful expression in sets earlier + CVE-2022-1972: c0aff1faf66b6b7a19103f83e6a5d0fdc64b9048 netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + Outstanding CVEs: CVE-2005-3660: (unk) CVE-2007-3719: (unk) @@ -506,14 +522,14 @@ CVE-2022-1671: (unk) rxrpc: fix some null-ptr-deref bugs in server_key.c CVE-2022-1679: (unk) CVE-2022-1786: (unk) io_uring: remove io_identity - CVE-2022-1852: (unk) KVM: x86: avoid calling x86 emulator without a decoded instruction CVE-2022-1882: (unk) CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse - CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier - CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory CVE-2022-23222: (unk) bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL CVE-2022-25265: (unk) CVE-2022-26878: (unk) CVE-2022-27950: (unk) HID: elo: fix memory leak in elo_probe CVE-2022-28796: (unk) jbd2: fix use-after-free of transaction_t race CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.11/5.11_CVEs.txt b/data/5.11/5.11_CVEs.txt index 25c74ba..8a1a830 100644 --- a/data/5.11/5.11_CVEs.txt +++ b/data/5.11/5.11_CVEs.txt
@@ -297,7 +297,16 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -332,3 +341,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.11/5.11_security.txt b/data/5.11/5.11_security.txt index 4110d06..55cd3ab 100644 --- a/data/5.11/5.11_security.txt +++ b/data/5.11/5.11_security.txt
@@ -337,7 +337,16 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -372,3 +381,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.12/5.12_CVEs.txt b/data/5.12/5.12_CVEs.txt index b124150..d5da201 100644 --- a/data/5.12/5.12_CVEs.txt +++ b/data/5.12/5.12_CVEs.txt
@@ -247,7 +247,16 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -282,3 +291,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.12/5.12_security.txt b/data/5.12/5.12_security.txt index 80f2e1c..96e849d 100644 --- a/data/5.12/5.12_security.txt +++ b/data/5.12/5.12_security.txt
@@ -279,7 +279,16 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -314,3 +323,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.13/5.13_CVEs.txt b/data/5.13/5.13_CVEs.txt index 6012365..400f2b5 100644 --- a/data/5.13/5.13_CVEs.txt +++ b/data/5.13/5.13_CVEs.txt
@@ -210,7 +210,15 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fixed with 5.13.16 +CVE-2022-20148: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -245,3 +253,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.13/5.13_security.txt b/data/5.13/5.13_security.txt index 34fc55a..6ee6530 100644 --- a/data/5.13/5.13_security.txt +++ b/data/5.13/5.13_security.txt
@@ -57,6 +57,9 @@ CVEs fixed in 5.13.15: CVE-2021-40490: c764e8fa4491da66780fcb30a0d43bfd3fccd12c ext4: fix race writing to an inline_data file while its xattrs are changing +CVEs fixed in 5.13.16: + CVE-2022-20141: 961447ff60291b91e27d5c32fa549c1411ad3b70 igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVEs fixed in 5.13.17: CVE-2021-20322: 8fda1d970f9e2bf3ba7d8c3662099f46765781bd ipv6: make exception cache less predictible @@ -240,7 +243,14 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -275,3 +285,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.14/5.14_CVEs.txt b/data/5.14/5.14_CVEs.txt index 2e358ff..a6d4087 100644 --- a/data/5.14/5.14_CVEs.txt +++ b/data/5.14/5.14_CVEs.txt
@@ -182,7 +182,15 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fixed with 5.14.3 +CVE-2022-20148: Fixed with 5.14.19 +CVE-2022-20154: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -218,3 +226,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.14/5.14_security.txt b/data/5.14/5.14_security.txt index 4e29b49..bdbdf44 100644 --- a/data/5.14/5.14_security.txt +++ b/data/5.14/5.14_security.txt
@@ -10,6 +10,9 @@ CVEs fixed in 5.14.2: CVE-2021-40490: f8ea208b3fbbc0546d71b47e8abaf98b0961dec1 ext4: fix race writing to an inline_data file while its xattrs are changing +CVEs fixed in 5.14.3: + CVE-2022-20141: d1a3c6d5925a8d00a32c5ef2d674dd9c0ce89c95 igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVEs fixed in 5.14.4: CVE-2021-20322: 55938482a1461a35087c6f3051f8447662889ea8 ipv6: make exception cache less predictible @@ -65,6 +68,7 @@ CVE-2021-3640: 2c2b295af72e4e30d17556375e100ae65ac0b896 Bluetooth: sco: Fix lock_sock() blockage by memcpy_from_msg() CVE-2021-3752: b87da982da1b4787e23316e3eedc6bba52cfba64 Bluetooth: fix use-after-free error in lock_sock_nested() CVE-2021-45868: b2d7d18457990ad15ee9f9f40da538fa58dae6b5 quota: check block number when reading the block in quota file + CVE-2022-20148: 5b67adb7425e758655e464bda4eb4174ac88b625 f2fs: fix UAF in f2fs_available_free_memory Outstanding CVEs: CVE-2005-3660: (unk) @@ -214,7 +218,13 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -250,3 +260,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.15/5.15_CVEs.txt b/data/5.15/5.15_CVEs.txt index 28e5cdb..b527076 100644 --- a/data/5.15/5.15_CVEs.txt +++ b/data/5.15/5.15_CVEs.txt
@@ -143,12 +143,19 @@ CVE-2022-1734: Fixed with 5.15.39 CVE-2022-1789: Fixed with 5.15.44 CVE-2022-1836: Fixed with 5.15.37 -CVE-2022-1852: Fix not seen in stream +CVE-2022-1852: Fixed with 5.15.45 CVE-2022-1882: Fix unknown CVE-2022-1943: Fixed with 5.15.40 -CVE-2022-1966: Fix not seen in stream -CVE-2022-1972: Fix not seen in stream +CVE-2022-1966: Fixed with 5.15.45 +CVE-2022-1972: Fixed with 5.15.45 +CVE-2022-1973: Fixed with 5.15.46 +CVE-2022-1974: Fixed with 5.15.39 +CVE-2022-1975: Fixed with 5.15.39 +CVE-2022-1998: Fixed with 5.15.20 CVE-2022-20008: Fixed with 5.15.25 +CVE-2022-20132: Fixed with 5.15.8 +CVE-2022-20148: Fixed with 5.15.3 +CVE-2022-20154: Fixed with 5.15.13 CVE-2022-22942: Fixed with 5.15.18 CVE-2022-23036: Fixed with 5.15.28 CVE-2022-23037: Fixed with 5.15.28 @@ -184,3 +191,4 @@ CVE-2022-29582: Fixed with 5.15.34 CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fixed with 5.15.33 +CVE-2022-32296: Fixed with 5.15.41
diff --git a/data/5.15/5.15_security.txt b/data/5.15/5.15_security.txt index b644672..ca61b67 100644 --- a/data/5.15/5.15_security.txt +++ b/data/5.15/5.15_security.txt
@@ -15,6 +15,7 @@ CVE-2021-3640: b990c219c4c9d4993ef65ea9db73d9497e70f697 Bluetooth: sco: Fix lock_sock() blockage by memcpy_from_msg() CVE-2021-3752: 7e22e4db95b04f09adcce18c75d27cbca8f53b99 Bluetooth: fix use-after-free error in lock_sock_nested() CVE-2021-45868: 332db0909293f3f4d853ee2ea695272c75082d87 quota: check block number when reading the block in quota file + CVE-2022-20148: 5e1b901dd470659bcfeaa76811d2af9165579d77 f2fs: fix UAF in f2fs_available_free_memory CVEs fixed in 5.15.5: CVE-2020-27820: 0b1a35d63995497a9186113c60a16e7ae59642c1 drm/nouveau: use drm_dev_unplug() during device removal @@ -30,6 +31,7 @@ CVEs fixed in 5.15.8: CVE-2021-39685: 36dfdf11af49d3c009c711fb16f5c6e7a274505d USB: gadget: detect too-big endpoint 0 requests CVE-2021-39698: 1ebb6cd8c754bfe1a5f9539027980756bce7cb08 wait: add wake_up_pollfree() + CVE-2022-20132: e1e21632a4c4d2f85587e204939883ce59d18447 HID: add hid_is_usb() function to make it simpler for USB detection CVEs fixed in 5.15.11: CVE-2021-22600: feb116a0ecc5625d6532c616d9a10ef4ef81514b net/packet: rx_owner_map depends on pg_vec @@ -49,6 +51,9 @@ CVE-2021-45469: a8a9d753edd7f71e6a2edaa580d8182530b68791 f2fs: fix to do sanity check on last xattr entry in __f2fs_setxattr() CVE-2022-1195: 03d00f7f1815ec00dab5035851b3de83afd054a8 hamradio: improve the incomplete fix to avoid NPD +CVEs fixed in 5.15.13: + CVE-2022-20154: 75799e71df1da11394740b43ae5686646179561d sctp: use call_rcu to free endpoint + CVEs fixed in 5.15.14: CVE-2021-4155: b0e72ba9e520b95346e68800afff0db65e766ca8 xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate CVE-2021-4197: c6ebc35298848accb5e50c37fdb2490cf4690c92 cgroup: Use open-time credentials for process migraton perm checks @@ -74,6 +79,7 @@ CVEs fixed in 5.15.20: CVE-2022-0492: 4b1c32bfaa02255a5df602b41587174004996477 cgroup-v1: Require capabilities to set release_agent CVE-2022-1055: f36cacd6c933183c1a8827d5987cf2cfc0a44c76 net: sched: fix use-after-free in tc_new_tfilter() + CVE-2022-1998: 60765e43e40fbf7a1df828116172440510fcc3e4 fanotify: Fix stale file descriptor in copy_event_to_user() CVEs fixed in 5.15.23: CVE-2022-0435: 1f1788616157b0222b0c2153828b475d95e374a7 tipc: improve size validations for received domain records @@ -158,6 +164,8 @@ CVEs fixed in 5.15.39: CVE-2022-1734: b8f2b836e7d0a553b886654e8b3925a85862d2eb nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs + CVE-2022-1974: a2168fb3128a576d0175443403c15dcf8bf128f6 nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: 7bd81a05d48942ef2c48630e5e7963b187e95727 NFC: netlink: fix sleep in atomic bug when firmware download timeout CVEs fixed in 5.15.40: CVE-2022-1943: 9e951f2d85c9430ea8ae0c8448e47e3c234f1580 udf: Avoid using stale lengthOfImpUse @@ -165,6 +173,7 @@ CVEs fixed in 5.15.41: CVE-2022-1012: 1a8ee547da2b64d6a2aedbd38a691578eff14718 secure_seq: use the 64 bits of the siphash for port offset calculation CVE-2022-28893: 54f6834b283d9b4d070b0639d9ef5e1d156fe7b0 SUNRPC: Ensure we flush any closed sockets before xs_xprt_free() + CVE-2022-32296: 952a238d779eea4ecb2f8deb5004c8f56be79bc9 tcp: increase source port perturb table to 2^16 CVEs fixed in 5.15.42: CVE-2022-1729: e085354dde254bc6c83ee604ea66c2b36f9f9067 perf: Fix sys_perf_event_open() race against self @@ -172,6 +181,14 @@ CVEs fixed in 5.15.44: CVE-2022-1789: acd12d16528152b32fa09be2c5ef95047f69af05 KVM: x86/mmu: fix NULL pointer dereference on guest INVPCID +CVEs fixed in 5.15.45: + CVE-2022-1852: 531d1070d864c78283b7597449e60ddc53319d88 KVM: x86: avoid calling x86 emulator without a decoded instruction + CVE-2022-1966: f692bcffd1f2ce5488d24fbcb8eab5f351abf79d netfilter: nf_tables: disallow non-stateful expression in sets earlier + CVE-2022-1972: 89ef50fe03a55feccf5681c237673a2f98161161 netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + +CVEs fixed in 5.15.46: + CVE-2022-1973: 61decb58486d7c0cbded25fe4d301ab4fa148cd8 fs/ntfs3: Fix invalid free in log_replay + Outstanding CVEs: CVE-2005-3660: (unk) CVE-2007-3719: (unk) @@ -243,10 +260,7 @@ CVE-2022-1462: (unk) CVE-2022-1652: (unk) CVE-2022-1679: (unk) - CVE-2022-1852: (unk) KVM: x86: avoid calling x86 emulator without a decoded instruction CVE-2022-1882: (unk) - CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier - CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() CVE-2022-24122: (unk) ucount: Make get_ucount a safe get_user replacement CVE-2022-25265: (unk) CVE-2022-26878: (unk)
diff --git a/data/5.16/5.16_CVEs.txt b/data/5.16/5.16_CVEs.txt index 1a6103d..670cf12 100644 --- a/data/5.16/5.16_CVEs.txt +++ b/data/5.16/5.16_CVEs.txt
@@ -117,6 +117,10 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fixed with 5.16.6 CVE-2022-20008: Fixed with 5.16.11 CVE-2022-22942: Fixed with 5.16.4 CVE-2022-23036: Fixed with 5.16.14 @@ -153,3 +157,4 @@ CVE-2022-29582: Fixed with 5.16.20 CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fixed with 5.16.19 +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.16/5.16_security.txt b/data/5.16/5.16_security.txt index a44fa6e..ffe477f 100644 --- a/data/5.16/5.16_security.txt +++ b/data/5.16/5.16_security.txt
@@ -25,6 +25,7 @@ CVEs fixed in 5.16.6: CVE-2022-0492: 9c9dbb954e618e3d9110f13cc02c5db1fb73ea5d cgroup-v1: Require capabilities to set release_agent CVE-2022-1055: 95e34f61b58a152656cbe8d6e19843cc343fb089 net: sched: fix use-after-free in tc_new_tfilter() + CVE-2022-1998: dea4fec0d87d4401b5d2717aa7c6c6cad050fb62 fanotify: Fix stale file descriptor in copy_event_to_user() CVEs fixed in 5.16.9: CVE-2022-0435: 59ff7514f8c56f166aadca49bcecfa028e0ad50f tipc: improve size validations for received domain records @@ -181,9 +182,13 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout CVE-2022-24122: (unk) ucount: Make get_ucount a safe get_user replacement CVE-2022-25265: (unk) CVE-2022-26878: (unk) CVE-2022-28796: (unk) jbd2: fix use-after-free of transaction_t race CVE-2022-29581: (unk) net/sched: cls_u32: fix netns refcount changes in u32_change() CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.17/5.17_CVEs.txt b/data/5.17/5.17_CVEs.txt index 61aa3c4..09b7e34 100644 --- a/data/5.17/5.17_CVEs.txt +++ b/data/5.17/5.17_CVEs.txt
@@ -82,11 +82,14 @@ CVE-2022-1734: Fixed with 5.17.7 CVE-2022-1789: Fixed with 5.17.12 CVE-2022-1836: Fixed with 5.17.6 -CVE-2022-1852: Fix not seen in stream +CVE-2022-1852: Fixed with 5.17.13 CVE-2022-1882: Fix unknown CVE-2022-1943: Fixed with 5.17.8 -CVE-2022-1966: Fix not seen in stream -CVE-2022-1972: Fix not seen in stream +CVE-2022-1966: Fixed with 5.17.13 +CVE-2022-1972: Fixed with 5.17.13 +CVE-2022-1973: Fixed with 5.17.14 +CVE-2022-1974: Fixed with 5.17.7 +CVE-2022-1975: Fixed with 5.17.7 CVE-2022-25265: Fix unknown CVE-2022-26878: Fix unknown CVE-2022-28356: Fixed with 5.17.1 @@ -99,3 +102,4 @@ CVE-2022-29582: Fixed with 5.17.3 CVE-2022-29968: Fixed with 5.17.6 CVE-2022-30594: Fixed with 5.17.2 +CVE-2022-32296: Fixed with 5.17.9
diff --git a/data/5.17/5.17_security.txt b/data/5.17/5.17_security.txt index b6c570c..44ed68a 100644 --- a/data/5.17/5.17_security.txt +++ b/data/5.17/5.17_security.txt
@@ -36,12 +36,15 @@ CVEs fixed in 5.17.7: CVE-2022-1734: f4bfbac45121c8638db5eacb1ebbb61ee956c668 nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs + CVE-2022-1974: 8b58d6e565d83443c51b3fc076bd4472674aca0c nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: 63a545103b77091f2309b44a8975cdf255bb99b2 NFC: netlink: fix sleep in atomic bug when firmware download timeout CVEs fixed in 5.17.8: CVE-2022-1943: cfd64b858cb2b56969138df7970cb0b7f2388fb0 udf: Avoid using stale lengthOfImpUse CVEs fixed in 5.17.9: CVE-2022-1012: 6976724355f5fdada89de528730f9a7b4928f2e3 secure_seq: use the 64 bits of the siphash for port offset calculation + CVE-2022-32296: e3ee7bb47d6509c3e8a3e96e5d8e3bf21549b6e8 tcp: increase source port perturb table to 2^16 CVEs fixed in 5.17.10: CVE-2022-1729: 22fb2974224c9836eeaf0d24fdd481fcdaa0aea8 perf: Fix sys_perf_event_open() race against self @@ -49,6 +52,14 @@ CVEs fixed in 5.17.12: CVE-2022-1789: 19a66796d1f0dd4ce4b05f76d53ce1d0a7dc817d KVM: x86/mmu: fix NULL pointer dereference on guest INVPCID +CVEs fixed in 5.17.13: + CVE-2022-1852: dca5ea67a3e627a3022fe58722a2807c1ef61c29 KVM: x86: avoid calling x86 emulator without a decoded instruction + CVE-2022-1966: d8db0465bcc4d4b54ecfb67b820ed26eb1440da7 netfilter: nf_tables: disallow non-stateful expression in sets earlier + CVE-2022-1972: c88f3e3d243d701586239c5b69356ec2b1fd05f1 netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + +CVEs fixed in 5.17.14: + CVE-2022-1973: 2088cc00491e8d25a99d0f247df843e9c3df2040 fs/ntfs3: Fix invalid free in log_replay + Outstanding CVEs: CVE-2005-3660: (unk) CVE-2007-3719: (unk) @@ -117,9 +128,6 @@ CVE-2022-1462: (unk) CVE-2022-1652: (unk) CVE-2022-1679: (unk) - CVE-2022-1852: (unk) KVM: x86: avoid calling x86 emulator without a decoded instruction CVE-2022-1882: (unk) - CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier - CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() CVE-2022-25265: (unk) CVE-2022-26878: (unk)
diff --git a/data/5.2/5.2_CVEs.txt b/data/5.2/5.2_CVEs.txt index 28dcf84..b50d626 100644 --- a/data/5.2/5.2_CVEs.txt +++ b/data/5.2/5.2_CVEs.txt
@@ -569,7 +569,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -604,3 +614,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.2/5.2_security.txt b/data/5.2/5.2_security.txt index 3859e3a..21b654e 100644 --- a/data/5.2/5.2_security.txt +++ b/data/5.2/5.2_security.txt
@@ -607,7 +607,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -642,3 +652,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.3/5.3_CVEs.txt b/data/5.3/5.3_CVEs.txt index 5291f80..d6459a4 100644 --- a/data/5.3/5.3_CVEs.txt +++ b/data/5.3/5.3_CVEs.txt
@@ -541,7 +541,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -576,3 +586,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.3/5.3_security.txt b/data/5.3/5.3_security.txt index 0625772..fdb9629 100644 --- a/data/5.3/5.3_security.txt +++ b/data/5.3/5.3_security.txt
@@ -577,7 +577,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -612,3 +622,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.4/5.4_CVEs.txt b/data/5.4/5.4_CVEs.txt index 17e21ce..28c6f07 100644 --- a/data/5.4/5.4_CVEs.txt +++ b/data/5.4/5.4_CVEs.txt
@@ -430,7 +430,7 @@ CVE-2022-0995: Fix not seen in stream CVE-2022-0998: Fix not seen in stream CVE-2022-1011: Fixed with 5.4.185 -CVE-2022-1012: Fix not seen in stream +CVE-2022-1012: Fixed with 5.4.197 CVE-2022-1015: Fix not seen in stream CVE-2022-1016: Fixed with 5.4.188 CVE-2022-1043: Fix not seen in stream @@ -466,7 +466,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fixed with 5.4.193 +CVE-2022-1975: Fixed with 5.4.193 +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fixed with 5.4.181 +CVE-2022-20132: Fixed with 5.4.165 +CVE-2022-20141: Fixed with 5.4.145 +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fixed with 5.4.170 +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fixed with 5.4.175 CVE-2022-23036: Fixed with 5.4.184 CVE-2022-23037: Fixed with 5.4.184 @@ -501,3 +511,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fixed with 5.4.189 +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.4/5.4_security.txt b/data/5.4/5.4_security.txt index 099d0e5..ace05ea 100644 --- a/data/5.4/5.4_security.txt +++ b/data/5.4/5.4_security.txt
@@ -498,6 +498,7 @@ CVEs fixed in 5.4.145: CVE-2021-40490: 9b3849ba667af99ee99a7853a021a7786851b9fd ext4: fix race writing to an inline_data file while its xattrs are changing + CVE-2022-20141: d84708451d9041dff8a81e3718f821f12d2eb6c5 igmp: Add ip_mc_list lock in ip_check_mc_rcu CVEs fixed in 5.4.146: CVE-2021-20322: f73cbdd1b8e7ea32c66138426f826c8734b70c18 ipv6: make exception cache less predictible @@ -556,6 +557,7 @@ CVEs fixed in 5.4.165: CVE-2021-39685: fd6de5a0cd42fc43810bd74ad129d98ab962ec6b USB: gadget: detect too-big endpoint 0 requests CVE-2021-39698: e0c03d15cd03476dd698c1ae7fb32a16d3e87f5c wait: add wake_up_pollfree() + CVE-2022-20132: 6e1e0a01425810494ce00d7b800b69482790b198 HID: add hid_is_usb() function to make it simpler for USB detection CVEs fixed in 5.4.168: CVE-2021-28711: 4ed9f5c511ce95cb8db05ff82026ea901f45fd76 xen/blkfront: harden blkfront against event channel storms @@ -571,6 +573,7 @@ CVEs fixed in 5.4.170: CVE-2021-44733: 940e68e57ab69248fabba5889e615305789db8a7 tee: handle lookup of shm with reference count 0 + CVE-2022-20154: 831de271452b87657fcf8d715ee20519b79caef5 sctp: use call_rcu to free endpoint CVEs fixed in 5.4.171: CVE-2021-4155: 102af6edfd3a372db6e229177762a91f552e5f5e xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate @@ -662,12 +665,17 @@ CVE-2022-0494: c7337efd1d11acb6f84c68ffee57d3f312e87b24 block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern CVE-2022-1048: fbeb492694ce0441053de57699e1e2b7bc148a69 ALSA: pcm: Fix races among concurrent hw_params and hw_free calls CVE-2022-1734: 33d3e76fc7a7037f402246c824d750542e2eb37f nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs + CVE-2022-1974: 85aecdef77f9c5b5c0d8988db6681960f0d46ab3 nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: 01d4363dd7176fd780066cd020f66c0f55c4b6f9 NFC: netlink: fix sleep in atomic bug when firmware download timeout CVEs fixed in 5.4.196: CVE-2022-0854: b2f140a9f980806f572d672e1780acea66b9a25c swiotlb: rework "fix info leak with DMA_FROM_DEVICE" CVE-2022-1729: dd0ea88b0a0f913f82500e988ef38158a9ad9885 perf: Fix sys_perf_event_open() race against self CVE-2022-28893: 2f8f6c393b11b5da059b1fc10a69fc2f2b6c446a SUNRPC: Ensure we flush any closed sockets before xs_xprt_free() +CVEs fixed in 5.4.197: + CVE-2022-1012: ab5b00cfe0500f5f5a3648ca945b892156b839fb secure_seq: use the 64 bits of the siphash for port offset calculation + Outstanding CVEs: CVE-2005-3660: (unk) CVE-2007-3719: (unk) @@ -764,7 +772,6 @@ CVE-2022-0742: (unk) ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report() CVE-2022-0995: (unk) watch_queue: Fix filter limit check CVE-2022-0998: (unk) vdpa: clean up get_config_size ret value handling - CVE-2022-1012: (unk) secure_seq: use the 64 bits of the siphash for port offset calculation CVE-2022-1015: (unk) netfilter: nf_tables: validate registers coming from userspace. CVE-2022-1043: (unk) io_uring: fix xa_alloc_cycle() error return value check CVE-2022-1116: (unk) @@ -785,6 +792,11 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-23222: (unk) bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL CVE-2022-25265: (unk) CVE-2022-26878: (unk) @@ -793,3 +805,4 @@ CVE-2022-29156: (unk) RDMA/rtrs-clt: Fix possible double free in error case CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.5/5.5_CVEs.txt b/data/5.5/5.5_CVEs.txt index 4a824c3..14bc567 100644 --- a/data/5.5/5.5_CVEs.txt +++ b/data/5.5/5.5_CVEs.txt
@@ -424,7 +424,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -459,3 +469,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.5/5.5_security.txt b/data/5.5/5.5_security.txt index 230f464..2092a89 100644 --- a/data/5.5/5.5_security.txt +++ b/data/5.5/5.5_security.txt
@@ -456,7 +456,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -491,3 +501,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.6/5.6_CVEs.txt b/data/5.6/5.6_CVEs.txt index ce717fd..41ee800 100644 --- a/data/5.6/5.6_CVEs.txt +++ b/data/5.6/5.6_CVEs.txt
@@ -398,7 +398,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -433,3 +443,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.6/5.6_security.txt b/data/5.6/5.6_security.txt index ab742b3..d32f1be 100644 --- a/data/5.6/5.6_security.txt +++ b/data/5.6/5.6_security.txt
@@ -430,7 +430,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -465,3 +475,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.7/5.7_CVEs.txt b/data/5.7/5.7_CVEs.txt index 7b5eee0..bd6e852 100644 --- a/data/5.7/5.7_CVEs.txt +++ b/data/5.7/5.7_CVEs.txt
@@ -384,7 +384,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -419,3 +429,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.7/5.7_security.txt b/data/5.7/5.7_security.txt index 3227bd4..c14eb5a 100644 --- a/data/5.7/5.7_security.txt +++ b/data/5.7/5.7_security.txt
@@ -418,7 +418,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -453,3 +463,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.8/5.8_CVEs.txt b/data/5.8/5.8_CVEs.txt index 309e7fa..e3af9da 100644 --- a/data/5.8/5.8_CVEs.txt +++ b/data/5.8/5.8_CVEs.txt
@@ -363,7 +363,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -398,3 +408,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.8/5.8_security.txt b/data/5.8/5.8_security.txt index ec31efb..7454880 100644 --- a/data/5.8/5.8_security.txt +++ b/data/5.8/5.8_security.txt
@@ -397,7 +397,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -432,3 +442,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/5.9/5.9_CVEs.txt b/data/5.9/5.9_CVEs.txt index 6092dda..29284a1 100644 --- a/data/5.9/5.9_CVEs.txt +++ b/data/5.9/5.9_CVEs.txt
@@ -334,7 +334,17 @@ CVE-2022-1943: Fix not seen in stream CVE-2022-1966: Fix not seen in stream CVE-2022-1972: Fix not seen in stream +CVE-2022-1973: Fix not seen in stream +CVE-2022-1974: Fix not seen in stream +CVE-2022-1975: Fix not seen in stream +CVE-2022-1998: Fix not seen in stream CVE-2022-20008: Fix not seen in stream +CVE-2022-20132: Fix not seen in stream +CVE-2022-20141: Fix not seen in stream +CVE-2022-20148: Fix not seen in stream +CVE-2022-20153: Fix not seen in stream +CVE-2022-20154: Fix not seen in stream +CVE-2022-20166: Fix not seen in stream CVE-2022-22942: Fix not seen in stream CVE-2022-23036: Fix not seen in stream CVE-2022-23037: Fix not seen in stream @@ -369,3 +379,4 @@ CVE-2022-29582: Fix not seen in stream CVE-2022-29968: Fix not seen in stream CVE-2022-30594: Fix not seen in stream +CVE-2022-32296: Fix not seen in stream
diff --git a/data/5.9/5.9_security.txt b/data/5.9/5.9_security.txt index f5e6ee4..53a222a 100644 --- a/data/5.9/5.9_security.txt +++ b/data/5.9/5.9_security.txt
@@ -364,7 +364,17 @@ CVE-2022-1943: (unk) udf: Avoid using stale lengthOfImpUse CVE-2022-1966: (unk) netfilter: nf_tables: disallow non-stateful expression in sets earlier CVE-2022-1972: (unk) netfilter: nf_tables: sanitize nft_set_desc_concat_parse() + CVE-2022-1973: (unk) fs/ntfs3: Fix invalid free in log_replay + CVE-2022-1974: (unk) nfc: replace improper check device_is_registered() in netlink related functions + CVE-2022-1975: (unk) NFC: netlink: fix sleep in atomic bug when firmware download timeout + CVE-2022-1998: (unk) fanotify: Fix stale file descriptor in copy_event_to_user() CVE-2022-20008: (unk) mmc: block: fix read single on recovery logic + CVE-2022-20132: (unk) HID: add hid_is_usb() function to make it simpler for USB detection + CVE-2022-20141: (unk) igmp: Add ip_mc_list lock in ip_check_mc_rcu + CVE-2022-20148: (unk) f2fs: fix UAF in f2fs_available_free_memory + CVE-2022-20153: (unk) io_uring: return back safer resurrect + CVE-2022-20154: (unk) sctp: use call_rcu to free endpoint + CVE-2022-20166: (unk) drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions CVE-2022-22942: (unk) drm/vmwgfx: Fix stale file descriptors on failed usercopy CVE-2022-23036: (unk) xen/grant-table: add gnttab_try_end_foreign_access() CVE-2022-23037: (unk) xen/netfront: don't use gnttab_query_foreign_access() for mapped status @@ -399,3 +409,4 @@ CVE-2022-29582: (unk) io_uring: fix race between timeout flush and removal CVE-2022-29968: (unk) io_uring: fix uninitialized field in rw io_kiocb CVE-2022-30594: (unk) ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE + CVE-2022-32296: (unk) tcp: increase source port perturb table to 2^16
diff --git a/data/CVEs.txt b/data/CVEs.txt index 3170bac..df1ec1f 100644 --- a/data/CVEs.txt +++ b/data/CVEs.txt
@@ -2014,12 +2014,22 @@ CVE-2022-1786: (n/a) - 4379bf8bd70b5de6bba7d53015b0c36c57a634ee (unk to v5.12-rc1-dontuse) CVE-2022-1789: (n/a) - 9f46c187e2e680ecd9de7983e4d081c3391acc76 (unk to v5.18) CVE-2022-1836: (n/a) - 233087ca063686964a53c829d547c7571e3f67bf (unk to v5.18-rc5) -CVE-2022-1852: (n/a) - fee060cd52d69c114b62d1a2948ea9648b5131f9 (unk to unk) +CVE-2022-1852: (n/a) - fee060cd52d69c114b62d1a2948ea9648b5131f9 (unk to v5.19-rc1) CVE-2022-1882: (n/a) - (n/a) (unk to unk) CVE-2022-1943: (n/a) - c1ad35dd0548ce947d97aaf92f7f2f9a202951cf (unk to v5.18-rc7) -CVE-2022-1966: (n/a) - 520778042ccca019f3ffa136dd0ca565c486cedd (unk to unk) -CVE-2022-1972: (n/a) - fecf31ee395b0295f2d7260aa29946b7605f7c85 (unk to unk) +CVE-2022-1966: (n/a) - 520778042ccca019f3ffa136dd0ca565c486cedd (unk to v5.19-rc1) +CVE-2022-1972: (n/a) - fecf31ee395b0295f2d7260aa29946b7605f7c85 (unk to v5.19-rc1) +CVE-2022-1973: (n/a) - f26967b9f7a830e228bb13fb41bd516ddd9d789d (unk to v5.19-rc1) +CVE-2022-1974: (n/a) - da5c0f119203ad9728920456a0f52a6d850c01cd (unk to v5.18-rc6) +CVE-2022-1975: (n/a) - 4071bf121d59944d5cd2238de0642f3d7995a997 (unk to v5.18-rc6) +CVE-2022-1998: (n/a) - ee12595147ac1fbfb5bcb23837e26dd58d94b15d (unk to v5.17-rc3) CVE-2022-20008: (n/a) - 54309fde1a352ad2674ebba004a79f7d20b9f037 (unk to v5.17-rc5) +CVE-2022-20132: (n/a) - f83baa0cb6cfc92ebaf7f9d3a99d7e34f2e77a8a (unk to v5.16-rc5) +CVE-2022-20141: (n/a) - 23d2b94043ca8835bd1e67749020e839f396a1c2 (unk to v5.15-rc1) +CVE-2022-20148: (n/a) - 5429c9dbc9025f9a166f64e22e3a69c94fd5b29b (unk to v5.16-rc1) +CVE-2022-20153: (n/a) - f70865db5ff35f5ed0c7e9ef63e7cca3d4947f04 (unk to v5.13-rc1) +CVE-2022-20154: (n/a) - 5ec7d18d1813a5bead0b495045606c93873aecbb (unk to v5.16-rc8) +CVE-2022-20166: (n/a) - aa838896d87af561a33ecefea1caa4c15a68bc47 (unk to v5.10-rc1) CVE-2022-22942: c906965dee22d5e95d0651759ba107b420212a9f - a0f90c8815706981c483a652a6aefca51a5e191c (v4.14-rc1 to v5.17-rc2) CVE-2022-23036: (n/a) - 6b1775f26a2da2b05a6dc8ec2b5d14e9a4701a1a (unk to v5.17-rc8) CVE-2022-23037: (n/a) - 31185df7e2b1d2fa1de4900247a12d7b9c7087eb (unk to v5.17-rc8) @@ -2055,3 +2065,4 @@ CVE-2022-29582: (n/a) - e677edbcabee849bfdd43f1602bccbecf736a646 (unk to v5.18-rc2) CVE-2022-29968: (n/a) - 32452a3eb8b64e01e2be717f518c0be046975b9d (unk to v5.18-rc5) CVE-2022-30594: (n/a) - ee1fee900537b5d9560e9f937402de5ddc8412f3 (unk to v5.18-rc1) +CVE-2022-32296: (n/a) - 4c2c8f03a5ab7cb04ec64724d7d176d00bcc91e5 (unk to v5.18-rc6)
diff --git a/data/cmts.json b/data/cmts.json index f56ce3d..b0b7f1a 100644 --- a/data/cmts.json +++ b/data/cmts.json
@@ -401,6 +401,7 @@ "23b133bdc452aa441fcb9b82cbf6dd05cfd342d0": "v4.0-rc1", "23c20ecd44750dd42e5fd53285a17ca8d8a9b0a3": "v3.7-rc1", "23c8a812dc3c621009e4f0e5342aa4e2ede1ceaa": "v4.6", + "23d2b94043ca8835bd1e67749020e839f396a1c2": "v5.15-rc1", "23da9588037ecdd4901db76a5b79a42b529c4ec3": "v5.1-rc3", "23fcb3340d033d9f081e21e6c12c2db7eaa541d3": "v4.18-rc3", "241699cd72a8489c9446ae3910ddd243e9b9061b": "v4.9-rc1", @@ -710,6 +711,7 @@ "401ca24fb34aee0cedf9c4fef361e533224f15a1": "v3.7-rc1", "401e7e88d4ef80188ffa07095ac00456f901b8c4": "v5.1-rc1", "40413955ee265a5e42f710940ec78f5450d49149": "v4.13-rc5", + "4071bf121d59944d5cd2238de0642f3d7995a997": "v5.18-rc6", "408fb0e5aa7fda0059db282ff58c3b2a4278baa0": "v4.4-rc6", "40d8abdee806d496a60ee607a6d01b1cd7fabaf0": "v4.7-rc1", "41061cdb98a0bec464278b4db8e894a3121671f5": "v3.17-rc1", @@ -825,6 +827,7 @@ "4c03b862b12f980456f9de92db6d508a4999b788": "v4.10", "4c185ce06dca14f5cea192f5a2c981ef50663f2b": "v4.1-rc1", "4c27fe4c4c84f3afd504ecff2420cc1ad420d38e": "v4.11-rc1", + "4c2c8f03a5ab7cb04ec64724d7d176d00bcc91e5": "v5.18-rc6", "4c41aa24baa4ed338241d05494f2c595c885af8f": "v4.16-rc7", "4c48abe91be03d191d0c20cc755877da2cb35622": "v4.13-rc1", "4c59406ed00379c8663f8663d82b2537467ce9d7": "v5.6", @@ -895,6 +898,7 @@ "51ebd3181572af8d5076808dab2682d800f6da5d": "v3.8-rc1", "51f3baad7de943780ce0c17bd7975df567dd6e14": "v4.12-rc1", "51f6b410fc220d8a5a4fae00ebfd8243b6c11d4e": "v4.20-rc1", + "520778042ccca019f3ffa136dd0ca565c486cedd": "v5.19-rc1", "5233252fce714053f0151680933571a2da9cbfb4": "v4.4-rc6", "52400ba946759af28442dee6265c5c0180ac7122": "v2.6.31-rc1", "52c479697c9b73f628140dcdfcd39ea302d05482": "v5.9-rc2", @@ -906,6 +910,7 @@ "537a50574175a2b68b0612ffb48cb044a394c7b4": "v4.13-rc1", "53a712bae5dd919521a58d7bad773b949358add0": "v5.2-rc1", "53b381b3abeb86f12787a6c40fee9b2f71edc23b": "v3.9-rc1", + "5429c9dbc9025f9a166f64e22e3a69c94fd5b29b": "v5.16-rc1", "542db01579fbb7ea7d1f7bb9ddcef1559df660b2": "v3.11-rc1", "54309fde1a352ad2674ebba004a79f7d20b9f037": "v5.17-rc5", "54648cf1ec2d7f4b6a71767799c45676a138ca24": "v4.19-rc1", @@ -1010,6 +1015,7 @@ "5ead97c84fa7d63a6a7a2f4e9f18f452bd109045": "v2.6.23-rc1", "5eaf563e53294d6696e651466697eb9d491f3946": "v3.8-rc1", "5ec0811d30378ae104f250bfc9b3640242d81e3f": "v4.6-rc7", + "5ec7d18d1813a5bead0b495045606c93873aecbb": "v5.16-rc8", "5eda3550a3cc1987a495e9f85e5998a76d15a0aa": "v3.9-rc1", "5edabca9d4cff7f1f2b68f0bac55ef99d9798ba4": "v4.10", "5eeb2ca02a2f6084fc57ae5c244a38baab07033a": "v4.16-rc3", @@ -1804,6 +1810,7 @@ "aa5873e96271611ae55586f65e49ea1fab90cb88": "v2.6.36-rc1", "aa6dd211e4b1dde9d5dc25d699d35f789ae7eeba": "v5.13-rc1", "aa6f8dcbab473f3a3c7454b74caa46d36cdc5d13": "v5.17-rc8", + "aa838896d87af561a33ecefea1caa4c15a68bc47": "v5.10-rc1", "aa93d1fee85c890a34f2510a310e55ee76a27848": "v4.7", "aa9c2669626ca7e5e5bab28e6caeb583fd40099b": "v3.11-rc1", "aa9f7d5172fac9bf1f09e678c35e287a40a7b7dd": "v5.7-rc1", @@ -2320,6 +2327,7 @@ "da029c11e6b12f321f36dac8771e833b65cec962": "v4.13-rc1", "da2311a6385c3b499da2ed5d9be59ce331fa93e9": "v5.5-rc3", "da4458bda237aa0cb1688f6c359477f203788f6a": "v2.6.30-rc1", + "da5c0f119203ad9728920456a0f52a6d850c01cd": "v5.18-rc6", "da99466ac243f15fbba65bd261bfc75ffa1532b6": "v5.3-rc1", "daac07156b330b18eb5071aec4b3ddca1c377f2c": "v5.3-rc5", "dab6cf55f81a6e16b8147aed9a843e1691dcd318": "v3.16-rc7", @@ -2501,6 +2509,7 @@ "edfbbf388f293d70bf4b7c0bc38774d05e6f711a": "v3.16-rc3", "ee07c6e7a6f8a25c18f0a6b18152fbd7499245f6": "v3.8-rc1", "ee0d8d8482345ff97a75a7d747efc309f13b0d80": "v4.12-rc1", + "ee12595147ac1fbfb5bcb23837e26dd58d94b15d": "v5.17-rc3", "ee18d64c1f632043a02e6f5ba5e045bb26a5465f": "v2.6.32-rc1", "ee1fee900537b5d9560e9f937402de5ddc8412f3": "v5.18-rc1", "ee40fb2e1eb5bc0ddd3f2f83c6e39a454ef5a741": "v4.15-rc1", @@ -2555,6 +2564,7 @@ "f1e255d60ae66a9f672ff9a207ee6cd8e33d2679": "v4.18-rc5", "f227e3ec3b5cad859ad15666874405e8c1bbc1d4": "v5.8", "f232326f6966cf2a1d1db7bc917a4ce5f9f55f76": "v5.12-rc5", + "f26967b9f7a830e228bb13fb41bd516ddd9d789d": "v5.19-rc1", "f2815633504b442ca0b0605c16bf3d88a3a0fcea": "v3.9-rc4", "f2d67fec0b43edce8c416101cdc52e71145b5fef": "v5.7-rc1", "f2e323ec96077642d397bb1c355def536d489d16": "v3.18-rc1", @@ -2615,12 +2625,14 @@ "f6fb8f100b807378fda19e83e5ac6828b638603a": "v3.2-rc1", "f70267f379b5e5e11bdc5d72a56bf17e5feed01f": "v5.5-rc2", "f7068114d45ec55996b9040e98111afa56e010fe": "v4.17-rc7", + "f70865db5ff35f5ed0c7e9ef63e7cca3d4947f04": "v5.13-rc1", "f70e2e06196ad4c1c762037da2f75354f6c16b81": "v2.6.35-rc1", "f78146b0f9230765c6315b2e14f56112513389ad": "v3.5-rc1", "f79643787e0a0762d2409b7b8334e83f22d85695": "v5.10-rc5", "f7a1337f0d29b98733c8824e165fca3371d7d4fd": "v5.4-rc7", "f7d8a19f9a056a05c5c509fa65af472a322abfee": "v5.15-rc7", "f7ed45be3ba524e06a6d933f0517dc7ad2d06703": "v3.9-rc1", + "f83baa0cb6cfc92ebaf7f9d3a99d7e34f2e77a8a": "v5.16-rc5", "f84598bd7c851f8b0bf8cd0d7c3be0d73c432ff4": "v4.0-rc1", "f84af32cbca70a3c6d30463dc08c7984af11c277": "v2.6.35-rc1", "f856567b930dfcdbc3323261bf77240ccdde01f5": "v3.12", @@ -2683,7 +2695,9 @@ "fe77ba6f4f97690baa4c756611a07f3cc033f6ae": "v2.6.13-rc1", "fe8222406c8277a21172479d3a8283d31c209028": "v2.6.38-rc1", "fe9c842695e26d8116b61b80bfb905356f07834b": "v4.16-rc3", + "fecf31ee395b0295f2d7260aa29946b7605f7c85": "v5.19-rc1", "fed1755b118147721f2c87b37b9d66e62c39b668": "v5.11-rc1", + "fee060cd52d69c114b62d1a2948ea9648b5131f9": "v5.19-rc1", "ff002b30181d30cdfbca316dadd099c3ca0d739c": "v5.6-rc2", "ff2bb89335daec6053b5ac778369f7f72b931142": "v4.7-rc1", "ff4dd73dd2b4806419f8ff65cbce11d5019548d0": "v4.11-rc1",
diff --git a/data/kernel_cves.json b/data/kernel_cves.json index 3e35813..94dd7c3 100644 --- a/data/kernel_cves.json +++ b/data/kernel_cves.json
@@ -69198,7 +69198,7 @@ "cwe": "Exposure of Sensitive Information to an Unauthorized Actor", "fixes": "cc8f7fe1f5eab010191aa4570f27641876fa1267", "last_affected_version": "5.16.12", - "last_modified": "2022-05-18", + "last_modified": "2022-06-09", "nvd_text": "A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO) to create issues with confidentiality.", "ref_urls": { "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-0494", @@ -69661,7 +69661,7 @@ "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation", "fixes": "b2d057560b8107c633b39aabe517ff9d93f285e3", "last_affected_version": "5.17.8", - "last_modified": "2022-06-02", + "last_modified": "2022-06-09", "ref_urls": { "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1012", "ExploitDB": "https://www.exploit-db.com/search?cve=2022-1012", @@ -70242,8 +70242,31 @@ "affected_versions": "unk to v4.20-rc1", "breaks": "", "cmt_msg": "tcp: optimize tcp internal pacing", + "cvss2": { + "Access Complexity": "Low", + "Access Vector": "Network Accessible", + "Authentication": "None", + "Availability Impact": "Partial", + "Confidentiality Impact": "None", + "Integrity Impact": "None", + "raw": "AV:N/AC:L/Au:N/C:N/I:N/A:P", + "score": 5.0 + }, + "cvss3": { + "Attack Complexity": "Low", + "Attack Vector": "Network", + "Availability": "High", + "Confidentiality": "None", + "Integrity": "None", + "Privileges Required": "None", + "Scope": "Unchanged", + "User Interaction": "None", + "raw": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "score": 7.5 + }, + "cwe": "Unspecified", "fixes": "864e5c090749448e879e86bec06ee396aa2c19c5", - "last_modified": "2022-05-26", + "last_modified": "2022-06-09", "nvd_text": "An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.", "ref_urls": { "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1678", @@ -70398,11 +70421,12 @@ } }, "CVE-2022-1852": { - "affected_versions": "unk to unk", + "affected_versions": "unk to v5.19-rc1", "breaks": "", "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction", "fixes": "fee060cd52d69c114b62d1a2948ea9648b5131f9", - "last_modified": "2022-06-02", + "last_affected_version": "5.17.12", + "last_modified": "2022-06-09", "ref_urls": { "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1852", "ExploitDB": "https://www.exploit-db.com/search?cve=2022-1852", @@ -70415,9 +70439,32 @@ "CVE-2022-1882": { "affected_versions": "unk to unk", "breaks": "", + "cvss2": { + "Access Complexity": "Low", + "Access Vector": "Local Access", + "Authentication": "None", + "Availability Impact": "Complete", + "Confidentiality Impact": "Complete", + "Integrity Impact": "Complete", + "raw": "AV:L/AC:L/Au:N/C:C/I:C/A:C", + "score": 7.2 + }, + "cvss3": { + "Attack Complexity": "Low", + "Attack Vector": "Local", + "Availability": "High", + "Confidentiality": "High", + "Integrity": "High", + "Privileges Required": "Low", + "Scope": "Unchanged", + "User Interaction": "None", + "raw": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "score": 7.8 + }, + "cwe": "Use After Free", "fixes": "", - "last_modified": "2022-05-31", - "nvd_text": "A flaw use after free in the Linux kernel pipes functionality was found in the way user do some manipulations with pipe ex. with the post_one_notification() after free_pipe_info() already called. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.", + "last_modified": "2022-06-09", + "nvd_text": "A use-after-free flaw was found in the Linux kernel\u2019s pipes functionality in how a user performs manipulations with the pipe post_one_notification() after free_pipe_info() that is already called. This flaw allows a local user to crash or potentially escalate their privileges on the system.", "ref_urls": { "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1882", "ExploitDB": "https://www.exploit-db.com/search?cve=2022-1882", @@ -70445,11 +70492,13 @@ } }, "CVE-2022-1966": { - "affected_versions": "unk to unk", + "affected_versions": "unk to v5.19-rc1", "breaks": "", "cmt_msg": "netfilter: nf_tables: disallow non-stateful expression in sets earlier", "fixes": "520778042ccca019f3ffa136dd0ca565c486cedd", - "last_modified": "2022-06-05", + "last_affected_version": "5.17.12", + "last_modified": "2022-06-09", + "nvd_text": "A use-after-free vulnerability was found in the Linux kernel's Netfilter subsystem in net/netfilter/nf_tables_api.c. This flaw allows a local attacker with user access to cause a privilege escalation issue.", "ref_urls": { "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1966", "ExploitDB": "https://www.exploit-db.com/search?cve=2022-1966", @@ -70460,11 +70509,12 @@ } }, "CVE-2022-1972": { - "affected_versions": "unk to unk", + "affected_versions": "unk to v5.19-rc1", "breaks": "", "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()", "fixes": "fecf31ee395b0295f2d7260aa29946b7605f7c85", - "last_modified": "2022-06-05", + "last_affected_version": "5.17.12", + "last_modified": "2022-06-09", "ref_urls": { "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1972", "ExploitDB": "https://www.exploit-db.com/search?cve=2022-1972", @@ -70474,6 +70524,70 @@ "Ubuntu": "https://ubuntu.com/security/CVE-2022-1972" } }, + "CVE-2022-1973": { + "affected_versions": "unk to v5.19-rc1", + "breaks": "", + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay", + "fixes": "f26967b9f7a830e228bb13fb41bd516ddd9d789d", + "last_affected_version": "5.17.13", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1973", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-1973", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-1973", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-1973", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-1973", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-1973" + } + }, + "CVE-2022-1974": { + "affected_versions": "unk to v5.18-rc6", + "breaks": "", + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions", + "fixes": "da5c0f119203ad9728920456a0f52a6d850c01cd", + "last_affected_version": "5.17.6", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1974", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-1974", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-1974", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-1974", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-1974", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-1974" + } + }, + "CVE-2022-1975": { + "affected_versions": "unk to v5.18-rc6", + "breaks": "", + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout", + "fixes": "4071bf121d59944d5cd2238de0642f3d7995a997", + "last_affected_version": "5.17.6", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1975", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-1975", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-1975", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-1975", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-1975", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-1975" + } + }, + "CVE-2022-1998": { + "affected_versions": "unk to v5.17-rc3", + "breaks": "", + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()", + "fixes": "ee12595147ac1fbfb5bcb23837e26dd58d94b15d", + "last_affected_version": "5.16.5", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-1998", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-1998", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-1998", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-1998", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-1998", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-1998" + } + }, "CVE-2022-20008": { "affected_versions": "unk to v5.17-rc5", "breaks": "", @@ -70514,6 +70628,101 @@ "Ubuntu": "https://ubuntu.com/security/CVE-2022-20008" } }, + "CVE-2022-20132": { + "affected_versions": "unk to v5.16-rc5", + "breaks": "", + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection", + "fixes": "f83baa0cb6cfc92ebaf7f9d3a99d7e34f2e77a8a", + "last_affected_version": "5.15.7", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-20132", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-20132", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-20132", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-20132", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-20132", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-20132" + } + }, + "CVE-2022-20141": { + "affected_versions": "unk to v5.15-rc1", + "breaks": "", + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu", + "fixes": "23d2b94043ca8835bd1e67749020e839f396a1c2", + "last_affected_version": "5.14.2", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-20141", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-20141", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-20141", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-20141", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-20141", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-20141" + } + }, + "CVE-2022-20148": { + "affected_versions": "unk to v5.16-rc1", + "breaks": "", + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory", + "fixes": "5429c9dbc9025f9a166f64e22e3a69c94fd5b29b", + "last_affected_version": "5.15.2", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-20148", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-20148", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-20148", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-20148", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-20148", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-20148" + } + }, + "CVE-2022-20153": { + "affected_versions": "unk to v5.13-rc1", + "breaks": "", + "cmt_msg": "io_uring: return back safer resurrect", + "fixes": "f70865db5ff35f5ed0c7e9ef63e7cca3d4947f04", + "last_affected_version": "5.10.106", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-20153", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-20153", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-20153", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-20153", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-20153", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-20153" + } + }, + "CVE-2022-20154": { + "affected_versions": "unk to v5.16-rc8", + "breaks": "", + "cmt_msg": "sctp: use call_rcu to free endpoint", + "fixes": "5ec7d18d1813a5bead0b495045606c93873aecbb", + "last_affected_version": "5.15.12", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-20154", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-20154", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-20154", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-20154", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-20154", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-20154" + } + }, + "CVE-2022-20166": { + "affected_versions": "unk to v5.10-rc1", + "breaks": "", + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions", + "fixes": "aa838896d87af561a33ecefea1caa4c15a68bc47", + "last_modified": "2022-06-09", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-20166", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-20166", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-20166", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-20166", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-20166", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-20166" + } + }, "CVE-2022-22942": { "affected_versions": "v4.14-rc1 to v5.17-rc2", "breaks": "c906965dee22d5e95d0651759ba107b420212a9f", @@ -71884,5 +72093,22 @@ "SUSE": "https://www.suse.com/security/cve/CVE-2022-30594", "Ubuntu": "https://ubuntu.com/security/CVE-2022-30594" } + }, + "CVE-2022-32296": { + "affected_versions": "unk to v5.18-rc6", + "breaks": "", + "cmt_msg": "tcp: increase source port perturb table to 2^16", + "fixes": "4c2c8f03a5ab7cb04ec64724d7d176d00bcc91e5", + "last_affected_version": "5.17.8", + "last_modified": "2022-06-09", + "nvd_text": "The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used.", + "ref_urls": { + "Debian": "https://security-tracker.debian.org/tracker/CVE-2022-32296", + "ExploitDB": "https://www.exploit-db.com/search?cve=2022-32296", + "NVD": "https://nvd.nist.gov/vuln/detail/CVE-2022-32296", + "Red Hat": "https://access.redhat.com/security/cve/CVE-2022-32296", + "SUSE": "https://www.suse.com/security/cve/CVE-2022-32296", + "Ubuntu": "https://ubuntu.com/security/CVE-2022-32296" + } } } \ No newline at end of file
diff --git a/data/stream_data.json b/data/stream_data.json index f1cac41..8e7c379 100644 --- a/data/stream_data.json +++ b/data/stream_data.json
@@ -2180,12 +2180,18 @@ "CVE-2015-8952": { "cmt_msg": "ext2: convert to mbcache2" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2016-8645": { "cmt_msg": "tcp: take care of truncations done by sk_filter()" }, @@ -2258,6 +2264,9 @@ "CVE-2016-3857": { "cmt_msg": "arm: oabi compat: add missing access checks" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -2333,6 +2342,9 @@ "CVE-2018-20510": { "cmt_msg": "binder: replace \"%p\" with \"%pK\"" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2016-5728": { "cmt_msg": "misc: mic: Fix for double fetch security bug in VOP driver" }, @@ -2426,6 +2438,9 @@ "CVE-2020-0444": { "cmt_msg": "audit: fix error handling in audit_data_to_entry()" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2020-8832": { "cmt_msg": "drm/i915: Record the default hw state after reset upon load" }, @@ -2621,8 +2636,8 @@ "CVE-2022-23042": { "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -2720,6 +2735,9 @@ "CVE-2021-34981": { "cmt_msg": "Bluetooth: cmtp: fix file refcount when cmtp_attach_device fails" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -2747,6 +2765,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2016-8630": { "cmt_msg": "kvm: x86: Check memopp before dereference (CVE-2016-8630)" }, @@ -3440,6 +3461,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2015-3332": { "cmt_msg": "tcp: Fix crash in TCP Fast Open" }, @@ -3521,6 +3545,9 @@ "CVE-2019-16746": { "cmt_msg": "nl80211: validate beacon head" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -3668,9 +3695,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2017-0786": { "cmt_msg": "brcmfmac: add length check in brcmf_cfg80211_escan_handler()" }, @@ -4253,6 +4286,9 @@ "CVE-2021-0920": { "cmt_msg": "af_unix: fix garbage collect vs MSG_PEEK" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2019-13631": { "cmt_msg": "Input: gtco - bounds check collection indent level" }, @@ -4454,12 +4490,18 @@ "CVE-2019-18680": { "cmt_msg": "" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-0995": { "cmt_msg": "watch_queue: Fix filter limit check" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2017-14991": { "cmt_msg": "scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE" }, @@ -4562,6 +4604,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-11600": { "cmt_msg": "xfrm: policy: check policy direction value" }, @@ -4631,6 +4676,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2019-2024": { "cmt_msg": "media: em28xx: Fix use-after-free when disconnecting" }, @@ -4685,6 +4733,9 @@ "CVE-2018-20510": { "cmt_msg": "binder: replace \"%p\" with \"%pK\"" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2020-15437": { "cmt_msg": "serial: 8250: fix null-ptr-deref in serial8250_start_tx()" }, @@ -5174,6 +5225,9 @@ "CVE-2017-14489": { "cmt_msg": "scsi: scsi_transport_iscsi: fix the issue that iscsi_if_rx doesn't parse nlmsg properly" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" }, @@ -5219,6 +5273,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -6305,6 +6362,9 @@ "CVE-2019-15215": { "cmt_msg": "media: cpia2_usb: first wake up, then free in disconnect" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -6518,9 +6578,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2022-1678": { "cmt_msg": "tcp: optimize tcp internal pacing" }, @@ -7467,12 +7533,18 @@ "CVE-2019-18680": { "cmt_msg": "" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-0995": { "cmt_msg": "watch_queue: Fix filter limit check" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-27363": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -7575,6 +7647,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-0861": { "cmt_msg": "ALSA: pcm: prevent UAF in snd_pcm_info" }, @@ -7623,6 +7698,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2019-2024": { "cmt_msg": "media: em28xx: Fix use-after-free when disconnecting" }, @@ -7662,6 +7740,9 @@ "CVE-2018-20510": { "cmt_msg": "binder: replace \"%p\" with \"%pK\"" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2019-14763": { "cmt_msg": "usb: dwc3: gadget: never call ->complete() from ->ep_queue()" }, @@ -7770,6 +7851,9 @@ "CVE-2020-0444": { "cmt_msg": "audit: fix error handling in audit_data_to_entry()" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2020-8832": { "cmt_msg": "drm/i915: Record the default hw state after reset upon load" }, @@ -8115,6 +8199,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -8148,6 +8235,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -9114,6 +9204,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -9306,9 +9399,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -10102,12 +10201,18 @@ "CVE-2019-18680": { "cmt_msg": "" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-0995": { "cmt_msg": "watch_queue: Fix filter limit check" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2017-14991": { "cmt_msg": "scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE" }, @@ -10207,6 +10312,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-0861": { "cmt_msg": "ALSA: pcm: prevent UAF in snd_pcm_info" }, @@ -10261,6 +10369,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2019-2024": { "cmt_msg": "media: em28xx: Fix use-after-free when disconnecting" }, @@ -10309,6 +10420,9 @@ "CVE-2018-20510": { "cmt_msg": "binder: replace \"%p\" with \"%pK\"" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2019-14763": { "cmt_msg": "usb: dwc3: gadget: never call ->complete() from ->ep_queue()" }, @@ -10423,6 +10537,9 @@ "CVE-2020-0444": { "cmt_msg": "audit: fix error handling in audit_data_to_entry()" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2017-16526": { "cmt_msg": "uwb: properly check kthread_run return value" }, @@ -10789,6 +10906,9 @@ "CVE-2017-14489": { "cmt_msg": "scsi: scsi_transport_iscsi: fix the issue that iscsi_if_rx doesn't parse nlmsg properly" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" }, @@ -10822,6 +10942,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -11845,6 +11968,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -12049,9 +12175,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2022-1678": { "cmt_msg": "tcp: optimize tcp internal pacing" }, @@ -12855,12 +12987,18 @@ "CVE-2019-18680": { "cmt_msg": "" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-27363": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -12960,6 +13098,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -13038,6 +13179,9 @@ "CVE-2018-20511": { "cmt_msg": "net/appletalk: fix minor pointer leak to userspace in SIOCFINDIPDDPRT" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2019-14763": { "cmt_msg": "usb: dwc3: gadget: never call ->complete() from ->ep_queue()" }, @@ -13149,6 +13293,9 @@ "CVE-2020-0444": { "cmt_msg": "audit: fix error handling in audit_data_to_entry()" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2020-8832": { "cmt_msg": "drm/i915: Record the default hw state after reset upon load" }, @@ -13368,8 +13515,8 @@ "CVE-2020-12655": { "cmt_msg": "xfs: add agf freeblocks verify in xfs_agf_verify" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -13482,6 +13629,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -13518,6 +13668,9 @@ "CVE-2019-19768": { "cmt_msg": "blktrace: Protect q->blk_trace with RCU" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -14307,6 +14460,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2018-18281": { "cmt_msg": "mremap: properly flush TLB before releasing the page" }, @@ -14394,6 +14550,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -14574,9 +14733,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -17635,6 +17800,10 @@ } }, "4.14.247": { + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu", + "cmt_id": "78967749984cf3614de346c90f3e259ff8272735" + }, "CVE-2021-42252": { "cmt_msg": "soc: aspeed: lpc-ctrl: Fix boundary check for mmap", "cmt_id": "b1b55e4073d3da6119ecc41636a2994b67a2be37" @@ -17761,6 +17930,10 @@ } }, "4.14.258": { + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection", + "cmt_id": "43cc4686b15d7d3a2b65b125393ea3f3d477e7d1" + }, "CVE-2021-39698": { "cmt_msg": "wait: add wake_up_pollfree()", "cmt_id": "a36e1978c6cb6282fadd5d62d4b3e7808cf0597b" @@ -17810,6 +17983,10 @@ "CVE-2021-44733": { "cmt_msg": "tee: handle lookup of shm with reference count 0", "cmt_id": "3d556a28bbfe34a80b014db49908b0f1bcb1ae80" + }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint", + "cmt_id": "8873140f95d4977bf37e4cf0d5c5e3f6e34cdd3e" } }, "4.14.262": { @@ -18031,14 +18208,6 @@ } }, "4.14.278": { - "CVE-2022-1419": { - "cmt_msg": "drm/vgem: Close use-after-free race in vgem_gem_create", - "cmt_id": "d2b8e8fbac9f175388d2808ade90d86402642b01" - }, - "CVE-2022-1734": { - "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs", - "cmt_id": "ced30680fb1c7c1daae39a9384d23cd1a022585f" - }, "CVE-2022-1836": { "cmt_msg": "floppy: disable FDRAWCMD by default", "cmt_id": "b7fa84ae1171a3c5ea5d710899080a6e63cfe084" @@ -18046,6 +18215,22 @@ "CVE-2022-29581": { "cmt_msg": "net/sched: cls_u32: fix netns refcount changes in u32_change()", "cmt_id": "0511cdd41a03ab396602dded4e778c5edcd8dcd1" + }, + "CVE-2022-1734": { + "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs", + "cmt_id": "ced30680fb1c7c1daae39a9384d23cd1a022585f" + }, + "CVE-2022-1419": { + "cmt_msg": "drm/vgem: Close use-after-free race in vgem_gem_create", + "cmt_id": "d2b8e8fbac9f175388d2808ade90d86402642b01" + }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions", + "cmt_id": "6f0ac4cd0377ab4e0b49b8f6efd37057c21336a9" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout", + "cmt_id": "c33b2afffe8ae90e0bd4790e0505edd92addf14c" } }, "4.14.279": { @@ -18064,6 +18249,16 @@ "cmt_id": "aaf166f37eb6bb55d81c3e40a2a460c8875c8813" } }, + "4.14.282": { + "CVE-2022-0494": { + "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern", + "cmt_id": "4f3ea768c56e8dce55ae538f18b37420366c5c22" + }, + "CVE-2022-1012": { + "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation", + "cmt_id": "40d20f3186ddd9b6b94598f4ef3d07644b0fa43c" + } + }, "outstanding": { "CVE-2021-0929": { "cmt_msg": "staging/android/ion: delete dma_buf->kmap/unmap implemenation" @@ -18089,6 +18284,9 @@ "CVE-2022-0168": { "cmt_msg": "cifs: fix NULL ptr dereference in smb2_ioctl_query_info()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-20854": { "cmt_msg": "phy: ocelot-serdes: fix out-of-bounds read" }, @@ -18185,9 +18383,6 @@ "CVE-2019-19241": { "cmt_msg": "io_uring: async workers should inherit the user creds" }, - "CVE-2022-1012": { - "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation" - }, "CVE-2021-43975": { "cmt_msg": "atlantic: Fix OOB read and write in hw_atl_utils_fw_rpc_wait" }, @@ -18212,8 +18407,8 @@ "CVE-2022-1678": { "cmt_msg": "tcp: optimize tcp internal pacing" }, - "CVE-2022-0494": { - "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" + "CVE-2022-1462": { + "cmt_msg": "" }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" @@ -18332,9 +18527,6 @@ "CVE-2022-29968": { "cmt_msg": "io_uring: fix uninitialized field in rw io_kiocb" }, - "CVE-2022-1462": { - "cmt_msg": "" - }, "CVE-2022-0812": { "cmt_msg": "xprtrdma: fix incorrect header size calculations" }, @@ -18371,6 +18563,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2021-0695": { "cmt_msg": "" }, @@ -18383,6 +18578,9 @@ "CVE-2021-28951": { "cmt_msg": "io_uring: ensure that SQPOLL thread is started for exit" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2020-14304": { "cmt_msg": "" }, @@ -18422,6 +18620,9 @@ "CVE-2020-12364": { "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-0500": { "cmt_msg": "bpf: Introduce MEM_RDONLY flag" }, @@ -18497,6 +18698,9 @@ "CVE-2020-36385": { "cmt_msg": "RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2019-12380": { "cmt_msg": "efi/x86/Add missing error handling to old_memmap 1:1 mapping code" }, @@ -18581,6 +18785,9 @@ "CVE-2021-32078": { "cmt_msg": "ARM: footbridge: remove personal server platform" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2019-10220": { "cmt_msg": "Convert filldir[64]() from __put_user() to unsafe_put_user()" }, @@ -19042,12 +19249,18 @@ "CVE-2019-18680": { "cmt_msg": "" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-27363": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -19147,6 +19360,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -19219,6 +19435,9 @@ "CVE-2018-20511": { "cmt_msg": "net/appletalk: fix minor pointer leak to userspace in SIOCFINDIPDDPRT" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2020-15437": { "cmt_msg": "serial: 8250: fix null-ptr-deref in serial8250_start_tx()" }, @@ -19513,8 +19732,8 @@ "CVE-2020-12655": { "cmt_msg": "xfs: add agf freeblocks verify in xfs_agf_verify" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -19624,6 +19843,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -19663,6 +19885,9 @@ "CVE-2019-19768": { "cmt_msg": "blktrace: Protect q->blk_trace with RCU" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -20389,6 +20614,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2018-18281": { "cmt_msg": "mremap: properly flush TLB before releasing the page" }, @@ -20476,6 +20704,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -20635,9 +20866,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -21370,12 +21610,18 @@ "CVE-2019-18680": { "cmt_msg": "" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-27363": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -21475,6 +21721,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -21550,6 +21799,9 @@ "CVE-2018-20511": { "cmt_msg": "net/appletalk: fix minor pointer leak to userspace in SIOCFINDIPDDPRT" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2020-15437": { "cmt_msg": "serial: 8250: fix null-ptr-deref in serial8250_start_tx()" }, @@ -21862,8 +22114,8 @@ "CVE-2020-12655": { "cmt_msg": "xfs: add agf freeblocks verify in xfs_agf_verify" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -21976,6 +22228,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -22015,6 +22270,9 @@ "CVE-2019-19768": { "cmt_msg": "blktrace: Protect q->blk_trace with RCU" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -22771,6 +23029,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2018-18281": { "cmt_msg": "mremap: properly flush TLB before releasing the page" }, @@ -22861,6 +23122,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -23038,9 +23302,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -25518,22 +25791,26 @@ } }, "4.19.207": { - "CVE-2021-42252": { - "cmt_msg": "soc: aspeed: lpc-ctrl: Fix boundary check for mmap", - "cmt_id": "9c8891b638319ddba9cfa330247922cd960c95b0" + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu", + "cmt_id": "4768973dffed4d0126854514335ed4fe87bec1ab" }, "CVE-2021-34556": { "cmt_msg": "bpf: Introduce BPF nospec instruction for mitigating Spectre v4", "cmt_id": "91cdb5b36234e6af69d6280f1510e4453707a2b8" }, - "CVE-2021-35477": { - "cmt_msg": "bpf: Introduce BPF nospec instruction for mitigating Spectre v4", - "cmt_id": "91cdb5b36234e6af69d6280f1510e4453707a2b8" - }, "CVE-2020-16119": { "cmt_msg": "dccp: don't duplicate ccid when cloning dccp sock", "cmt_id": "dfec82f3e5b8bd93ab65b7417a64886ec8c42f14" }, + "CVE-2021-35477": { + "cmt_msg": "bpf: Introduce BPF nospec instruction for mitigating Spectre v4", + "cmt_id": "91cdb5b36234e6af69d6280f1510e4453707a2b8" + }, + "CVE-2021-42252": { + "cmt_msg": "soc: aspeed: lpc-ctrl: Fix boundary check for mmap", + "cmt_id": "9c8891b638319ddba9cfa330247922cd960c95b0" + }, "CVE-2021-40490": { "cmt_msg": "ext4: fix race writing to an inline_data file while its xattrs are changing", "cmt_id": "c481607ba522e31e6ed01efefc19cc1d0e0a46fa" @@ -25674,6 +25951,10 @@ "cmt_msg": "wait: add wake_up_pollfree()", "cmt_id": "8dd7c46a59756bdc29cb9783338b899cd3fb4b83" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection", + "cmt_id": "b1efa723b986a84f84a95b6907cffe3a357338c9" + }, "CVE-2021-39685": { "cmt_msg": "USB: gadget: detect too-big endpoint 0 requests", "cmt_id": "13e45e7a262dd96e8161823314679543048709b9" @@ -25719,6 +26000,10 @@ "CVE-2021-44733": { "cmt_msg": "tee: handle lookup of shm with reference count 0", "cmt_id": "b4a661b4212b8fac8853ec3b68e4a909dccc88a1" + }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint", + "cmt_id": "af6e6e58f7ebf86b4e7201694b1e4f3a62cbc3ec" } }, "4.19.225": { @@ -25948,6 +26233,14 @@ "cmt_msg": "drm/vgem: Close use-after-free race in vgem_gem_create", "cmt_id": "df2c1f38939aabb8c6beca108f08b90f050b9ebc" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions", + "cmt_id": "7deebb94a311da0e02e621e765c3aef3d5936572" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout", + "cmt_id": "d360fc8df363ecd7892d755d69ffc8c61d699e38" + }, "CVE-2022-1734": { "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs", "cmt_id": "b266f492b2af82269aaaab871ac3949420ae678c" @@ -25969,6 +26262,16 @@ "cmt_id": "06cb238b0f7ac1669cb06390704c61794724c191" } }, + "4.19.246": { + "CVE-2022-0494": { + "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern", + "cmt_id": "18243d8479fd77952bdb6340024169d30b173a40" + }, + "CVE-2022-1012": { + "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation", + "cmt_id": "695309c5c71526d32f5539f008bbf20ed2218528" + } + }, "outstanding": { "CVE-2021-0929": { "cmt_msg": "staging/android/ion: delete dma_buf->kmap/unmap implemenation" @@ -25994,6 +26297,9 @@ "CVE-2022-0168": { "cmt_msg": "cifs: fix NULL ptr dereference in smb2_ioctl_query_info()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-20854": { "cmt_msg": "phy: ocelot-serdes: fix out-of-bounds read" }, @@ -26078,9 +26384,6 @@ "CVE-2019-19241": { "cmt_msg": "io_uring: async workers should inherit the user creds" }, - "CVE-2022-1012": { - "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation" - }, "CVE-2021-26934": { "cmt_msg": "" }, @@ -26099,8 +26402,8 @@ "CVE-2019-12378": { "cmt_msg": "ipv6_sockglue: Fix a missing-check bug in ip6_ra_control()" }, - "CVE-2022-0494": { - "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" + "CVE-2022-1462": { + "cmt_msg": "" }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" @@ -26189,9 +26492,6 @@ "CVE-2022-29968": { "cmt_msg": "io_uring: fix uninitialized field in rw io_kiocb" }, - "CVE-2022-1462": { - "cmt_msg": "" - }, "CVE-2022-0812": { "cmt_msg": "xprtrdma: fix incorrect header size calculations" }, @@ -26222,6 +26522,9 @@ "CVE-2021-4159": { "cmt_msg": "bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2021-0695": { "cmt_msg": "" }, @@ -26234,6 +26537,9 @@ "CVE-2021-28951": { "cmt_msg": "io_uring: ensure that SQPOLL thread is started for exit" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2020-14304": { "cmt_msg": "" }, @@ -26273,6 +26579,9 @@ "CVE-2020-12364": { "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-0500": { "cmt_msg": "bpf: Introduce MEM_RDONLY flag" }, @@ -26342,6 +26651,9 @@ "CVE-2020-36385": { "cmt_msg": "RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2019-12380": { "cmt_msg": "efi/x86/Add missing error handling to old_memmap 1:1 mapping code" }, @@ -26417,6 +26729,9 @@ "CVE-2021-32078": { "cmt_msg": "ARM: footbridge: remove personal server platform" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2019-10220": { "cmt_msg": "Convert filldir[64]() from __put_user() to unsafe_put_user()" }, @@ -26856,12 +27171,18 @@ "CVE-2019-18680": { "cmt_msg": "" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-27363": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -26961,6 +27282,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -27033,6 +27357,9 @@ "CVE-2019-16229": { "cmt_msg": "drm/amdkfd: fix a potential NULL pointer dereference (v2)" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2020-15437": { "cmt_msg": "serial: 8250: fix null-ptr-deref in serial8250_start_tx()" }, @@ -27309,8 +27636,8 @@ "CVE-2020-12655": { "cmt_msg": "xfs: add agf freeblocks verify in xfs_agf_verify" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -27411,6 +27738,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -27453,6 +27783,9 @@ "CVE-2019-19768": { "cmt_msg": "blktrace: Protect q->blk_trace with RCU" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -28167,6 +28500,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2019-8912": { "cmt_msg": "net: crypto set sk to NULL when af_alg_release." }, @@ -28248,6 +28584,9 @@ "CVE-2020-10757": { "cmt_msg": "mm: Fix mremap not considering huge pmd devmap" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -28404,9 +28743,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -30297,6 +30645,9 @@ "CVE-2021-3847": { "cmt_msg": "" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2019-19241": { "cmt_msg": "io_uring: async workers should inherit the user creds" }, @@ -30492,12 +30843,18 @@ "CVE-2015-8952": { "cmt_msg": "ext2: convert to mbcache2" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-0995": { "cmt_msg": "watch_queue: Fix filter limit check" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-27363": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -30585,6 +30942,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-11600": { "cmt_msg": "xfrm: policy: check policy direction value" }, @@ -30651,6 +31011,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2020-0067": { "cmt_msg": "f2fs: fix to avoid memory leakage in f2fs_listxattr" }, @@ -30810,6 +31173,9 @@ "CVE-2022-30594": { "cmt_msg": "ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2017-16528": { "cmt_msg": "ALSA: seq: Cancel pending autoload work at unbinding device" }, @@ -31179,6 +31545,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2017-15116": { "cmt_msg": "crypto: rng - Remove old low-level rng interface" }, @@ -31332,6 +31701,9 @@ "CVE-2020-12364": { "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2022-25375": { "cmt_msg": "usb: gadget: rndis: check size of RNDIS_MSG_SET command" }, @@ -32151,6 +32523,9 @@ "CVE-2019-15215": { "cmt_msg": "media: cpia2_usb: first wake up, then free in disconnect" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -32346,9 +32721,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2022-1678": { "cmt_msg": "tcp: optimize tcp internal pacing" }, @@ -33787,6 +34168,9 @@ "CVE-2021-3847": { "cmt_msg": "" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2019-13631": { "cmt_msg": "Input: gtco - bounds check collection indent level" }, @@ -34012,6 +34396,9 @@ "CVE-2015-8952": { "cmt_msg": "ext2: convert to mbcache2" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2020-26558": { "cmt_msg": "Bluetooth: SMP: Fail if remote and local public keys are identical" }, @@ -34021,6 +34408,9 @@ "CVE-2017-1000410": { "cmt_msg": "Bluetooth: Prevent stack info leak from the EFS element." }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2016-8645": { "cmt_msg": "tcp: take care of truncations done by sk_filter()" }, @@ -34111,6 +34501,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-11600": { "cmt_msg": "xfrm: policy: check policy direction value" }, @@ -34183,6 +34576,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2020-0067": { "cmt_msg": "f2fs: fix to avoid memory leakage in f2fs_listxattr" }, @@ -34714,6 +35110,9 @@ "CVE-2017-14489": { "cmt_msg": "scsi: scsi_transport_iscsi: fix the issue that iscsi_if_rx doesn't parse nlmsg properly" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2018-9422": { "cmt_msg": "futex: Remove requirement for lock_page() in get_futex_key()" }, @@ -34774,6 +35173,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2018-5344": { "cmt_msg": "loop: fix concurrent lo_open/lo_release" }, @@ -34945,6 +35347,9 @@ "CVE-2020-12364": { "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2016-9588": { "cmt_msg": "kvm: nVMX: Allow L1 to intercept software exceptions (#BP and #OF)" }, @@ -35854,6 +36259,9 @@ "CVE-2019-15215": { "cmt_msg": "media: cpia2_usb: first wake up, then free in disconnect" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -36079,9 +36487,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2022-1678": { "cmt_msg": "tcp: optimize tcp internal pacing" }, @@ -39356,12 +39770,18 @@ "CVE-2019-18680": { "cmt_msg": "" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-45868": { "cmt_msg": "quota: check block number when reading the block in quota file" }, @@ -39404,6 +39824,9 @@ "CVE-2020-27068": { "cmt_msg": "cfg80211: add missing policy for NL80211_ATTR_STATUS_CODE" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -39509,6 +39932,9 @@ "CVE-2019-19039": { "cmt_msg": "btrfs: Don't submit any btree write bio if the fs has errors" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2020-8832": { "cmt_msg": "drm/i915: Record the default hw state after reset upon load" }, @@ -39659,8 +40085,8 @@ "CVE-2022-23042": { "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -39740,6 +40166,9 @@ "CVE-2021-34981": { "cmt_msg": "Bluetooth: cmtp: fix file refcount when cmtp_attach_device fails" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" }, @@ -39761,6 +40190,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2018-5344": { "cmt_msg": "loop: fix concurrent lo_open/lo_release" }, @@ -40154,6 +40586,9 @@ "CVE-2021-3542": { "cmt_msg": "" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2020-12656": { "cmt_msg": "sunrpc: check that domain table is empty at module unload." }, @@ -40208,6 +40643,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2015-3339": { "cmt_msg": "fs: take i_mutex during prepare_binprm for set[ug]id executables" }, @@ -40265,6 +40703,9 @@ "CVE-2021-35477": { "cmt_msg": "bpf: Introduce BPF nospec instruction for mitigating Spectre v4" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2019-12614": { "cmt_msg": "powerpc/pseries/dlpar: Fix a missing check in dlpar_parse_cc_property()" }, @@ -40373,9 +40814,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2018-12130": { "cmt_msg": "s390/speculation: Support 'mitigations=' cmdline option" }, @@ -42999,12 +43446,18 @@ "CVE-2015-8952": { "cmt_msg": "ext2: convert to mbcache2" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-27363": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -43086,6 +43539,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -43245,6 +43701,9 @@ "CVE-2019-19039": { "cmt_msg": "btrfs: Don't submit any btree write bio if the fs has errors" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2020-8832": { "cmt_msg": "drm/i915: Record the default hw state after reset upon load" }, @@ -43413,8 +43872,8 @@ "CVE-2022-23042": { "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -43515,6 +43974,9 @@ "CVE-2021-34981": { "cmt_msg": "Bluetooth: cmtp: fix file refcount when cmtp_attach_device fails" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2018-9422": { "cmt_msg": "futex: Remove requirement for lock_page() in get_futex_key()" }, @@ -43548,6 +44010,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2017-15116": { "cmt_msg": "crypto: rng - Remove old low-level rng interface" }, @@ -43668,6 +44133,9 @@ "CVE-2022-24958": { "cmt_msg": "usb: gadget: don't release an existing dev->buf" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2020-10766": { "cmt_msg": "x86/speculation: Prevent rogue cross-process SSBD shutdown" }, @@ -44217,6 +44685,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2015-3332": { "cmt_msg": "tcp: Fix crash in TCP Fast Open" }, @@ -44292,6 +44763,9 @@ "CVE-2019-16746": { "cmt_msg": "nl80211: validate beacon head" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -44430,9 +44904,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2017-0786": { "cmt_msg": "brcmfmac: add length check in brcmf_cfg80211_escan_handler()" }, @@ -45017,6 +45497,9 @@ "CVE-2018-17182": { "cmt_msg": "mm: get rid of vmacache_flush_all() entirely" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2019-13631": { "cmt_msg": "Input: gtco - bounds check collection indent level" }, @@ -45260,6 +45743,9 @@ "CVE-2017-1000410": { "cmt_msg": "Bluetooth: Prevent stack info leak from the EFS element." }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2016-8645": { "cmt_msg": "tcp: take care of truncations done by sk_filter()" }, @@ -45350,6 +45836,9 @@ "CVE-2016-3857": { "cmt_msg": "arm: oabi compat: add missing access checks" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-11600": { "cmt_msg": "xfrm: policy: check policy direction value" }, @@ -45425,6 +45914,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2019-2024": { "cmt_msg": "media: em28xx: Fix use-after-free when disconnecting" }, @@ -45482,6 +45974,9 @@ "CVE-2018-20510": { "cmt_msg": "binder: replace \"%p\" with \"%pK\"" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2016-5728": { "cmt_msg": "misc: mic: Fix for double fetch security bug in VOP driver" }, @@ -45632,6 +46127,9 @@ "CVE-2022-30594": { "cmt_msg": "ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2017-16528": { "cmt_msg": "ALSA: seq: Cancel pending autoload work at unbinding device" }, @@ -46046,6 +46544,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2016-8630": { "cmt_msg": "kvm: x86: Check memopp before dereference (CVE-2016-8630)" }, @@ -46835,6 +47336,9 @@ "CVE-2017-2636": { "cmt_msg": "tty: n_hdlc: get rid of racy n_hdlc.tbuf" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2020-15437": { "cmt_msg": "serial: 8250: fix null-ptr-deref in serial8250_start_tx()" }, @@ -47216,6 +47720,9 @@ "CVE-2019-15215": { "cmt_msg": "media: cpia2_usb: first wake up, then free in disconnect" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -47444,9 +47951,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2017-2596": { "cmt_msg": "kvm: fix page struct leak in handle_vmon" }, @@ -51250,6 +51763,10 @@ } }, "4.4.284": { + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu", + "cmt_id": "b24065948ae6c48c9e20891f8cfe9850f1d748be" + }, "CVE-2021-40490": { "cmt_msg": "ext4: fix race writing to an inline_data file while its xattrs are changing", "cmt_id": "69d82df68fbc5e368820123200d7b88f6c058350" @@ -51344,6 +51861,10 @@ } }, "4.4.295": { + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection", + "cmt_id": "6a0bc60a84cb5186a84e7501616dacfd9e991b54" + }, "CVE-2021-39698": { "cmt_msg": "wait: add wake_up_pollfree()", "cmt_id": "d0ceebaae0e406263b83462701b5645e075c1467" @@ -51622,6 +52143,9 @@ "CVE-2020-16120": { "cmt_msg": "ovl: switch to mounter creds in readdir" }, + "CVE-2022-23222": { + "cmt_msg": "bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL" + }, "CVE-2020-15802": { "cmt_msg": "" }, @@ -51739,6 +52263,9 @@ "CVE-2021-38300": { "cmt_msg": "bpf, mips: Validate conditional branch offsets" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2021-3669": { "cmt_msg": "ipc: replace costly bailout check in sysvipc_find_ipc()" }, @@ -51769,6 +52296,9 @@ "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2017-13694": { "cmt_msg": "" }, @@ -51805,6 +52335,9 @@ "CVE-2022-1184": { "cmt_msg": "" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, @@ -51862,6 +52395,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -51994,8 +52530,8 @@ "CVE-2022-23960": { "cmt_msg": "ARM: report Spectre v2 status through sysfs" }, - "CVE-2022-23222": { - "cmt_msg": "bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL" + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" }, "CVE-2018-5995": { "cmt_msg": "printk: hash addresses printed with %p" @@ -52087,6 +52623,9 @@ "CVE-2021-3542": { "cmt_msg": "" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2022-25375": { "cmt_msg": "usb: gadget: rndis: check size of RNDIS_MSG_SET command" }, @@ -52171,6 +52710,9 @@ "CVE-2021-26401": { "cmt_msg": "x86/speculation: Use generic retpoline by default on AMD" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2021-3847": { "cmt_msg": "" }, @@ -52198,6 +52740,12 @@ "CVE-2022-30594": { "cmt_msg": "ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2019-10220": { "cmt_msg": "Convert filldir[64]() from __put_user() to unsafe_put_user()" }, @@ -52405,6 +52953,9 @@ "CVE-2021-0920": { "cmt_msg": "af_unix: fix garbage collect vs MSG_PEEK" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2019-13631": { "cmt_msg": "Input: gtco - bounds check collection indent level" }, @@ -52633,12 +53184,18 @@ "CVE-2019-18680": { "cmt_msg": "unknown" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2017-1000410": { "cmt_msg": "Bluetooth: Prevent stack info leak from the EFS element." }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2016-8645": { "cmt_msg": "tcp: take care of truncations done by sk_filter()" }, @@ -52729,6 +53286,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-11600": { "cmt_msg": "xfrm: policy: check policy direction value" }, @@ -52801,6 +53361,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2019-2024": { "cmt_msg": "media: em28xx: Fix use-after-free when disconnecting" }, @@ -53356,6 +53919,9 @@ "CVE-2017-14489": { "cmt_msg": "scsi: scsi_transport_iscsi: fix the issue that iscsi_if_rx doesn't parse nlmsg properly" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" }, @@ -53407,6 +53973,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -53578,6 +54147,9 @@ "CVE-2020-12364": { "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2017-12146": { "cmt_msg": "driver core: platform: fix race condition with driver_override" }, @@ -54532,6 +55104,9 @@ "CVE-2019-15215": { "cmt_msg": "media: cpia2_usb: first wake up, then free in disconnect" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -54763,9 +55338,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2017-2596": { "cmt_msg": "kvm: fix page struct leak in handle_vmon" }, @@ -55407,6 +55988,9 @@ "CVE-2021-0920": { "cmt_msg": "af_unix: fix garbage collect vs MSG_PEEK" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2019-13631": { "cmt_msg": "Input: gtco - bounds check collection indent level" }, @@ -55644,6 +56228,9 @@ "CVE-2019-18680": { "cmt_msg": "unknown" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2020-26558": { "cmt_msg": "Bluetooth: SMP: Fail if remote and local public keys are identical" }, @@ -55653,6 +56240,9 @@ "CVE-2017-1000410": { "cmt_msg": "Bluetooth: Prevent stack info leak from the EFS element." }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2016-8645": { "cmt_msg": "tcp: take care of truncations done by sk_filter()" }, @@ -55743,6 +56333,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-11600": { "cmt_msg": "xfrm: policy: check policy direction value" }, @@ -55815,6 +56408,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2019-2024": { "cmt_msg": "media: em28xx: Fix use-after-free when disconnecting" }, @@ -56370,6 +56966,9 @@ "CVE-2017-14489": { "cmt_msg": "scsi: scsi_transport_iscsi: fix the issue that iscsi_if_rx doesn't parse nlmsg properly" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" }, @@ -56421,6 +57020,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2021-45095": { "cmt_msg": "phonet: refcount leak in pep_sock_accep" }, @@ -56592,6 +57194,9 @@ "CVE-2020-12364": { "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2017-12146": { "cmt_msg": "driver core: platform: fix race condition with driver_override" }, @@ -57552,6 +58157,9 @@ "CVE-2019-15215": { "cmt_msg": "media: cpia2_usb: first wake up, then free in disconnect" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -57783,9 +58391,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2017-2596": { "cmt_msg": "kvm: fix page struct leak in handle_vmon" }, @@ -59778,12 +60392,18 @@ "CVE-2015-8952": { "cmt_msg": "ext2: convert to mbcache2" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2016-8645": { "cmt_msg": "tcp: take care of truncations done by sk_filter()" }, @@ -59868,6 +60488,9 @@ "CVE-2016-3857": { "cmt_msg": "arm: oabi compat: add missing access checks" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -59964,6 +60587,9 @@ "CVE-2018-20510": { "cmt_msg": "binder: replace \"%p\" with \"%pK\"" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2016-5728": { "cmt_msg": "misc: mic: Fix for double fetch security bug in VOP driver" }, @@ -60063,6 +60689,9 @@ "CVE-2020-0444": { "cmt_msg": "audit: fix error handling in audit_data_to_entry()" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2020-8832": { "cmt_msg": "drm/i915: Record the default hw state after reset upon load" }, @@ -60075,6 +60704,9 @@ "CVE-2022-30594": { "cmt_msg": "ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2019-11833": { "cmt_msg": "ext4: zero out the unused memory region in the extent tree block" }, @@ -60264,8 +60896,8 @@ "CVE-2020-12655": { "cmt_msg": "xfs: add agf freeblocks verify in xfs_agf_verify" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -60396,6 +61028,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2016-8630": { "cmt_msg": "kvm: x86: Check memopp before dereference (CVE-2016-8630)" }, @@ -61167,6 +61802,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2018-18281": { "cmt_msg": "mremap: properly flush TLB before releasing the page" }, @@ -61251,6 +61889,9 @@ "CVE-2019-16746": { "cmt_msg": "nl80211: validate beacon head" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -61419,9 +62060,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -62104,6 +62751,9 @@ "CVE-2021-32399": { "cmt_msg": "bluetooth: eliminate the potential race condition when removing the HCI controller" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2021-27364": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -62113,6 +62763,9 @@ "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-45868": { "cmt_msg": "quota: check block number when reading the block in quota file" }, @@ -62158,6 +62811,9 @@ "CVE-2022-29582": { "cmt_msg": "io_uring: fix race between timeout flush and removal" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -62446,6 +63102,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -62467,6 +63126,9 @@ "CVE-2022-1158": { "cmt_msg": "KVM: x86/mmu: do compare-and-exchange of gPTE via the user address" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -62554,6 +63216,9 @@ "CVE-2021-3739": { "cmt_msg": "btrfs: fix NULL pointer dereference when deleting device by invalid id" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2021-3732": { "cmt_msg": "ovl: prevent private clone if bind mount is not allowed" }, @@ -62650,6 +63315,9 @@ "CVE-2020-14356": { "cmt_msg": "cgroup: fix cgroup_sk_alloc() for sk_clone_lock()" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2020-0423": { "cmt_msg": "binder: fix UAF when releasing todo list" }, @@ -62971,6 +63639,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -63043,9 +63714,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -63507,6 +64187,9 @@ "CVE-2018-17182": { "cmt_msg": "mm: get rid of vmacache_flush_all() entirely" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2019-13631": { "cmt_msg": "Input: gtco - bounds check collection indent level" }, @@ -63762,6 +64445,9 @@ "CVE-2017-1000410": { "cmt_msg": "Bluetooth: Prevent stack info leak from the EFS element." }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2016-8645": { "cmt_msg": "tcp: take care of truncations done by sk_filter()" }, @@ -63849,6 +64535,9 @@ "CVE-2016-3857": { "cmt_msg": "arm: oabi compat: add missing access checks" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-11600": { "cmt_msg": "xfrm: policy: check policy direction value" }, @@ -63924,6 +64613,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2019-2024": { "cmt_msg": "media: em28xx: Fix use-after-free when disconnecting" }, @@ -63981,6 +64673,9 @@ "CVE-2018-20510": { "cmt_msg": "binder: replace \"%p\" with \"%pK\"" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2016-5728": { "cmt_msg": "misc: mic: Fix for double fetch security bug in VOP driver" }, @@ -64140,6 +64835,9 @@ "CVE-2022-30594": { "cmt_msg": "ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2017-16528": { "cmt_msg": "ALSA: seq: Cancel pending autoload work at unbinding device" }, @@ -64578,6 +65276,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2016-8630": { "cmt_msg": "kvm: x86: Check memopp before dereference (CVE-2016-8630)" }, @@ -65400,6 +66101,9 @@ "CVE-2017-2636": { "cmt_msg": "tty: n_hdlc: get rid of racy n_hdlc.tbuf" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2020-15437": { "cmt_msg": "serial: 8250: fix null-ptr-deref in serial8250_start_tx()" }, @@ -65790,6 +66494,9 @@ "CVE-2019-15215": { "cmt_msg": "media: cpia2_usb: first wake up, then free in disconnect" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -66036,9 +66743,15 @@ "CVE-2018-10675": { "cmt_msg": "mm/mempolicy: fix use after free when calling get_mempolicy" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2017-2596": { "cmt_msg": "kvm: fix page struct leak in handle_vmon" }, @@ -66759,6 +67472,9 @@ "CVE-2021-32399": { "cmt_msg": "bluetooth: eliminate the potential race condition when removing the HCI controller" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2021-27364": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -66768,6 +67484,9 @@ "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-45868": { "cmt_msg": "quota: check block number when reading the block in quota file" }, @@ -66813,6 +67532,9 @@ "CVE-2021-33033": { "cmt_msg": "cipso,calipso: resolve a number of problems with the DOI refcounts" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -67083,9 +67805,15 @@ "CVE-2022-1158": { "cmt_msg": "KVM: x86/mmu: do compare-and-exchange of gPTE via the user address" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2022-28389": { "cmt_msg": "can: mcba_usb: mcba_usb_start_xmit(): fix double dev_kfree_skb in error path" }, @@ -67161,6 +67889,9 @@ "CVE-2021-3739": { "cmt_msg": "btrfs: fix NULL pointer dereference when deleting device by invalid id" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2021-3732": { "cmt_msg": "ovl: prevent private clone if bind mount is not allowed" }, @@ -67233,6 +67964,9 @@ "CVE-2020-14351": { "cmt_msg": "perf/core: Fix race in the perf_mmap_close() function" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2020-0423": { "cmt_msg": "binder: fix UAF when releasing todo list" }, @@ -67542,6 +68276,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -67614,9 +68351,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -68115,6 +68861,9 @@ "CVE-2021-32399": { "cmt_msg": "bluetooth: eliminate the potential race condition when removing the HCI controller" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2021-27364": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -68124,6 +68873,9 @@ "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-45868": { "cmt_msg": "quota: check block number when reading the block in quota file" }, @@ -68163,6 +68915,9 @@ "CVE-2021-33033": { "cmt_msg": "cipso,calipso: resolve a number of problems with the DOI refcounts" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -68379,8 +69134,8 @@ "CVE-2022-23960": { "cmt_msg": "ARM: report Spectre v2 status through sysfs" }, - "CVE-2021-4154": { - "cmt_msg": "cgroup: verify that source is a string" + "CVE-2022-25258": { + "cmt_msg": "USB: gadget: validate interface OS descriptor requests" }, "CVE-2021-39656": { "cmt_msg": "configfs: fix a use-after-free in __configfs_open_file" @@ -68409,9 +69164,15 @@ "CVE-2022-1158": { "cmt_msg": "KVM: x86/mmu: do compare-and-exchange of gPTE via the user address" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2008-4609": { "cmt_msg": "" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2022-28389": { "cmt_msg": "can: mcba_usb: mcba_usb_start_xmit(): fix double dev_kfree_skb in error path" }, @@ -68550,6 +69311,9 @@ "CVE-2020-29569": { "cmt_msg": "xen-blkback: set ring->xenblkd to NULL after kthread_stop()" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2022-1789": { "cmt_msg": "KVM: x86/mmu: fix NULL pointer dereference on guest INVPCID" }, @@ -68727,6 +69491,9 @@ "CVE-2021-3542": { "cmt_msg": "" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2022-23041": { "cmt_msg": "xen/9p: use alloc/free_pages_exact()" }, @@ -68832,6 +69599,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -68901,9 +69671,18 @@ "CVE-2021-46283": { "cmt_msg": "netfilter: nf_tables: initialize set before expression setup" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -68913,8 +69692,8 @@ "CVE-2021-4157": { "cmt_msg": "pNFS/flexfiles: fix incorrect size check in decode_nfs_fh()" }, - "CVE-2022-25258": { - "cmt_msg": "USB: gadget: validate interface OS descriptor requests" + "CVE-2021-4154": { + "cmt_msg": "cgroup: verify that source is a string" }, "CVE-2021-4155": { "cmt_msg": "xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate" @@ -69239,6 +70018,252 @@ "CVE-2020-36322": { "cmt_msg": "fuse: fix bad inode" }, + "CVE-2020-35501": { + "cmt_msg": "" + }, + "CVE-2021-45095": { + "cmt_msg": "phonet: refcount leak in pep_sock_accep" + }, + "CVE-2022-0001": { + "cmt_msg": "x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE" + }, + "CVE-2022-0002": { + "cmt_msg": "x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE" + }, + "CVE-2020-24587": { + "cmt_msg": "mac80211: prevent mixed key and fragment cache attacks" + }, + "CVE-2020-24586": { + "cmt_msg": "mac80211: prevent mixed key and fragment cache attacks" + }, + "CVE-2022-0995": { + "cmt_msg": "watch_queue: Fix filter limit check" + }, + "CVE-2021-0129": { + "cmt_msg": "Bluetooth: SMP: Fail if remote and local public keys are identical" + }, + "CVE-2020-24588": { + "cmt_msg": "cfg80211: mitigate A-MSDU aggregation attacks" + }, + "CVE-2021-3444": { + "cmt_msg": "bpf: Fix truncation handling for mod32 dst reg wrt zero" + }, + "CVE-2020-36158": { + "cmt_msg": "mwifiex: Fix possible buffer overflows in mwifiex_cmd_802_11_ad_hoc_start" + }, + "CVE-2022-0480": { + "cmt_msg": "memcg: enable accounting for file lock caches" + }, + "CVE-2022-0487": { + "cmt_msg": "moxart: fix potential use-after-free on remove path" + }, + "CVE-2021-42252": { + "cmt_msg": "soc: aspeed: lpc-ctrl: Fix boundary check for mmap" + }, + "CVE-2021-28688": { + "cmt_msg": "xen-blkback: don't leak persistent grants from xen_blkbk_map()" + }, + "CVE-2021-39686": { + "cmt_msg": "binder: use euid from cred instead of using task" + }, + "CVE-2021-39685": { + "cmt_msg": "USB: gadget: detect too-big endpoint 0 requests" + }, + "CVE-2021-43975": { + "cmt_msg": "atlantic: Fix OOB read and write in hw_atl_utils_fw_rpc_wait" + }, + "CVE-2021-43976": { + "cmt_msg": "mwifiex: Fix skb_over_panic in mwifiex_usb_recv()" + }, + "CVE-2021-3669": { + "cmt_msg": "ipc: replace costly bailout check in sysvipc_find_ipc()" + }, + "CVE-2021-3744": { + "cmt_msg": "crypto: ccp - fix resource leaks in ccp_run_aes_gcm_cmd()" + }, + "CVE-2021-30002": { + "cmt_msg": "media: v4l: ioctl: Fix memory leak in video_usercopy" + }, + "CVE-2021-3743": { + "cmt_msg": "net: qrtr: fix OOB Read in qrtr_endpoint_post" + }, + "CVE-2021-0941": { + "cmt_msg": "bpf: Remove MTU check in __bpf_skb_max_len" + }, + "CVE-2020-15802": { + "cmt_msg": "" + }, + "CVE-2021-28715": { + "cmt_msg": "xen/netback: don't queue unlimited number of packages" + }, + "CVE-2020-26145": { + "cmt_msg": "ath10k: drop fragments with multicast DA for PCIe" + }, + "CVE-2020-26147": { + "cmt_msg": "mac80211: assure all fragments are encrypted" + }, + "CVE-2020-26141": { + "cmt_msg": "ath10k: Fix TKIP Michael MIC verification for PCIe" + }, + "CVE-2020-26140": { + "cmt_msg": "" + }, + "CVE-2021-43389": { + "cmt_msg": "isdn: cpai: check ctr->cnr to avoid array index out of bound" + }, + "CVE-2020-26142": { + "cmt_msg": "" + }, + "CVE-2022-1734": { + "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs" + }, + "CVE-2021-32399": { + "cmt_msg": "bluetooth: eliminate the potential race condition when removing the HCI controller" + }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, + "CVE-2021-27364": { + "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" + }, + "CVE-2022-23038": { + "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" + }, + "CVE-2022-23039": { + "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" + }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, + "CVE-2021-45868": { + "cmt_msg": "quota: check block number when reading the block in quota file" + }, + "CVE-2022-23036": { + "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" + }, + "CVE-2022-23037": { + "cmt_msg": "xen/netfront: don't use gnttab_query_foreign_access() for mapped status" + }, + "CVE-2021-38160": { + "cmt_msg": "virtio_console: Assure used length from device is limited" + }, + "CVE-2021-42008": { + "cmt_msg": "net: 6pack: fix slab-out-of-bounds in decode_data" + }, + "CVE-2021-38166": { + "cmt_msg": "bpf: Fix integer overflow involving bucket_size" + }, + "CVE-2021-3490": { + "cmt_msg": "bpf: Fix alu32 const subreg bound tracking on bitwise operations" + }, + "CVE-2021-3491": { + "cmt_msg": "io_uring: truncate lengths larger than MAX_RW_COUNT on provide buffers" + }, + "CVE-2005-3660": { + "cmt_msg": "" + }, + "CVE-2022-0516": { + "cmt_msg": "KVM: s390: Return error on SIDA memop on normal guest" + }, + "CVE-2021-33135": { + "cmt_msg": "" + }, + "CVE-2021-33034": { + "cmt_msg": "Bluetooth: verify AMP hci_chan before amp_destroy" + }, + "CVE-2021-33033": { + "cmt_msg": "cipso,calipso: resolve a number of problems with the DOI refcounts" + }, + "CVE-2022-0286": { + "cmt_msg": "bonding: fix null dereference in bond_ipsec_add_sa()" + }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, + "CVE-2020-14304": { + "cmt_msg": "" + }, + "CVE-2022-29581": { + "cmt_msg": "net/sched: cls_u32: fix netns refcount changes in u32_change()" + }, + "CVE-2021-3564": { + "cmt_msg": "Bluetooth: fix the erroneous flush_work() order" + }, + "CVE-2022-1943": { + "cmt_msg": "udf: Avoid using stale lengthOfImpUse" + }, + "CVE-2020-26560": { + "cmt_msg": "" + }, + "CVE-2021-28964": { + "cmt_msg": "btrfs: fix race when cloning extent buffer during rewind of an old root" + }, + "CVE-2021-4083": { + "cmt_msg": "fget: check that the fd still exists after getting a ref to it" + }, + "CVE-2022-29582": { + "cmt_msg": "io_uring: fix race between timeout flush and removal" + }, + "CVE-2022-1116": { + "cmt_msg": "" + }, + "CVE-2021-28660": { + "cmt_msg": "staging: rtl8188eu: prevent ->ssid overflow in rtw_wx_set_scan()" + }, + "CVE-2020-36385": { + "cmt_msg": "RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy" + }, + "CVE-2022-1882": { + "cmt_msg": "" + }, + "CVE-2021-3573": { + "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" + }, + "CVE-2022-1204": { + "cmt_msg": "ax25: Fix refcount leaks caused by ax25_cb_del()" + }, + "CVE-2022-1205": { + "cmt_msg": "ax25: Fix NULL pointer dereferences in ax25 timers" + }, + "CVE-2021-34693": { + "cmt_msg": "can: bcm: fix infoleak in struct bcm_msg_head" + }, + "CVE-2022-26490": { + "cmt_msg": "nfc: st21nfca: Fix potential buffer overflows in EVT_TRANSACTION" + }, + "CVE-2022-1836": { + "cmt_msg": "floppy: disable FDRAWCMD by default" + }, + "CVE-2021-32078": { + "cmt_msg": "ARM: footbridge: remove personal server platform" + }, + "CVE-2022-30594": { + "cmt_msg": "ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE" + }, + "CVE-2021-38204": { + "cmt_msg": "usb: max-3421: Prevent corruption of freed memory" + }, + "CVE-2021-38205": { + "cmt_msg": "net: xilinx_emaclite: Do not print real IOMEM pointer" + }, + "CVE-2021-38206": { + "cmt_msg": "mac80211: Fix NULL ptr deref for injected rate info" + }, + "CVE-2021-38207": { + "cmt_msg": "net: ll_temac: Fix TX BD buffer overwrite" + }, + "CVE-2022-27666": { + "cmt_msg": "esp: Fix possible buffer overflow in ESP transformation" + }, + "CVE-2021-38208": { + "cmt_msg": "nfc: fix NULL ptr dereference in llcp_sock_getname() after failed connect" + }, + "CVE-2021-38209": { + "cmt_msg": "netfilter: conntrack: Make global sysctls readonly in non-init netns" + }, + "CVE-2022-0168": { + "cmt_msg": "cifs: fix NULL ptr dereference in smb2_ioctl_query_info()" + }, "CVE-2020-26556": { "cmt_msg": "" }, @@ -69251,135 +70276,21 @@ "CVE-2019-20794": { "cmt_msg": "" }, - "CVE-2021-0920": { - "cmt_msg": "af_unix: fix garbage collect vs MSG_PEEK" - }, - "CVE-2020-35501": { + "CVE-2020-26559": { "cmt_msg": "" }, - "CVE-2022-0168": { - "cmt_msg": "cifs: fix NULL ptr dereference in smb2_ioctl_query_info()" - }, - "CVE-2021-45095": { - "cmt_msg": "phonet: refcount leak in pep_sock_accep" - }, - "CVE-2022-28388": { - "cmt_msg": "can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path" - }, - "CVE-2021-3491": { - "cmt_msg": "io_uring: truncate lengths larger than MAX_RW_COUNT on provide buffers" - }, - "CVE-2022-0001": { - "cmt_msg": "x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE" - }, - "CVE-2022-29156": { - "cmt_msg": "RDMA/rtrs-clt: Fix possible double free in error case" - }, - "CVE-2022-0002": { - "cmt_msg": "x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE" - }, - "CVE-2020-28374": { - "cmt_msg": "scsi: target: Fix XCOPY NAA identifier lookup" - }, - "CVE-2019-19378": { + "CVE-2018-1121": { "cmt_msg": "" }, - "CVE-2022-1016": { - "cmt_msg": "netfilter: nf_tables: initialize registers in nft_do_chain()" - }, - "CVE-2020-24587": { - "cmt_msg": "mac80211: prevent mixed key and fragment cache attacks" - }, - "CVE-2020-24586": { - "cmt_msg": "mac80211: prevent mixed key and fragment cache attacks" - }, - "CVE-2022-0995": { - "cmt_msg": "watch_queue: Fix filter limit check" - }, - "CVE-2022-0185": { - "cmt_msg": "vfs: fs_context: fix up param length parsing in legacy_parse_param" - }, - "CVE-2022-20008": { - "cmt_msg": "mmc: block: fix read single on recovery logic" - }, - "CVE-2021-0129": { - "cmt_msg": "Bluetooth: SMP: Fail if remote and local public keys are identical" - }, - "CVE-2020-24588": { - "cmt_msg": "cfg80211: mitigate A-MSDU aggregation attacks" - }, - "CVE-2021-39698": { - "cmt_msg": "wait: add wake_up_pollfree()" - }, "CVE-2019-15794": { "cmt_msg": "ovl: fix reference counting in ovl_mmap error path" }, - "CVE-2021-3444": { - "cmt_msg": "bpf: Fix truncation handling for mod32 dst reg wrt zero" - }, - "CVE-2022-0850": { - "cmt_msg": "ext4: fix kernel infoleak via ext4_extent_header" - }, "CVE-2022-0644": { "cmt_msg": "vfs: check fd has read access in kernel_read_file_from_fd()" }, - "CVE-2021-3759": { - "cmt_msg": "memcg: enable accounting of ipc resources" - }, - "CVE-2020-27820": { - "cmt_msg": "drm/nouveau: use drm_dev_unplug() during device removal" - }, - "CVE-2021-3612": { - "cmt_msg": "Input: joydev - prevent potential read overflow in ioctl" - }, - "CVE-2020-36158": { - "cmt_msg": "mwifiex: Fix possible buffer overflows in mwifiex_cmd_802_11_ad_hoc_start" - }, - "CVE-2020-24503": { - "cmt_msg": "" - }, - "CVE-2020-24502": { - "cmt_msg": "" - }, - "CVE-2019-19449": { - "cmt_msg": "f2fs: fix to do sanity check on segment/section count" - }, - "CVE-2020-26558": { - "cmt_msg": "Bluetooth: SMP: Fail if remote and local public keys are identical" - }, - "CVE-2021-3753": { - "cmt_msg": "vt_kdsetmode: extend console locking" - }, - "CVE-2020-24504": { - "cmt_msg": "ice: create scheduler aggregator node config and move VSIs" - }, - "CVE-2020-26541": { - "cmt_msg": "certs: Add EFI_CERT_X509_GUID support for dbx entries" - }, - "CVE-2020-11725": { - "cmt_msg": "" - }, - "CVE-2020-26559": { - "cmt_msg": "" - }, "CVE-2022-0382": { "cmt_msg": "net ticp:fix a kernel-infoleak in __tipc_sendmsg()" }, - "CVE-2021-43389": { - "cmt_msg": "isdn: cpai: check ctr->cnr to avoid array index out of bound" - }, - "CVE-2021-39633": { - "cmt_msg": "ip_gre: add validation for csum_start" - }, - "CVE-2021-33061": { - "cmt_msg": "ixgbe: add improvement for MDD response functionality" - }, - "CVE-2021-42252": { - "cmt_msg": "soc: aspeed: lpc-ctrl: Fix boundary check for mmap" - }, - "CVE-2021-35477": { - "cmt_msg": "bpf: Introduce BPF nospec instruction for mitigating Spectre v4" - }, "CVE-2020-25672": { "cmt_msg": "nfc: fix memory leak in llcp_sock_connect()" }, @@ -69395,66 +70306,27 @@ "CVE-2022-0998": { "cmt_msg": "vdpa: clean up get_config_size ret value handling" }, - "CVE-2021-3864": { - "cmt_msg": "" - }, - "CVE-2021-41864": { - "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" - }, "CVE-2019-19814": { "cmt_msg": "" }, - "CVE-2022-27950": { - "cmt_msg": "HID: elo: fix memory leak in elo_probe" - }, "CVE-2022-1015": { "cmt_msg": "netfilter: nf_tables: validate registers coming from userspace." }, - "CVE-2022-1652": { - "cmt_msg": "" - }, - "CVE-2022-1651": { - "cmt_msg": "virt: acrn: fix a memory leak in acrn_dev_ioctl()" - }, - "CVE-2021-39648": { - "cmt_msg": "usb: gadget: configfs: Fix use-after-free issue with udc_name" + "CVE-2022-1016": { + "cmt_msg": "netfilter: nf_tables: initialize registers in nft_do_chain()" }, "CVE-2022-1011": { "cmt_msg": "fuse: fix pipe buffer lifetime for direct_io" }, - "CVE-2021-37576": { - "cmt_msg": "KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow" + "CVE-2021-3659": { + "cmt_msg": "net: mac802154: Fix general protection fault" }, - "CVE-2020-29568": { - "cmt_msg": "xen/xenbus: Allow watches discard events before queueing" - }, - "CVE-2020-29569": { - "cmt_msg": "xen-blkback: set ring->xenblkd to NULL after kthread_stop()" - }, - "CVE-2021-28688": { - "cmt_msg": "xen-blkback: don't leak persistent grants from xen_blkbk_map()" - }, - "CVE-2022-1966": { - "cmt_msg": "netfilter: nf_tables: disallow non-stateful expression in sets earlier" - }, - "CVE-2021-39686": { - "cmt_msg": "binder: use euid from cred instead of using task" - }, - "CVE-2021-39685": { - "cmt_msg": "USB: gadget: detect too-big endpoint 0 requests" - }, - "CVE-2021-43056": { - "cmt_msg": "KVM: PPC: Book3S HV: Make idle_kvm_start_guest() return 0 if it went to guest" - }, - "CVE-2021-44879": { - "cmt_msg": "f2fs: fix to do sanity check on inode type during garbage collection" + "CVE-2022-1012": { + "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation" }, "CVE-2021-26934": { "cmt_msg": "" }, - "CVE-2021-43976": { - "cmt_msg": "mwifiex: Fix skb_over_panic in mwifiex_usb_recv()" - }, "CVE-2021-26931": { "cmt_msg": "xen-blkback: don't \"handle\" error by BUG()" }, @@ -69464,149 +70336,35 @@ "CVE-2021-26932": { "cmt_msg": "Xen/x86: don't bail early from clear_foreign_p2m_mapping()" }, - "CVE-2022-1789": { - "cmt_msg": "KVM: x86/mmu: fix NULL pointer dereference on guest INVPCID" + "CVE-2022-0492": { + "cmt_msg": "cgroup-v1: Require capabilities to set release_agent" }, - "CVE-2021-38206": { - "cmt_msg": "mac80211: Fix NULL ptr deref for injected rate info" - }, - "CVE-2020-27815": { - "cmt_msg": "jfs: Fix array index bounds check in dbAdjTree" - }, - "CVE-2016-8660": { - "cmt_msg": "" - }, - "CVE-2021-43975": { - "cmt_msg": "atlantic: Fix OOB read and write in hw_atl_utils_fw_rpc_wait" - }, - "CVE-2021-3669": { - "cmt_msg": "ipc: replace costly bailout check in sysvipc_find_ipc()" - }, - "CVE-2021-3744": { - "cmt_msg": "crypto: ccp - fix resource leaks in ccp_run_aes_gcm_cmd()" - }, - "CVE-2022-23041": { - "cmt_msg": "xen/9p: use alloc/free_pages_exact()" - }, - "CVE-2021-30002": { - "cmt_msg": "media: v4l: ioctl: Fix memory leak in video_usercopy" - }, - "CVE-2021-3743": { - "cmt_msg": "net: qrtr: fix OOB Read in qrtr_endpoint_post" + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" }, - "CVE-2022-1786": { - "cmt_msg": "io_uring: remove io_identity" - }, - "CVE-2021-0941": { - "cmt_msg": "bpf: Remove MTU check in __bpf_skb_max_len" - }, - "CVE-2022-23222": { - "cmt_msg": "bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL" - }, - "CVE-2020-15802": { - "cmt_msg": "" - }, "CVE-2008-2544": { "cmt_msg": "" }, - "CVE-2022-1204": { - "cmt_msg": "ax25: Fix refcount leaks caused by ax25_cb_del()" - }, "CVE-2021-3178": { "cmt_msg": "nfsd4: readdirplus shouldn't return parent of export" }, "CVE-2022-28796": { "cmt_msg": "jbd2: fix use-after-free of transaction_t race" }, - "CVE-2021-34556": { - "cmt_msg": "bpf: Introduce BPF nospec instruction for mitigating Spectre v4" - }, - "CVE-2021-31440": { - "cmt_msg": "bpf: Fix propagation of 32 bit unsigned bounds from 64 bit bounds" - }, - "CVE-2022-1353": { - "cmt_msg": "af_key: add __GFP_ZERO flag for compose_sadb_supported in function pfkey_register" - }, - "CVE-2021-46283": { - "cmt_msg": "netfilter: nf_tables: initialize set before expression setup" - }, - "CVE-2021-28714": { - "cmt_msg": "xen/netback: fix rx queue stall detection" - }, - "CVE-2021-4135": { - "cmt_msg": "netdevsim: Zero-initialize memory for new map's value in function nsim_bpf_map_alloc" - }, - "CVE-2021-28038": { - "cmt_msg": "Xen/gnttab: handle p2m update errors on a per-slot basis" - }, - "CVE-2018-1121": { - "cmt_msg": "" - }, - "CVE-2019-15239": { - "cmt_msg": "unknown" - }, - "CVE-2022-23040": { - "cmt_msg": "xen/xenbus: don't let xenbus_grant_ring() remove grants in error case" - }, - "CVE-2022-29968": { - "cmt_msg": "io_uring: fix uninitialized field in rw io_kiocb" - }, "CVE-2022-0330": { "cmt_msg": "drm/i915: Flush TLBs before releasing backing store" }, "CVE-2007-3719": { "cmt_msg": "" }, - "CVE-2021-31829": { - "cmt_msg": "bpf: Fix masking negation logic upon negative dst register" + "CVE-2021-45402": { + "cmt_msg": "bpf: Fix signed bounds propagation after mov32" }, - "CVE-2021-22543": { - "cmt_msg": "KVM: do not allow mapping valid but non-reference-counted pages" - }, - "CVE-2021-3501": { - "cmt_msg": "KVM: VMX: Don't use vcpu->run->internal.ndata as an array index" - }, - "CVE-2021-3348": { - "cmt_msg": "nbd: freeze the queue while we're adding connections" - }, - "CVE-2021-3752": { - "cmt_msg": "Bluetooth: fix use-after-free error in lock_sock_nested()" - }, - "CVE-2021-3506": { - "cmt_msg": "f2fs: fix to avoid out-of-bounds memory access" - }, - "CVE-2022-1247": { - "cmt_msg": "" - }, - "CVE-2021-3347": { - "cmt_msg": "futex: Ensure the correct return value from futex_lock_pi()" - }, - "CVE-2020-26145": { - "cmt_msg": "ath10k: drop fragments with multicast DA for PCIe" - }, - "CVE-2022-0171": { - "cmt_msg": "" - }, - "CVE-2020-26147": { - "cmt_msg": "mac80211: assure all fragments are encrypted" - }, - "CVE-2010-4563": { - "cmt_msg": "" - }, - "CVE-2020-26140": { - "cmt_msg": "" - }, - "CVE-2020-26143": { - "cmt_msg": "" - }, - "CVE-2020-26142": { - "cmt_msg": "" - }, - "CVE-2021-3483": { - "cmt_msg": "firewire: nosy: Fix a use-after-free bug in nosy_ioctl()" + "CVE-2022-28893": { + "cmt_msg": "SUNRPC: Ensure we flush any closed sockets before xs_xprt_free()" }, "CVE-2021-3772": { "cmt_msg": "sctp: use init_tag from inithdr for ABORT chunk" @@ -69614,20 +70372,11 @@ "CVE-2021-3679": { "cmt_msg": "tracing: Fix bug in rb_per_cpu_empty() that might cause deadloop." }, - "CVE-2022-1280": { - "cmt_msg": "drm: avoid circular locks in drm_mode_getconnector" + "CVE-2021-34556": { + "cmt_msg": "bpf: Introduce BPF nospec instruction for mitigating Spectre v4" }, - "CVE-2021-3587": { - "cmt_msg": "nfc: fix NULL ptr dereference in llcp_sock_getname() after failed connect" - }, - "CVE-2021-44733": { - "cmt_msg": "tee: handle lookup of shm with reference count 0" - }, - "CVE-2021-28715": { - "cmt_msg": "xen/netback: don't queue unlimited number of packages" - }, - "CVE-2021-20268": { - "cmt_msg": "bpf: Fix signed_{sub,add32}_overflows type handling" + "CVE-2021-28714": { + "cmt_msg": "xen/netback: fix rx queue stall detection" }, "CVE-2021-28713": { "cmt_msg": "xen/console: harden hvc_xen against event channel storms" @@ -69638,26 +70387,14 @@ "CVE-2021-28711": { "cmt_msg": "xen/blkfront: harden blkfront against event channel storms" }, - "CVE-2021-4157": { - "cmt_msg": "pNFS/flexfiles: fix incorrect size check in decode_nfs_fh()" - }, - "CVE-2021-3489": { - "cmt_msg": "bpf, ringbuf: Deny reserve of buffers larger than ringbuf" - }, - "CVE-2022-25258": { - "cmt_msg": "USB: gadget: validate interface OS descriptor requests" + "CVE-2022-1247": { + "cmt_msg": "" }, "CVE-2022-23960": { "cmt_msg": "ARM: report Spectre v2 status through sysfs" }, - "CVE-2022-28389": { - "cmt_msg": "can: mcba_usb: mcba_usb_start_xmit(): fix double dev_kfree_skb in error path" - }, - "CVE-2022-1734": { - "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs" - }, - "CVE-2021-38300": { - "cmt_msg": "bpf, mips: Validate conditional branch offsets" + "CVE-2021-4154": { + "cmt_msg": "cgroup: verify that source is a string" }, "CVE-2021-39656": { "cmt_msg": "configfs: fix a use-after-free in __configfs_open_file" @@ -69665,65 +70402,224 @@ "CVE-2021-39657": { "cmt_msg": "scsi: ufs: Correct the LUN used in eh_device_reset_handler() callback" }, - "CVE-2022-0492": { - "cmt_msg": "cgroup-v1: Require capabilities to set release_agent" + "CVE-2021-34866": { + "cmt_msg": "bpf: Fix ringbuf helper function compatibility" }, - "CVE-2021-22600": { - "cmt_msg": "net/packet: rx_owner_map depends on pg_vec" + "CVE-2021-34981": { + "cmt_msg": "Bluetooth: cmtp: fix file refcount when cmtp_attach_device fails" }, - "CVE-2020-10708": { + "CVE-2013-7445": { "cmt_msg": "" }, - "CVE-2022-0322": { - "cmt_msg": "sctp: account stream padding length for reconf chunk" + "CVE-2022-28390": { + "cmt_msg": "can: ems_usb: ems_usb_start_xmit(): fix double dev_kfree_skb() in error path" }, - "CVE-2021-4023": { - "cmt_msg": "io-wq: fix cancellation on create-worker failure" + "CVE-2021-3653": { + "cmt_msg": "KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653)" }, - "CVE-2021-22555": { - "cmt_msg": "netfilter: x_tables: fix compat match/target pad out-of-bound write" + "CVE-2022-1158": { + "cmt_msg": "KVM: x86/mmu: do compare-and-exchange of gPTE via the user address" }, - "CVE-2021-32399": { - "cmt_msg": "bluetooth: eliminate the potential race condition when removing the HCI controller" + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" }, - "CVE-2017-13693": { - "cmt_msg": "" + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" }, - "CVE-2021-0399": { + "CVE-2022-28389": { + "cmt_msg": "can: mcba_usb: mcba_usb_start_xmit(): fix double dev_kfree_skb in error path" + }, + "CVE-2022-28388": { + "cmt_msg": "can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path" + }, + "CVE-2020-12362": { + "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" + }, + "CVE-2020-12363": { + "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" + }, + "CVE-2020-12364": { + "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" + }, + "CVE-2022-0500": { + "cmt_msg": "bpf: Introduce MEM_RDONLY flag" + }, + "CVE-2020-25639": { + "cmt_msg": "drm/nouveau: bail out of nouveau_channel_new if channel init fails" + }, + "CVE-2021-4001": { + "cmt_msg": "bpf: Fix toctou on read-only map's constant scalar tracking" + }, + "CVE-2021-4002": { + "cmt_msg": "hugetlbfs: flush TLBs correctly after huge_pmd_unshare" + }, + "CVE-2022-1055": { + "cmt_msg": "net: sched: fix use-after-free in tc_new_tfilter()" + }, + "CVE-2022-20008": { + "cmt_msg": "mmc: block: fix read single on recovery logic" + }, + "CVE-2021-31440": { + "cmt_msg": "bpf: Fix propagation of 32 bit unsigned bounds from 64 bit bounds" + }, + "CVE-2019-15290": { "cmt_msg": "" }, "CVE-2022-0617": { "cmt_msg": "udf: Fix NULL ptr deref when converting from inline format" }, - "CVE-2022-1943": { - "cmt_msg": "udf: Avoid using stale lengthOfImpUse" + "CVE-2022-26878": { + "cmt_msg": "" }, - "CVE-2022-23039": { - "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" + "CVE-2018-12930": { + "cmt_msg": "" }, - "CVE-2021-34866": { - "cmt_msg": "bpf: Fix ringbuf helper function compatibility" + "CVE-2018-12931": { + "cmt_msg": "" + }, + "CVE-2021-33098": { + "cmt_msg": "ixgbe: fix large MTU request from VF" + }, + "CVE-2022-0185": { + "cmt_msg": "vfs: fs_context: fix up param length parsing in legacy_parse_param" + }, + "CVE-2021-28971": { + "cmt_msg": "perf/x86/intel: Fix a crash caused by zero PEBS status" + }, + "CVE-2022-22942": { + "cmt_msg": "drm/vmwgfx: Fix stale file descriptors on failed usercopy" + }, + "CVE-2021-3739": { + "cmt_msg": "btrfs: fix NULL pointer dereference when deleting device by invalid id" + }, + "CVE-2021-3732": { + "cmt_msg": "ovl: prevent private clone if bind mount is not allowed" + }, + "CVE-2021-35039": { + "cmt_msg": "module: limit enabling module.sig_enforce" + }, + "CVE-2019-0146": { + "cmt_msg": "" + }, + "CVE-2020-26139": { + "cmt_msg": "mac80211: do not accept/forward invalid EAPOL frames" + }, + "CVE-2021-3609": { + "cmt_msg": "can: bcm: delay release of struct bcm_op after synchronize_rcu()" + }, + "CVE-2022-0847": { + "cmt_msg": "lib/iov_iter: initialize \"flags\" in new pipe_buffer" + }, + "CVE-2021-3600": { + "cmt_msg": "bpf: Fix 32 bit src register truncation on div/mod" + }, + "CVE-2021-23133": { + "cmt_msg": "net/sctp: fix race condition in sctp_destroy_sock" + }, + "CVE-2021-0920": { + "cmt_msg": "af_unix: fix garbage collect vs MSG_PEEK" + }, + "CVE-2020-28374": { + "cmt_msg": "scsi: target: Fix XCOPY NAA identifier lookup" + }, + "CVE-2020-27820": { + "cmt_msg": "drm/nouveau: use drm_dev_unplug() during device removal" + }, + "CVE-2020-26558": { + "cmt_msg": "Bluetooth: SMP: Fail if remote and local public keys are identical" + }, + "CVE-2020-26541": { + "cmt_msg": "certs: Add EFI_CERT_X509_GUID support for dbx entries" + }, + "CVE-2020-26143": { + "cmt_msg": "" + }, + "CVE-2021-33061": { + "cmt_msg": "ixgbe: add improvement for MDD response functionality" + }, + "CVE-2021-3864": { + "cmt_msg": "" + }, + "CVE-2022-27950": { + "cmt_msg": "HID: elo: fix memory leak in elo_probe" + }, + "CVE-2022-1652": { + "cmt_msg": "" + }, + "CVE-2022-1651": { + "cmt_msg": "virt: acrn: fix a memory leak in acrn_dev_ioctl()" + }, + "CVE-2020-29568": { + "cmt_msg": "xen/xenbus: Allow watches discard events before queueing" + }, + "CVE-2020-29569": { + "cmt_msg": "xen-blkback: set ring->xenblkd to NULL after kthread_stop()" + }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, + "CVE-2022-1789": { + "cmt_msg": "KVM: x86/mmu: fix NULL pointer dereference on guest INVPCID" + }, + "CVE-2016-8660": { + "cmt_msg": "" + }, + "CVE-2022-1786": { + "cmt_msg": "io_uring: remove io_identity" + }, + "CVE-2008-4609": { + "cmt_msg": "" + }, + "CVE-2022-0435": { + "cmt_msg": "tipc: improve size validations for received domain records" + }, + "CVE-2021-4135": { + "cmt_msg": "netdevsim: Zero-initialize memory for new map's value in function nsim_bpf_map_alloc" + }, + "CVE-2019-15239": { + "cmt_msg": "unknown" + }, + "CVE-2021-4037": { + "cmt_msg": "xfs: fix up non-directory creation in SGID directories" + }, + "CVE-2021-22543": { + "cmt_msg": "KVM: do not allow mapping valid but non-reference-counted pages" + }, + "CVE-2021-3348": { + "cmt_msg": "nbd: freeze the queue while we're adding connections" + }, + "CVE-2021-3347": { + "cmt_msg": "futex: Ensure the correct return value from futex_lock_pi()" + }, + "CVE-2022-1966": { + "cmt_msg": "netfilter: nf_tables: disallow non-stateful expression in sets earlier" + }, + "CVE-2021-3587": { + "cmt_msg": "nfc: fix NULL ptr dereference in llcp_sock_getname() after failed connect" + }, + "CVE-2021-44733": { + "cmt_msg": "tee: handle lookup of shm with reference count 0" + }, + "CVE-2021-20268": { + "cmt_msg": "bpf: Fix signed_{sub,add32}_overflows type handling" + }, + "CVE-2021-22600": { + "cmt_msg": "net/packet: rx_owner_map depends on pg_vec" + }, + "CVE-2022-0322": { + "cmt_msg": "sctp: account stream padding length for reconf chunk" + }, + "CVE-2017-13693": { + "cmt_msg": "" }, "CVE-2017-13694": { "cmt_msg": "" }, - "CVE-2020-36516": { - "cmt_msg": "" + "CVE-2021-4149": { + "cmt_msg": "btrfs: unlock newly allocated extent buffer after error" }, - "CVE-2021-34981": { - "cmt_msg": "Bluetooth: cmtp: fix file refcount when cmtp_attach_device fails" - }, - "CVE-2022-23037": { - "cmt_msg": "xen/netfront: don't use gnttab_query_foreign_access() for mapped status" - }, - "CVE-2021-28039": { - "cmt_msg": "xen: fix p2m size in dom0 for disabled memory hotplug case" - }, - "CVE-2012-4542": { - "cmt_msg": "" - }, - "CVE-2022-1729": { - "cmt_msg": "perf: Fix sys_perf_event_open() race against self" + "CVE-2021-4148": { + "cmt_msg": "mm: khugepaged: skip huge page collapse for special files" }, "CVE-2021-3640": { "cmt_msg": "Bluetooth: sco: Fix lock_sock() blockage by memcpy_from_msg()" @@ -69734,51 +70630,6 @@ "CVE-2021-3760": { "cmt_msg": "nfc: nci: fix the UAF of rf_conn_info object" }, - "CVE-2022-1462": { - "cmt_msg": "" - }, - "CVE-2021-3573": { - "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" - }, - "CVE-2022-1679": { - "cmt_msg": "" - }, - "CVE-2021-38160": { - "cmt_msg": "virtio_console: Assure used length from device is limited" - }, - "CVE-2021-42008": { - "cmt_msg": "net: 6pack: fix slab-out-of-bounds in decode_data" - }, - "CVE-2022-1972": { - "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" - }, - "CVE-2013-7445": { - "cmt_msg": "" - }, - "CVE-2021-38166": { - "cmt_msg": "bpf: Fix integer overflow involving bucket_size" - }, - "CVE-2022-28390": { - "cmt_msg": "can: ems_usb: ems_usb_start_xmit(): fix double dev_kfree_skb() in error path" - }, - "CVE-2021-3490": { - "cmt_msg": "bpf: Fix alu32 const subreg bound tracking on bitwise operations" - }, - "CVE-2021-28691": { - "cmt_msg": "xen-netback: take a reference to the RX task thread" - }, - "CVE-2021-31916": { - "cmt_msg": "dm ioctl: fix out of bounds array access when no devices" - }, - "CVE-2005-3660": { - "cmt_msg": "" - }, - "CVE-2021-28952": { - "cmt_msg": "ASoC: qcom: sdm845: Fix array out of bounds access" - }, - "CVE-2021-33135": { - "cmt_msg": "" - }, "CVE-2022-1508": { "cmt_msg": "io_uring: reexpand under-reexpanded iters" }, @@ -69791,20 +70642,11 @@ "CVE-2021-29266": { "cmt_msg": "vhost-vdpa: fix use-after-free of v->config_ctx" }, - "CVE-2021-3655": { - "cmt_msg": "sctp: validate from_addr_param return" + "CVE-2021-39648": { + "cmt_msg": "usb: gadget: configfs: Fix use-after-free issue with udc_name" }, - "CVE-2021-42739": { - "cmt_msg": "media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt()" - }, - "CVE-2021-33034": { - "cmt_msg": "Bluetooth: verify AMP hci_chan before amp_destroy" - }, - "CVE-2021-33033": { - "cmt_msg": "cipso,calipso: resolve a number of problems with the DOI refcounts" - }, - "CVE-2022-0286": { - "cmt_msg": "bonding: fix null dereference in bond_ipsec_add_sa()" + "CVE-2021-43056": { + "cmt_msg": "KVM: PPC: Book3S HV: Make idle_kvm_start_guest() return 0 if it went to guest" }, "CVE-2021-21781": { "cmt_msg": "ARM: ensure the signal page contains defined contents" @@ -69812,11 +70654,260 @@ "CVE-2021-0512": { "cmt_msg": "HID: make arrays usage and value to be the same" }, - "CVE-2021-3659": { - "cmt_msg": "net: mac802154: Fix general protection fault" + "CVE-2020-0347": { + "cmt_msg": "" }, - "CVE-2021-4154": { - "cmt_msg": "cgroup: verify that source is a string" + "CVE-2021-40490": { + "cmt_msg": "ext4: fix race writing to an inline_data file while its xattrs are changing" + }, + "CVE-2021-33909": { + "cmt_msg": "seq_file: disallow extremely large seq buffer allocations" + }, + "CVE-2019-12456": { + "cmt_msg": "" + }, + "CVE-2021-29646": { + "cmt_msg": "tipc: better validate user input in tipc_nl_retrieve_key()" + }, + "CVE-2021-29647": { + "cmt_msg": "net: qrtr: fix a kernel-infoleak in qrtr_recvmsg()" + }, + "CVE-2022-0742": { + "cmt_msg": "ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report()" + }, + "CVE-2022-0854": { + "cmt_msg": "swiotlb: rework \"fix info leak with DMA_FROM_DEVICE\"" + }, + "CVE-2021-45469": { + "cmt_msg": "f2fs: fix to do sanity check on last xattr entry in __f2fs_setxattr()" + }, + "CVE-2022-1184": { + "cmt_msg": "" + }, + "CVE-2019-15902": { + "cmt_msg": "unknown" + }, + "CVE-2021-33624": { + "cmt_msg": "bpf: Inherit expanded/patched seen count from old aux data" + }, + "CVE-2021-27365": { + "cmt_msg": "scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE" + }, + "CVE-2021-3752": { + "cmt_msg": "Bluetooth: fix use-after-free error in lock_sock_nested()" + }, + "CVE-2021-27363": { + "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" + }, + "CVE-2018-17977": { + "cmt_msg": "" + }, + "CVE-2010-5321": { + "cmt_msg": "" + }, + "CVE-2021-20322": { + "cmt_msg": "ipv6: make exception cache less predictible" + }, + "CVE-2021-20320": { + "cmt_msg": "s390/bpf: Fix optimizing out zero-extensions" + }, + "CVE-2021-20321": { + "cmt_msg": "ovl: fix missing negative dentry check in ovl_rename()" + }, + "CVE-2022-1043": { + "cmt_msg": "io_uring: fix xa_alloc_cycle() error return value check" + }, + "CVE-2022-1048": { + "cmt_msg": "ALSA: pcm: Fix races among concurrent hw_params and hw_free calls" + }, + "CVE-2022-29968": { + "cmt_msg": "io_uring: fix uninitialized field in rw io_kiocb" + }, + "CVE-2021-3542": { + "cmt_msg": "" + }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, + "CVE-2022-23041": { + "cmt_msg": "xen/9p: use alloc/free_pages_exact()" + }, + "CVE-2022-23040": { + "cmt_msg": "xen/xenbus: don't let xenbus_grant_ring() remove grants in error case" + }, + "CVE-2022-23042": { + "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" + }, + "CVE-2018-12929": { + "cmt_msg": "" + }, + "CVE-2018-12928": { + "cmt_msg": "" + }, + "CVE-2021-28972": { + "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" + }, + "CVE-2020-10708": { + "cmt_msg": "" + }, + "CVE-2022-0400": { + "cmt_msg": "" + }, + "CVE-2021-0707": { + "cmt_msg": "dmabuf: fix use-after-free of dmabuf's file->f_inode" + }, + "CVE-2022-26966": { + "cmt_msg": "sr9700: sanity check for packet length" + }, + "CVE-2021-42739": { + "cmt_msg": "media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt()" + }, + "CVE-2021-37159": { + "cmt_msg": "usb: hso: fix error handling code of hso_create_net_device" + }, + "CVE-2022-25265": { + "cmt_msg": "" + }, + "CVE-2019-19378": { + "cmt_msg": "" + }, + "CVE-2021-28691": { + "cmt_msg": "xen-netback: take a reference to the RX task thread" + }, + "CVE-2021-39698": { + "cmt_msg": "wait: add wake_up_pollfree()" + }, + "CVE-2022-0850": { + "cmt_msg": "ext4: fix kernel infoleak via ext4_extent_header" + }, + "CVE-2021-3759": { + "cmt_msg": "memcg: enable accounting of ipc resources" + }, + "CVE-2021-4197": { + "cmt_msg": "cgroup: Use open-time credentials for process migraton perm checks" + }, + "CVE-2021-3612": { + "cmt_msg": "Input: joydev - prevent potential read overflow in ioctl" + }, + "CVE-2020-24503": { + "cmt_msg": "" + }, + "CVE-2020-24502": { + "cmt_msg": "" + }, + "CVE-2019-19449": { + "cmt_msg": "f2fs: fix to do sanity check on segment/section count" + }, + "CVE-2021-3753": { + "cmt_msg": "vt_kdsetmode: extend console locking" + }, + "CVE-2020-24504": { + "cmt_msg": "ice: create scheduler aggregator node config and move VSIs" + }, + "CVE-2020-11725": { + "cmt_msg": "" + }, + "CVE-2021-0937": { + "cmt_msg": "netfilter: x_tables: fix compat match/target pad out-of-bound write" + }, + "CVE-2022-1263": { + "cmt_msg": "KVM: avoid NULL pointer dereference in kvm_dirty_ring_push" + }, + "CVE-2021-35477": { + "cmt_msg": "bpf: Introduce BPF nospec instruction for mitigating Spectre v4" + }, + "CVE-2021-41864": { + "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" + }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, + "CVE-2022-1852": { + "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" + }, + "CVE-2021-37576": { + "cmt_msg": "KVM: PPC: Book3S: Fix H_RTAS rets buffer overflow" + }, + "CVE-2020-27815": { + "cmt_msg": "jfs: Fix array index bounds check in dbAdjTree" + }, + "CVE-2022-1462": { + "cmt_msg": "" + }, + "CVE-2022-1729": { + "cmt_msg": "perf: Fix sys_perf_event_open() race against self" + }, + "CVE-2021-28038": { + "cmt_msg": "Xen/gnttab: handle p2m update errors on a per-slot basis" + }, + "CVE-2021-28039": { + "cmt_msg": "xen: fix p2m size in dom0 for disabled memory hotplug case" + }, + "CVE-2021-31829": { + "cmt_msg": "bpf: Fix masking negation logic upon negative dst register" + }, + "CVE-2021-3501": { + "cmt_msg": "KVM: VMX: Don't use vcpu->run->internal.ndata as an array index" + }, + "CVE-2021-3506": { + "cmt_msg": "f2fs: fix to avoid out-of-bounds memory access" + }, + "CVE-2010-4563": { + "cmt_msg": "" + }, + "CVE-2021-3483": { + "cmt_msg": "firewire: nosy: Fix a use-after-free bug in nosy_ioctl()" + }, + "CVE-2022-29156": { + "cmt_msg": "RDMA/rtrs-clt: Fix possible double free in error case" + }, + "CVE-2021-3489": { + "cmt_msg": "bpf, ringbuf: Deny reserve of buffers larger than ringbuf" + }, + "CVE-2021-38300": { + "cmt_msg": "bpf, mips: Validate conditional branch offsets" + }, + "CVE-2022-24448": { + "cmt_msg": "NFSv4: Handle case where the lookup of a directory fails" + }, + "CVE-2021-4023": { + "cmt_msg": "io-wq: fix cancellation on create-worker failure" + }, + "CVE-2021-22555": { + "cmt_msg": "netfilter: x_tables: fix compat match/target pad out-of-bound write" + }, + "CVE-2021-0399": { + "cmt_msg": "" + }, + "CVE-2020-36516": { + "cmt_msg": "" + }, + "CVE-2012-4542": { + "cmt_msg": "" + }, + "CVE-2021-46283": { + "cmt_msg": "netfilter: nf_tables: initialize set before expression setup" + }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, + "CVE-2022-1972": { + "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" + }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, + "CVE-2021-31916": { + "cmt_msg": "dm ioctl: fix out of bounds array access when no devices" + }, + "CVE-2021-4157": { + "cmt_msg": "pNFS/flexfiles: fix incorrect size check in decode_nfs_fh()" + }, + "CVE-2022-25258": { + "cmt_msg": "USB: gadget: validate interface OS descriptor requests" }, "CVE-2021-4155": { "cmt_msg": "xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate" @@ -69824,9 +70915,6 @@ "CVE-2021-0695": { "cmt_msg": "" }, - "CVE-2008-4609": { - "cmt_msg": "" - }, "CVE-2021-4150": { "cmt_msg": "block: fix incorrect references to disk objects" }, @@ -69836,27 +70924,18 @@ "CVE-2021-28951": { "cmt_msg": "io_uring: ensure that SQPOLL thread is started for exit" }, - "CVE-2021-37159": { - "cmt_msg": "usb: hso: fix error handling code of hso_create_net_device" + "CVE-2021-26401": { + "cmt_msg": "x86/speculation: Use generic retpoline by default on AMD" }, - "CVE-2020-14304": { - "cmt_msg": "" + "CVE-2021-28952": { + "cmt_msg": "ASoC: qcom: sdm845: Fix array out of bounds access" }, - "CVE-2021-28660": { - "cmt_msg": "staging: rtl8188eu: prevent ->ssid overflow in rtw_wx_set_scan()" - }, - "CVE-2022-29581": { - "cmt_msg": "net/sched: cls_u32: fix netns refcount changes in u32_change()" - }, - "CVE-2021-3564": { - "cmt_msg": "Bluetooth: fix the erroneous flush_work() order" + "CVE-2021-3655": { + "cmt_msg": "sctp: validate from_addr_param return" }, "CVE-2021-3656": { "cmt_msg": "KVM: nSVM: always intercept VMLOAD/VMSAVE when nested (CVE-2021-3656)" }, - "CVE-2020-0347": { - "cmt_msg": "" - }, "CVE-2021-29154": { "cmt_msg": "bpf, x86: Validate computation of branch displacements for x86-64" }, @@ -69866,203 +70945,53 @@ "CVE-2021-3714": { "cmt_msg": "" }, - "CVE-2021-40490": { - "cmt_msg": "ext4: fix race writing to an inline_data file while its xattrs are changing" - }, - "CVE-2021-33909": { - "cmt_msg": "seq_file: disallow extremely large seq buffer allocations" - }, "CVE-2021-3896": { "cmt_msg": "isdn: cpai: check ctr->cnr to avoid array index out of bound" }, - "CVE-2019-12456": { - "cmt_msg": "" - }, - "CVE-2020-26560": { - "cmt_msg": "" - }, - "CVE-2021-29646": { - "cmt_msg": "tipc: better validate user input in tipc_nl_retrieve_key()" - }, - "CVE-2021-20320": { - "cmt_msg": "s390/bpf: Fix optimizing out zero-extensions" - }, - "CVE-2021-4197": { - "cmt_msg": "cgroup: Use open-time credentials for process migraton perm checks" - }, - "CVE-2020-12362": { - "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" - }, - "CVE-2020-12363": { - "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" - }, - "CVE-2021-20321": { - "cmt_msg": "ovl: fix missing negative dentry check in ovl_rename()" - }, - "CVE-2022-0742": { - "cmt_msg": "ipv6: fix skb drops in igmp6_event_query() and igmp6_event_report()" - }, - "CVE-2022-0854": { - "cmt_msg": "swiotlb: rework \"fix info leak with DMA_FROM_DEVICE\"" - }, - "CVE-2020-12364": { - "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" - }, - "CVE-2022-24959": { - "cmt_msg": "yam: fix a memory leak in yam_siocdevprivate()" - }, - "CVE-2022-0500": { - "cmt_msg": "bpf: Introduce MEM_RDONLY flag" - }, - "CVE-2020-25639": { - "cmt_msg": "drm/nouveau: bail out of nouveau_channel_new if channel init fails" - }, - "CVE-2022-1671": { - "cmt_msg": "rxrpc: fix some null-ptr-deref bugs in server_key.c" - }, - "CVE-2022-1852": { - "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" - }, - "CVE-2022-0435": { - "cmt_msg": "tipc: improve size validations for received domain records" - }, - "CVE-2022-28893": { - "cmt_msg": "SUNRPC: Ensure we flush any closed sockets before xs_xprt_free()" - }, - "CVE-2021-4001": { - "cmt_msg": "bpf: Fix toctou on read-only map's constant scalar tracking" - }, - "CVE-2021-4002": { - "cmt_msg": "hugetlbfs: flush TLBs correctly after huge_pmd_unshare" - }, - "CVE-2022-1055": { - "cmt_msg": "net: sched: fix use-after-free in tc_new_tfilter()" - }, - "CVE-2022-0480": { - "cmt_msg": "memcg: enable accounting for file lock caches" - }, - "CVE-2021-45469": { - "cmt_msg": "f2fs: fix to do sanity check on last xattr entry in __f2fs_setxattr()" - }, - "CVE-2022-1184": { - "cmt_msg": "" - }, - "CVE-2022-0516": { - "cmt_msg": "KVM: s390: Return error on SIDA memop on normal guest" - }, "CVE-2021-3894": { "cmt_msg": "sctp: account stream padding length for reconf chunk" }, - "CVE-2022-1836": { - "cmt_msg": "floppy: disable FDRAWCMD by default" - }, - "CVE-2021-28964": { - "cmt_msg": "btrfs: fix race when cloning extent buffer during rewind of an old root" - }, - "CVE-2021-4203": { - "cmt_msg": "af_unix: fix races in sk_peer_pid and sk_peer_cred accesses" - }, - "CVE-2020-26141": { - "cmt_msg": "ath10k: Fix TKIP Michael MIC verification for PCIe" - }, - "CVE-2022-25265": { - "cmt_msg": "" - }, - "CVE-2022-1199": { - "cmt_msg": "ax25: Fix NULL pointer dereference in ax25_kill_by_device" - }, "CVE-2021-3892": { "cmt_msg": "" }, - "CVE-2021-4083": { - "cmt_msg": "fget: check that the fd still exists after getting a ref to it" - }, - "CVE-2019-15902": { - "cmt_msg": "unknown" - }, - "CVE-2022-28356": { - "cmt_msg": "llc: fix netdevice reference leaks in llc_ui_bind()" - }, - "CVE-2021-29647": { - "cmt_msg": "net: qrtr: fix a kernel-infoleak in qrtr_recvmsg()" + "CVE-2021-39633": { + "cmt_msg": "ip_gre: add validation for csum_start" }, "CVE-2022-27223": { "cmt_msg": "USB: gadget: validate endpoint index for xilinx udc" }, - "CVE-2019-15290": { - "cmt_msg": "" + "CVE-2022-24958": { + "cmt_msg": "usb: gadget: don't release an existing dev->buf" }, - "CVE-2022-0487": { - "cmt_msg": "moxart: fix potential use-after-free on remove path" + "CVE-2022-24959": { + "cmt_msg": "yam: fix a memory leak in yam_siocdevprivate()" }, - "CVE-2021-33624": { - "cmt_msg": "bpf: Inherit expanded/patched seen count from old aux data" + "CVE-2022-25375": { + "cmt_msg": "usb: gadget: rndis: check size of RNDIS_MSG_SET command" }, - "CVE-2022-24448": { - "cmt_msg": "NFSv4: Handle case where the lookup of a directory fails" + "CVE-2021-45486": { + "cmt_msg": "inet: use bigger hash table for IP ID generation" + }, + "CVE-2022-23222": { + "cmt_msg": "bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL" }, "CVE-2021-29650": { "cmt_msg": "netfilter: x_tables: Use correct memory barriers." }, - "CVE-2021-27365": { - "cmt_msg": "scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE" + "CVE-2022-1353": { + "cmt_msg": "af_key: add __GFP_ZERO flag for compose_sadb_supported in function pfkey_register" }, - "CVE-2021-27364": { - "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" - }, - "CVE-2021-27363": { - "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" - }, - "CVE-2022-23036": { - "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" - }, - "CVE-2022-27666": { - "cmt_msg": "esp: Fix possible buffer overflow in ESP transformation" - }, - "CVE-2018-17977": { - "cmt_msg": "" - }, - "CVE-2022-26878": { - "cmt_msg": "" - }, - "CVE-2022-29582": { - "cmt_msg": "io_uring: fix race between timeout flush and removal" - }, - "CVE-2022-23038": { - "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" - }, - "CVE-2021-4149": { - "cmt_msg": "btrfs: unlock newly allocated extent buffer after error" - }, - "CVE-2010-5321": { - "cmt_msg": "" - }, - "CVE-2021-20322": { - "cmt_msg": "ipv6: make exception cache less predictible" - }, - "CVE-2021-3653": { - "cmt_msg": "KVM: nSVM: avoid picking up unsupported bits from L2 in int_ctl (CVE-2021-3653)" - }, - "CVE-2018-12930": { - "cmt_msg": "" - }, - "CVE-2018-12931": { - "cmt_msg": "" + "CVE-2022-28356": { + "cmt_msg": "llc: fix netdevice reference leaks in llc_ui_bind()" }, "CVE-2020-16119": { "cmt_msg": "dccp: don't duplicate ccid when cloning dccp sock" }, - "CVE-2021-4148": { - "cmt_msg": "mm: khugepaged: skip huge page collapse for special files" - }, "CVE-2022-1198": { "cmt_msg": "drivers: hamradio: 6pack: fix UAF bug caused by mod_timer()" }, - "CVE-2022-1043": { - "cmt_msg": "io_uring: fix xa_alloc_cycle() error return value check" - }, - "CVE-2021-0937": { - "cmt_msg": "netfilter: x_tables: fix compat match/target pad out-of-bound write" + "CVE-2022-1199": { + "cmt_msg": "ax25: Fix NULL pointer dereference in ax25_kill_by_device" }, "CVE-2021-39801": { "cmt_msg": "" @@ -70076,91 +71005,34 @@ "CVE-2021-28375": { "cmt_msg": "misc: fastrpc: restrict user apps from sending kernel RPC messages" }, - "CVE-2022-1048": { - "cmt_msg": "ALSA: pcm: Fix races among concurrent hw_params and hw_free calls" - }, - "CVE-2020-36385": { - "cmt_msg": "RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy" - }, "CVE-2022-1195": { "cmt_msg": "hamradio: improve the incomplete fix to avoid NPD" }, "CVE-2021-26708": { "cmt_msg": "vsock: fix the race conditions in multi-transport support" }, - "CVE-2021-45868": { - "cmt_msg": "quota: check block number when reading the block in quota file" + "CVE-2021-4202": { + "cmt_msg": "NFC: reorganize the functions in nci_request" }, - "CVE-2021-33098": { - "cmt_msg": "ixgbe: fix large MTU request from VF" + "CVE-2021-4203": { + "cmt_msg": "af_unix: fix races in sk_peer_pid and sk_peer_cred accesses" }, - "CVE-2021-28972": { - "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" + "CVE-2021-4204": { + "cmt_msg": "bpf: Generalize check_ctx_reg for reuse with other types" }, - "CVE-2021-28971": { - "cmt_msg": "perf/x86/intel: Fix a crash caused by zero PEBS status" - }, - "CVE-2022-24958": { - "cmt_msg": "usb: gadget: don't release an existing dev->buf" - }, - "CVE-2022-22942": { - "cmt_msg": "drm/vmwgfx: Fix stale file descriptors on failed usercopy" - }, - "CVE-2021-3739": { - "cmt_msg": "btrfs: fix NULL pointer dereference when deleting device by invalid id" - }, - "CVE-2022-1116": { - "cmt_msg": "" - }, - "CVE-2021-3732": { - "cmt_msg": "ovl: prevent private clone if bind mount is not allowed" - }, - "CVE-2021-3542": { - "cmt_msg": "" - }, - "CVE-2022-25375": { - "cmt_msg": "usb: gadget: rndis: check size of RNDIS_MSG_SET command" - }, - "CVE-2021-4037": { - "cmt_msg": "xfs: fix up non-directory creation in SGID directories" - }, - "CVE-2022-1263": { - "cmt_msg": "KVM: avoid NULL pointer dereference in kvm_dirty_ring_push" + "CVE-2021-44879": { + "cmt_msg": "f2fs: fix to do sanity check on inode type during garbage collection" }, "CVE-2022-1516": { "cmt_msg": "net/x25: Fix null-ptr-deref caused by x25_disconnect" }, - "CVE-2022-1882": { - "cmt_msg": "" - }, - "CVE-2021-35039": { - "cmt_msg": "module: limit enabling module.sig_enforce" - }, - "CVE-2022-23042": { - "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" - }, - "CVE-2018-12929": { - "cmt_msg": "" - }, - "CVE-2018-12928": { - "cmt_msg": "" - }, - "CVE-2021-4202": { - "cmt_msg": "NFC: reorganize the functions in nci_request" - }, "CVE-2020-25220": { "cmt_msg": "" }, "CVE-2015-2877": { "cmt_msg": "" }, - "CVE-2021-45402": { - "cmt_msg": "bpf: Fix signed bounds propagation after mov32" - }, - "CVE-2022-1205": { - "cmt_msg": "ax25: Fix NULL pointer dereferences in ax25 timers" - }, - "CVE-2019-0146": { + "CVE-2022-0171": { "cmt_msg": "" }, "CVE-2019-16089": { @@ -70172,83 +71044,23 @@ "CVE-2021-38199": { "cmt_msg": "NFSv4: Initialise connection to the server in nfs4_alloc_client()" }, - "CVE-2021-0707": { - "cmt_msg": "dmabuf: fix use-after-free of dmabuf's file->f_inode" + "CVE-2022-1679": { + "cmt_msg": "" }, - "CVE-2022-1158": { - "cmt_msg": "KVM: x86/mmu: do compare-and-exchange of gPTE via the user address" - }, - "CVE-2022-26966": { - "cmt_msg": "sr9700: sanity check for packet length" - }, - "CVE-2021-34693": { - "cmt_msg": "can: bcm: fix infoleak in struct bcm_msg_head" - }, - "CVE-2022-26490": { - "cmt_msg": "nfc: st21nfca: Fix potential buffer overflows in EVT_TRANSACTION" - }, - "CVE-2021-26401": { - "cmt_msg": "x86/speculation: Use generic retpoline by default on AMD" + "CVE-2022-1671": { + "cmt_msg": "rxrpc: fix some null-ptr-deref bugs in server_key.c" }, "CVE-2021-3847": { "cmt_msg": "" }, - "CVE-2022-1012": { - "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation" - }, - "CVE-2021-45486": { - "cmt_msg": "inet: use bigger hash table for IP ID generation" - }, - "CVE-2021-4204": { - "cmt_msg": "bpf: Generalize check_ctx_reg for reuse with other types" + "CVE-2022-1280": { + "cmt_msg": "drm: avoid circular locks in drm_mode_getconnector" }, "CVE-2011-4917": { "cmt_msg": "" }, "CVE-2021-45485": { "cmt_msg": "ipv6: use prandom_u32() for ID generation" - }, - "CVE-2021-32078": { - "cmt_msg": "ARM: footbridge: remove personal server platform" - }, - "CVE-2022-30594": { - "cmt_msg": "ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE" - }, - "CVE-2020-26139": { - "cmt_msg": "mac80211: do not accept/forward invalid EAPOL frames" - }, - "CVE-2021-38209": { - "cmt_msg": "netfilter: conntrack: Make global sysctls readonly in non-init netns" - }, - "CVE-2021-38204": { - "cmt_msg": "usb: max-3421: Prevent corruption of freed memory" - }, - "CVE-2021-38205": { - "cmt_msg": "net: xilinx_emaclite: Do not print real IOMEM pointer" - }, - "CVE-2021-3609": { - "cmt_msg": "can: bcm: delay release of struct bcm_op after synchronize_rcu()" - }, - "CVE-2021-38207": { - "cmt_msg": "net: ll_temac: Fix TX BD buffer overwrite" - }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" - }, - "CVE-2022-0847": { - "cmt_msg": "lib/iov_iter: initialize \"flags\" in new pipe_buffer" - }, - "CVE-2022-0400": { - "cmt_msg": "" - }, - "CVE-2021-3600": { - "cmt_msg": "bpf: Fix 32 bit src register truncation on div/mod" - }, - "CVE-2021-38208": { - "cmt_msg": "nfc: fix NULL ptr dereference in llcp_sock_getname() after failed connect" - }, - "CVE-2021-23133": { - "cmt_msg": "net/sctp: fix race condition in sctp_destroy_sock" } } }, @@ -73416,6 +74228,10 @@ } }, "4.9.283": { + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu", + "cmt_id": "e9924c4204ede999b0515fd31a370a1e27f676bc" + }, "CVE-2021-40490": { "cmt_msg": "ext4: fix race writing to an inline_data file while its xattrs are changing", "cmt_id": "7067b09fe587cbd47544a3047a40c64e4d636fff" @@ -73518,6 +74334,10 @@ } }, "4.9.293": { + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection", + "cmt_id": "28d8244f3ec961a11bfb4ad83cdc48ff9b8c47a7" + }, "CVE-2021-39698": { "cmt_msg": "wait: add wake_up_pollfree()", "cmt_id": "0e92a7e47a0411d5208990c83a3d200515e314e8" @@ -73752,6 +74572,14 @@ } }, "4.9.313": { + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions", + "cmt_id": "fa2217b66467917a623993c14d671661ad625fb6" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout", + "cmt_id": "a93ea9595fde438996d7b9322749d4d1921162f7" + }, "CVE-2022-1734": { "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs", "cmt_id": "4721695be941626e4b18b89e0641e36fc385cfd8" @@ -73767,6 +74595,12 @@ "cmt_id": "a1466528d8ae5d9a3bb29781f0098fa3476e9e1c" } }, + "4.9.317": { + "CVE-2022-0494": { + "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern", + "cmt_id": "d59073bedb7cf752b8cd4027dd0f67cf7ac4330f" + } + }, "outstanding": { "CVE-2021-0929": { "cmt_msg": "staging/android/ion: delete dma_buf->kmap/unmap implemenation" @@ -73792,6 +74626,9 @@ "CVE-2022-0168": { "cmt_msg": "cifs: fix NULL ptr dereference in smb2_ioctl_query_info()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-20854": { "cmt_msg": "phy: ocelot-serdes: fix out-of-bounds read" }, @@ -73945,8 +74782,8 @@ "CVE-2022-23041": { "cmt_msg": "xen/9p: use alloc/free_pages_exact()" }, - "CVE-2022-0494": { - "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" + "CVE-2022-1462": { + "cmt_msg": "" }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" @@ -73954,6 +74791,9 @@ "CVE-2020-16120": { "cmt_msg": "ovl: switch to mounter creds in readdir" }, + "CVE-2022-23222": { + "cmt_msg": "bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL" + }, "CVE-2020-15802": { "cmt_msg": "" }, @@ -74089,6 +74929,9 @@ "CVE-2021-0399": { "cmt_msg": "" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2017-13694": { "cmt_msg": "" }, @@ -74101,9 +74944,6 @@ "CVE-2022-29968": { "cmt_msg": "io_uring: fix uninitialized field in rw io_kiocb" }, - "CVE-2022-1462": { - "cmt_msg": "" - }, "CVE-2022-0812": { "cmt_msg": "xprtrdma: fix incorrect header size calculations" }, @@ -74152,6 +74992,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2021-0695": { "cmt_msg": "" }, @@ -74164,6 +75007,9 @@ "CVE-2021-28951": { "cmt_msg": "io_uring: ensure that SQPOLL thread is started for exit" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2020-14304": { "cmt_msg": "" }, @@ -74260,8 +75106,8 @@ "CVE-2021-4218": { "cmt_msg": "sysctl: pass kernel pointers to ->proc_handler" }, - "CVE-2022-23222": { - "cmt_msg": "bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL" + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" }, "CVE-2019-15290": { "cmt_msg": "" @@ -74317,6 +75163,9 @@ "CVE-2020-36385": { "cmt_msg": "RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2019-12380": { "cmt_msg": "efi/x86/Add missing error handling to old_memmap 1:1 mapping code" }, @@ -74410,6 +75259,9 @@ "CVE-2021-32078": { "cmt_msg": "ARM: footbridge: remove personal server platform" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2019-10220": { "cmt_msg": "Convert filldir[64]() from __put_user() to unsafe_put_user()" }, @@ -74660,6 +75512,9 @@ "CVE-2021-0920": { "cmt_msg": "af_unix: fix garbage collect vs MSG_PEEK" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2019-13631": { "cmt_msg": "Input: gtco - bounds check collection indent level" }, @@ -74885,12 +75740,18 @@ "CVE-2019-18680": { "cmt_msg": "unknown" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2017-6074": { "cmt_msg": "dccp: fix freeing skb too early for IPV6_RECVPKTINFO" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2019-11815": { "cmt_msg": "net: rds: force to destroy connection if t_sock is NULL in rds_tcp_kill_sock()." }, @@ -74990,6 +75851,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-11600": { "cmt_msg": "xfrm: policy: check policy direction value" }, @@ -75065,6 +75929,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2019-2024": { "cmt_msg": "media: em28xx: Fix use-after-free when disconnecting" }, @@ -75611,6 +76478,9 @@ "CVE-2017-14489": { "cmt_msg": "scsi: scsi_transport_iscsi: fix the issue that iscsi_if_rx doesn't parse nlmsg properly" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" }, @@ -75659,6 +76529,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -75830,6 +76703,9 @@ "CVE-2020-12364": { "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2017-12146": { "cmt_msg": "driver core: platform: fix race condition with driver_override" }, @@ -76775,6 +77651,9 @@ "CVE-2019-15215": { "cmt_msg": "media: cpia2_usb: first wake up, then free in disconnect" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -77003,9 +77882,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2017-2596": { "cmt_msg": "kvm: fix page struct leak in handle_vmon" }, @@ -77666,6 +78551,9 @@ "CVE-2020-26558": { "cmt_msg": "Bluetooth: SMP: Fail if remote and local public keys are identical" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2019-10124": { "cmt_msg": "mm: hwpoison: fix thp split handing in soft_offline_in_use_page()" }, @@ -77870,12 +78758,18 @@ "CVE-2019-18680": { "cmt_msg": "" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-0995": { "cmt_msg": "watch_queue: Fix filter limit check" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2017-14991": { "cmt_msg": "scsi: sg: fixup infoleak when using SG_GET_REQUEST_TABLE" }, @@ -77978,6 +78872,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2017-11600": { "cmt_msg": "xfrm: policy: check policy direction value" }, @@ -78038,6 +78935,9 @@ "CVE-2018-10021": { "cmt_msg": "scsi: libsas: defer ata device eh commands to libata" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2019-2024": { "cmt_msg": "media: em28xx: Fix use-after-free when disconnecting" }, @@ -78089,6 +78989,9 @@ "CVE-2018-20510": { "cmt_msg": "binder: replace \"%p\" with \"%pK\"" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2019-14763": { "cmt_msg": "usb: dwc3: gadget: never call ->complete() from ->ep_queue()" }, @@ -78578,6 +79481,9 @@ "CVE-2017-14489": { "cmt_msg": "scsi: scsi_transport_iscsi: fix the issue that iscsi_if_rx doesn't parse nlmsg properly" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2022-1786": { "cmt_msg": "io_uring: remove io_identity" }, @@ -78614,6 +79520,9 @@ "CVE-2017-5715": { "cmt_msg": "x86/cpufeatures: Add X86_BUG_SPECTRE_V[12]" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -79655,6 +80564,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-18021": { "cmt_msg": "arm64: KVM: Tighten guest core register access from userspace" }, @@ -79862,9 +80774,15 @@ "CVE-2018-1000026": { "cmt_msg": "bnx2x: disable GSO where gso_size is too big for hardware" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2022-1678": { "cmt_msg": "tcp: optimize tcp internal pacing" }, @@ -80737,12 +81655,18 @@ "CVE-2019-19070": { "cmt_msg": "spi: gpio: prevent memory leak in spi_gpio_probe" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-45868": { "cmt_msg": "quota: check block number when reading the block in quota file" }, @@ -80830,6 +81754,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -81148,8 +82075,8 @@ "CVE-2022-23042": { "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -81241,6 +82168,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2019-18813": { "cmt_msg": "usb: dwc3: pci: prevent memory leak in dwc3_pci_probe" }, @@ -81283,6 +82213,9 @@ "CVE-2019-19768": { "cmt_msg": "blktrace: Protect q->blk_trace with RCU" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -81844,6 +82777,9 @@ "CVE-2021-3542": { "cmt_msg": "" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2020-12659": { "cmt_msg": "xsk: Add missing check on user supplied headroom size" }, @@ -81922,6 +82858,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2020-29370": { "cmt_msg": "mm: slub: add missing TID bump in kmem_cache_alloc_bulk()" }, @@ -82000,6 +82939,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -82129,9 +83071,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -82823,12 +83774,18 @@ "CVE-2019-19070": { "cmt_msg": "spi: gpio: prevent memory leak in spi_gpio_probe" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-45868": { "cmt_msg": "quota: check block number when reading the block in quota file" }, @@ -82898,6 +83855,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -83210,8 +84170,8 @@ "CVE-2022-23042": { "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -83300,6 +84260,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2019-18813": { "cmt_msg": "usb: dwc3: pci: prevent memory leak in dwc3_pci_probe" }, @@ -83339,6 +84302,9 @@ "CVE-2019-19768": { "cmt_msg": "blktrace: Protect q->blk_trace with RCU" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -83879,6 +84845,9 @@ "CVE-2021-3542": { "cmt_msg": "" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2020-12659": { "cmt_msg": "xsk: Add missing check on user supplied headroom size" }, @@ -83957,6 +84926,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2020-29373": { "cmt_msg": "io_uring: grab ->fs as part of async preparation" }, @@ -84032,6 +85004,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -84164,9 +85139,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -84847,12 +85831,18 @@ "CVE-2019-19070": { "cmt_msg": "spi: gpio: prevent memory leak in spi_gpio_probe" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-45868": { "cmt_msg": "quota: check block number when reading the block in quota file" }, @@ -84913,6 +85903,9 @@ "CVE-2020-15436": { "cmt_msg": "block: Fix use-after-free in blkdev_get()" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -85186,8 +86179,8 @@ "CVE-2022-23042": { "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -85270,6 +86263,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2019-18813": { "cmt_msg": "usb: dwc3: pci: prevent memory leak in dwc3_pci_probe" }, @@ -85309,6 +86305,9 @@ "CVE-2019-19768": { "cmt_msg": "blktrace: Protect q->blk_trace with RCU" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -85420,6 +86419,9 @@ "CVE-2021-3739": { "cmt_msg": "btrfs: fix NULL pointer dereference when deleting device by invalid id" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2021-3732": { "cmt_msg": "ovl: prevent private clone if bind mount is not allowed" }, @@ -85909,6 +86911,9 @@ "CVE-2020-29374": { "cmt_msg": "gup: document and work around \"COW can break either way\" issue" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2020-29373": { "cmt_msg": "io_uring: grab ->fs as part of async preparation" }, @@ -85975,6 +86980,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -86107,9 +87115,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-20292": { "cmt_msg": "drm/ttm/nouveau: don't call tt destroy callback on alloc failure." }, @@ -86590,6 +87607,9 @@ "CVE-2021-45095": { "cmt_msg": "phonet: refcount leak in pep_sock_accep" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-0001": { "cmt_msg": "x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE" }, @@ -86605,6 +87625,9 @@ "CVE-2019-19378": { "cmt_msg": "" }, + "CVE-2022-25265": { + "cmt_msg": "" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -86737,8 +87760,8 @@ "CVE-2022-23041": { "cmt_msg": "xen/9p: use alloc/free_pages_exact()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -86803,6 +87826,9 @@ "CVE-2021-44733": { "cmt_msg": "tee: handle lookup of shm with reference count 0" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2021-28715": { "cmt_msg": "xen/netback: don't queue unlimited number of packages" }, @@ -86896,6 +87922,12 @@ "CVE-2022-1462": { "cmt_msg": "" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2021-42008": { "cmt_msg": "net: 6pack: fix slab-out-of-bounds in decode_data" }, @@ -86932,6 +87964,9 @@ "CVE-2021-4090": { "cmt_msg": "NFSD: Fix exposure in nfsd4_decode_bitmap()" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2022-25258": { "cmt_msg": "USB: gadget: validate interface OS descriptor requests" }, @@ -87007,8 +88042,8 @@ "CVE-2022-24958": { "cmt_msg": "usb: gadget: don't release an existing dev->buf" }, - "CVE-2022-24959": { - "cmt_msg": "yam: fix a memory leak in yam_siocdevprivate()" + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" }, "CVE-2022-0500": { "cmt_msg": "bpf: Introduce MEM_RDONLY flag" @@ -87049,8 +88084,8 @@ "CVE-2022-1836": { "cmt_msg": "floppy: disable FDRAWCMD by default" }, - "CVE-2022-25265": { - "cmt_msg": "" + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" }, "CVE-2022-1043": { "cmt_msg": "io_uring: fix xa_alloc_cycle() error return value check" @@ -87151,6 +88186,9 @@ "CVE-2021-3739": { "cmt_msg": "btrfs: fix NULL pointer dereference when deleting device by invalid id" }, + "CVE-2022-24959": { + "cmt_msg": "yam: fix a memory leak in yam_siocdevprivate()" + }, "CVE-2021-3732": { "cmt_msg": "ovl: prevent private clone if bind mount is not allowed" }, @@ -87229,6 +88267,9 @@ "CVE-2021-3847": { "cmt_msg": "" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1280": { "cmt_msg": "drm: avoid circular locks in drm_mode_getconnector" }, @@ -87244,12 +88285,18 @@ "CVE-2022-30594": { "cmt_msg": "ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-38204": { "cmt_msg": "usb: max-3421: Prevent corruption of freed memory" }, "CVE-2022-28389": { "cmt_msg": "can: mcba_usb: mcba_usb_start_xmit(): fix double dev_kfree_skb in error path" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2022-0847": { "cmt_msg": "lib/iov_iter: initialize \"flags\" in new pipe_buffer" }, @@ -87419,6 +88466,12 @@ "cmt_id": "c764e8fa4491da66780fcb30a0d43bfd3fccd12c" } }, + "5.13.16": { + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu", + "cmt_id": "961447ff60291b91e27d5c32fa549c1411ad3b70" + } + }, "5.13.17": { "CVE-2021-20322": { "cmt_msg": "ipv6: make exception cache less predictible", @@ -87456,6 +88509,9 @@ "CVE-2021-45095": { "cmt_msg": "phonet: refcount leak in pep_sock_accep" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-0001": { "cmt_msg": "x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE" }, @@ -87588,8 +88644,8 @@ "CVE-2022-23041": { "cmt_msg": "xen/9p: use alloc/free_pages_exact()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -87711,6 +88767,9 @@ "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2017-13694": { "cmt_msg": "" }, @@ -87744,6 +88803,15 @@ "CVE-2022-1462": { "cmt_msg": "" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, @@ -87777,6 +88845,9 @@ "CVE-2021-4090": { "cmt_msg": "NFSD: Fix exposure in nfsd4_decode_bitmap()" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2022-25258": { "cmt_msg": "USB: gadget: validate interface OS descriptor requests" }, @@ -88059,6 +89130,12 @@ "CVE-2022-30594": { "cmt_msg": "ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2022-0847": { "cmt_msg": "lib/iov_iter: initialize \"flags\" in new pipe_buffer" }, @@ -88681,6 +89758,10 @@ } }, "5.10.64": { + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu", + "cmt_id": "ddd7e8b7b84836c584a284b98ca9bd7a348a0558" + }, "CVE-2021-46283": { "cmt_msg": "netfilter: nf_tables: initialize set before expression setup", "cmt_id": "36983fc2f87ea3b74a33bf460c9ee7329735b7b5" @@ -88853,6 +89934,10 @@ } }, "5.10.85": { + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection", + "cmt_id": "61144329606cb9518642b7d2e940b21eb3214204" + }, "CVE-2021-39698": { "cmt_msg": "wait: add wake_up_pollfree()", "cmt_id": "8e04c8397bf98235b1aa41153717de7a05e652a2" @@ -88910,6 +89995,12 @@ "cmt_id": "7dd52af1eb5798f590d9d9e1c56ed8f5744ee0ca" } }, + "5.10.90": { + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint", + "cmt_id": "769d14abd35e0e153b5149c3e1e989a9d719e3ff" + } + }, "5.10.91": { "CVE-2021-45095": { "cmt_msg": "phonet: refcount leak in pep_sock_accep", @@ -88961,6 +90052,10 @@ "cmt_msg": "cgroup-v1: Require capabilities to set release_agent", "cmt_id": "1fc3444cda9a78c65b769e3fa93455e09ff7a0d3" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()", + "cmt_id": "7b4741644cf718c422187e74fb07661ef1d68e85" + }, "CVE-2022-1055": { "cmt_msg": "net: sched: fix use-after-free in tc_new_tfilter()", "cmt_id": "e7be56926397cf9d992be8913f74a76152f8f08d" @@ -89084,6 +90179,12 @@ "cmt_id": "648895da69ced90ca770fd941c3d9479a9d72c16" } }, + "5.10.107": { + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect", + "cmt_id": "dc1163203ae6e24b86168390fe5b4a3295fcba7f" + } + }, "5.10.108": { "CVE-2022-27666": { "cmt_msg": "esp: Fix possible buffer overflow in ESP transformation", @@ -89179,6 +90280,14 @@ } }, "5.10.115": { + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions", + "cmt_id": "8a9e7c64f4a02c4c397e55ba379609168ec7df4a" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout", + "cmt_id": "879b075a9a364a325988d4484b74311edfef82a1" + }, "CVE-2022-1734": { "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs", "cmt_id": "1961c5a688edb53fe3bc25cbda57f47adf12563c" @@ -89214,6 +90323,20 @@ "cmt_id": "a5c68f457fbf52c5564ca4eea03f84776ef14e41" } }, + "5.10.120": { + "CVE-2022-1852": { + "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction", + "cmt_id": "3d8fc6e28f321d753ab727e3c3e740daf36a8fa3" + }, + "CVE-2022-1972": { + "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()", + "cmt_id": "c0aff1faf66b6b7a19103f83e6a5d0fdc64b9048" + }, + "CVE-2022-1966": { + "cmt_msg": "netfilter: nf_tables: disallow non-stateful expression in sets earlier", + "cmt_id": "ea62d169b6e731e0b54abda1d692406f6bc6a696" + } + }, "outstanding": { "CVE-2020-26556": { "cmt_msg": "" @@ -89287,9 +90410,6 @@ "CVE-2022-1651": { "cmt_msg": "virt: acrn: fix a memory leak in acrn_dev_ioctl()" }, - "CVE-2022-1852": { - "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" - }, "CVE-2021-26934": { "cmt_msg": "" }, @@ -89335,9 +90455,6 @@ "CVE-2020-26142": { "cmt_msg": "" }, - "CVE-2022-1966": { - "cmt_msg": "netfilter: nf_tables: disallow non-stateful expression in sets earlier" - }, "CVE-2022-1247": { "cmt_msg": "" }, @@ -89365,9 +90482,6 @@ "CVE-2022-29968": { "cmt_msg": "io_uring: fix uninitialized field in rw io_kiocb" }, - "CVE-2022-1972": { - "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" - }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -89380,6 +90494,9 @@ "CVE-2022-1508": { "cmt_msg": "io_uring: reexpand under-reexpanded iters" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2021-0695": { "cmt_msg": "" }, @@ -89389,6 +90506,9 @@ "CVE-2021-4150": { "cmt_msg": "block: fix incorrect references to disk objects" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2020-14304": { "cmt_msg": "" }, @@ -89523,6 +90643,9 @@ }, "CVE-2021-32078": { "cmt_msg": "ARM: footbridge: remove personal server platform" + }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" } } }, @@ -89842,6 +90965,9 @@ "CVE-2021-45095": { "cmt_msg": "phonet: refcount leak in pep_sock_accep" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-0001": { "cmt_msg": "x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE" }, @@ -89857,6 +90983,9 @@ "CVE-2019-19378": { "cmt_msg": "" }, + "CVE-2022-25265": { + "cmt_msg": "" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -90109,6 +91238,9 @@ "CVE-2021-44733": { "cmt_msg": "tee: handle lookup of shm with reference count 0" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2021-28715": { "cmt_msg": "xen/netback: don't queue unlimited number of packages" }, @@ -90208,12 +91340,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2021-32606": { "cmt_msg": "can: isotp: prevent race between isotp_bind() and isotp_setsockopt()" }, "CVE-2021-38160": { "cmt_msg": "virtio_console: Assure used length from device is limited" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, "CVE-2021-42008": { "cmt_msg": "net: 6pack: fix slab-out-of-bounds in decode_data" }, @@ -90250,6 +91388,9 @@ "CVE-2021-4090": { "cmt_msg": "NFSD: Fix exposure in nfsd4_decode_bitmap()" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2021-4154": { "cmt_msg": "cgroup: verify that source is a string" }, @@ -90334,8 +91475,8 @@ "CVE-2022-24958": { "cmt_msg": "usb: gadget: don't release an existing dev->buf" }, - "CVE-2022-24959": { - "cmt_msg": "yam: fix a memory leak in yam_siocdevprivate()" + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" }, "CVE-2022-0500": { "cmt_msg": "bpf: Introduce MEM_RDONLY flag" @@ -90361,6 +91502,9 @@ "CVE-2022-1055": { "cmt_msg": "net: sched: fix use-after-free in tc_new_tfilter()" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2022-0480": { "cmt_msg": "memcg: enable accounting for file lock caches" }, @@ -90388,8 +91532,8 @@ "CVE-2020-26141": { "cmt_msg": "ath10k: Fix TKIP Michael MIC verification for PCIe" }, - "CVE-2022-25265": { - "cmt_msg": "" + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" }, "CVE-2022-1199": { "cmt_msg": "ax25: Fix NULL pointer dereference in ax25_kill_by_device" @@ -90499,6 +91643,9 @@ "CVE-2021-3739": { "cmt_msg": "btrfs: fix NULL pointer dereference when deleting device by invalid id" }, + "CVE-2022-24959": { + "cmt_msg": "yam: fix a memory leak in yam_siocdevprivate()" + }, "CVE-2021-3732": { "cmt_msg": "ovl: prevent private clone if bind mount is not allowed" }, @@ -90580,6 +91727,9 @@ "CVE-2021-3847": { "cmt_msg": "" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1280": { "cmt_msg": "drm: avoid circular locks in drm_mode_getconnector" }, @@ -90601,6 +91751,9 @@ "CVE-2020-26139": { "cmt_msg": "mac80211: do not accept/forward invalid EAPOL frames" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-38204": { "cmt_msg": "usb: max-3421: Prevent corruption of freed memory" }, @@ -90701,6 +91854,10 @@ "cmt_msg": "cgroup-v1: Require capabilities to set release_agent", "cmt_id": "9c9dbb954e618e3d9110f13cc02c5db1fb73ea5d" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()", + "cmt_id": "dea4fec0d87d4401b5d2717aa7c6c6cad050fb62" + }, "CVE-2022-1055": { "cmt_msg": "net: sched: fix use-after-free in tc_new_tfilter()", "cmt_id": "95e34f61b58a152656cbe8d6e19843cc343fb089" @@ -91064,11 +92221,17 @@ "CVE-2022-29968": { "cmt_msg": "io_uring: fix uninitialized field in rw io_kiocb" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, - "CVE-2021-4095": { - "cmt_msg": "KVM: x86: Fix wall clock writes in Xen shared_info not to mark page dirty" + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" }, "CVE-2005-3660": { "cmt_msg": "" @@ -91079,6 +92242,9 @@ "CVE-2022-24122": { "cmt_msg": "ucount: Make get_ucount a safe get_user replacement" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2021-0695": { "cmt_msg": "" }, @@ -91112,12 +92278,15 @@ "CVE-2022-1184": { "cmt_msg": "" }, - "CVE-2011-4917": { + "CVE-2022-25265": { "cmt_msg": "" }, "CVE-2019-15902": { "cmt_msg": "unknown" }, + "CVE-2021-4095": { + "cmt_msg": "KVM: x86: Fix wall clock writes in Xen shared_info not to mark page dirty" + }, "CVE-2019-15290": { "cmt_msg": "" }, @@ -91193,7 +92362,7 @@ "CVE-2022-1836": { "cmt_msg": "floppy: disable FDRAWCMD by default" }, - "CVE-2022-25265": { + "CVE-2011-4917": { "cmt_msg": "" }, "CVE-2013-7445": { @@ -91307,6 +92476,14 @@ } }, "5.17.7": { + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions", + "cmt_id": "8b58d6e565d83443c51b3fc076bd4472674aca0c" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout", + "cmt_id": "63a545103b77091f2309b44a8975cdf255bb99b2" + }, "CVE-2022-1734": { "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs", "cmt_id": "f4bfbac45121c8638db5eacb1ebbb61ee956c668" @@ -91319,6 +92496,10 @@ } }, "5.17.9": { + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16", + "cmt_id": "e3ee7bb47d6509c3e8a3e96e5d8e3bf21549b6e8" + }, "CVE-2022-1012": { "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation", "cmt_id": "6976724355f5fdada89de528730f9a7b4928f2e3" @@ -91336,6 +92517,26 @@ "cmt_id": "19a66796d1f0dd4ce4b05f76d53ce1d0a7dc817d" } }, + "5.17.13": { + "CVE-2022-1852": { + "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction", + "cmt_id": "dca5ea67a3e627a3022fe58722a2807c1ef61c29" + }, + "CVE-2022-1972": { + "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()", + "cmt_id": "c88f3e3d243d701586239c5b69356ec2b1fd05f1" + }, + "CVE-2022-1966": { + "cmt_msg": "netfilter: nf_tables: disallow non-stateful expression in sets earlier", + "cmt_id": "d8db0465bcc4d4b54ecfb67b820ed26eb1440da7" + } + }, + "5.17.14": { + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay", + "cmt_id": "2088cc00491e8d25a99d0f247df843e9c3df2040" + } + }, "outstanding": { "CVE-2018-17977": { "cmt_msg": "" @@ -91391,9 +92592,6 @@ "CVE-2019-19378": { "cmt_msg": "" }, - "CVE-2022-1852": { - "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" - }, "CVE-2021-0695": { "cmt_msg": "" }, @@ -91514,9 +92712,6 @@ "CVE-2021-0399": { "cmt_msg": "" }, - "CVE-2022-1966": { - "cmt_msg": "netfilter: nf_tables: disallow non-stateful expression in sets earlier" - }, "CVE-2022-25265": { "cmt_msg": "" }, @@ -91547,9 +92742,6 @@ "CVE-2021-33135": { "cmt_msg": "" }, - "CVE-2022-1972": { - "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" - }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -91585,6 +92777,12 @@ "cmt_id": "f8ea208b3fbbc0546d71b47e8abaf98b0961dec1" } }, + "5.14.3": { + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu", + "cmt_id": "d1a3c6d5925a8d00a32c5ef2d674dd9c0ce89c95" + } + }, "5.14.4": { "CVE-2021-20322": { "cmt_msg": "ipv6: make exception cache less predictible", @@ -91724,6 +92922,10 @@ } }, "5.14.19": { + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory", + "cmt_id": "5b67adb7425e758655e464bda4eb4174ac88b625" + }, "CVE-2021-3752": { "cmt_msg": "Bluetooth: fix use-after-free error in lock_sock_nested()", "cmt_id": "b87da982da1b4787e23316e3eedc6bba52cfba64" @@ -91762,6 +92964,9 @@ "CVE-2021-45095": { "cmt_msg": "phonet: refcount leak in pep_sock_accep" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-0001": { "cmt_msg": "x86/speculation: Rename RETPOLINE_AMD to RETPOLINE_LFENCE" }, @@ -91867,8 +93072,8 @@ "CVE-2022-23041": { "cmt_msg": "xen/9p: use alloc/free_pages_exact()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -91906,6 +93111,9 @@ "CVE-2007-3719": { "cmt_msg": "" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2022-0171": { "cmt_msg": "" }, @@ -91978,6 +93186,9 @@ "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2017-13694": { "cmt_msg": "" }, @@ -92002,6 +93213,12 @@ "CVE-2022-1462": { "cmt_msg": "" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, @@ -92029,6 +93246,9 @@ "CVE-2020-0347": { "cmt_msg": "" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2022-25258": { "cmt_msg": "USB: gadget: validate interface OS descriptor requests" }, @@ -92281,6 +93501,9 @@ "CVE-2013-7445": { "cmt_msg": "" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2022-0847": { "cmt_msg": "lib/iov_iter: initialize \"flags\" in new pipe_buffer" }, @@ -92321,6 +93544,10 @@ } }, "5.15.3": { + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory", + "cmt_id": "5e1b901dd470659bcfeaa76811d2af9165579d77" + }, "CVE-2021-3752": { "cmt_msg": "Bluetooth: fix use-after-free error in lock_sock_nested()", "cmt_id": "7e22e4db95b04f09adcce18c75d27cbca8f53b99" @@ -92367,6 +93594,10 @@ } }, "5.15.8": { + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection", + "cmt_id": "e1e21632a4c4d2f85587e204939883ce59d18447" + }, "CVE-2021-39698": { "cmt_msg": "wait: add wake_up_pollfree()", "cmt_id": "1ebb6cd8c754bfe1a5f9539027980756bce7cb08" @@ -92436,6 +93667,12 @@ "cmt_id": "a2c144d17623984fdafa4634ecf4ab64580d29bb" } }, + "5.15.13": { + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint", + "cmt_id": "75799e71df1da11394740b43ae5686646179561d" + } + }, "5.15.14": { "CVE-2021-45095": { "cmt_msg": "phonet: refcount leak in pep_sock_accep", @@ -92499,6 +93736,10 @@ "cmt_msg": "cgroup-v1: Require capabilities to set release_agent", "cmt_id": "4b1c32bfaa02255a5df602b41587174004996477" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()", + "cmt_id": "60765e43e40fbf7a1df828116172440510fcc3e4" + }, "CVE-2022-1055": { "cmt_msg": "net: sched: fix use-after-free in tc_new_tfilter()", "cmt_id": "f36cacd6c933183c1a8827d5987cf2cfc0a44c76" @@ -92751,6 +93992,14 @@ } }, "5.15.39": { + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions", + "cmt_id": "a2168fb3128a576d0175443403c15dcf8bf128f6" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout", + "cmt_id": "7bd81a05d48942ef2c48630e5e7963b187e95727" + }, "CVE-2022-1734": { "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs", "cmt_id": "b8f2b836e7d0a553b886654e8b3925a85862d2eb" @@ -92767,6 +94016,10 @@ "cmt_msg": "SUNRPC: Ensure we flush any closed sockets before xs_xprt_free()", "cmt_id": "54f6834b283d9b4d070b0639d9ef5e1d156fe7b0" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16", + "cmt_id": "952a238d779eea4ecb2f8deb5004c8f56be79bc9" + }, "CVE-2022-1012": { "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation", "cmt_id": "1a8ee547da2b64d6a2aedbd38a691578eff14718" @@ -92784,6 +94037,26 @@ "cmt_id": "acd12d16528152b32fa09be2c5ef95047f69af05" } }, + "5.15.45": { + "CVE-2022-1852": { + "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction", + "cmt_id": "531d1070d864c78283b7597449e60ddc53319d88" + }, + "CVE-2022-1972": { + "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()", + "cmt_id": "89ef50fe03a55feccf5681c237673a2f98161161" + }, + "CVE-2022-1966": { + "cmt_msg": "netfilter: nf_tables: disallow non-stateful expression in sets earlier", + "cmt_id": "f692bcffd1f2ce5488d24fbcb8eab5f351abf79d" + } + }, + "5.15.46": { + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay", + "cmt_id": "61decb58486d7c0cbded25fe4d301ab4fa148cd8" + } + }, "outstanding": { "CVE-2018-17977": { "cmt_msg": "" @@ -92845,9 +94118,6 @@ "CVE-2019-19378": { "cmt_msg": "" }, - "CVE-2022-1852": { - "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" - }, "CVE-2021-0695": { "cmt_msg": "" }, @@ -92971,9 +94241,6 @@ "CVE-2021-0399": { "cmt_msg": "" }, - "CVE-2022-1966": { - "cmt_msg": "netfilter: nf_tables: disallow non-stateful expression in sets earlier" - }, "CVE-2022-25265": { "cmt_msg": "" }, @@ -93013,9 +94280,6 @@ "CVE-2021-33135": { "cmt_msg": "" }, - "CVE-2022-1972": { - "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" - }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -93415,12 +94679,18 @@ "CVE-2019-19070": { "cmt_msg": "spi: gpio: prevent memory leak in spi_gpio_probe" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-27363": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -93520,6 +94790,9 @@ "CVE-2020-8648": { "cmt_msg": "vt: selection, close sel_buffer race" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -93592,6 +94865,9 @@ "CVE-2020-10757": { "cmt_msg": "mm: Fix mremap not considering huge pmd devmap" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2020-15437": { "cmt_msg": "serial: 8250: fix null-ptr-deref in serial8250_start_tx()" }, @@ -93859,8 +95135,8 @@ "CVE-2022-23042": { "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -93955,6 +95231,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2019-18813": { "cmt_msg": "usb: dwc3: pci: prevent memory leak in dwc3_pci_probe" }, @@ -93997,6 +95276,9 @@ "CVE-2019-19768": { "cmt_msg": "blktrace: Protect q->blk_trace with RCU" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -94687,6 +95969,9 @@ "CVE-2020-25284": { "cmt_msg": "rbd: require global CAP_SYS_ADMIN for mapping and unmapping" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2020-29370": { "cmt_msg": "mm: slub: add missing TID bump in kmem_cache_alloc_bulk()" }, @@ -94768,6 +96053,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -94906,9 +96194,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" }, @@ -96520,6 +97817,10 @@ } }, "5.4.145": { + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu", + "cmt_id": "d84708451d9041dff8a81e3718f821f12d2eb6c5" + }, "CVE-2021-40490": { "cmt_msg": "ext4: fix race writing to an inline_data file while its xattrs are changing", "cmt_id": "9b3849ba667af99ee99a7853a021a7786851b9fd" @@ -96676,6 +97977,10 @@ } }, "5.4.165": { + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection", + "cmt_id": "6e1e0a01425810494ce00d7b800b69482790b198" + }, "CVE-2021-39698": { "cmt_msg": "wait: add wake_up_pollfree()", "cmt_id": "e0c03d15cd03476dd698c1ae7fb32a16d3e87f5c" @@ -96725,6 +98030,10 @@ "CVE-2021-44733": { "cmt_msg": "tee: handle lookup of shm with reference count 0", "cmt_id": "940e68e57ab69248fabba5889e615305789db8a7" + }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint", + "cmt_id": "831de271452b87657fcf8d715ee20519b79caef5" } }, "5.4.171": { @@ -96968,10 +98277,18 @@ "cmt_msg": "ALSA: pcm: Fix races among concurrent hw_params and hw_free calls", "cmt_id": "fbeb492694ce0441053de57699e1e2b7bc148a69" }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout", + "cmt_id": "01d4363dd7176fd780066cd020f66c0f55c4b6f9" + }, "CVE-2022-1734": { "cmt_msg": "nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unregister_dev to avoid bugs", "cmt_id": "33d3e76fc7a7037f402246c824d750542e2eb37f" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions", + "cmt_id": "85aecdef77f9c5b5c0d8988db6681960f0d46ab3" + }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern", "cmt_id": "c7337efd1d11acb6f84c68ffee57d3f312e87b24" @@ -96991,6 +98308,12 @@ "cmt_id": "b2f140a9f980806f572d672e1780acea66b9a25c" } }, + "5.4.197": { + "CVE-2022-1012": { + "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation", + "cmt_id": "ab5b00cfe0500f5f5a3648ca945b892156b839fb" + } + }, "outstanding": { "CVE-2021-0929": { "cmt_msg": "staging/android/ion: delete dma_buf->kmap/unmap implemenation" @@ -97016,6 +98339,9 @@ "CVE-2022-0168": { "cmt_msg": "cifs: fix NULL ptr dereference in smb2_ioctl_query_info()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2018-1121": { "cmt_msg": "" }, @@ -97082,9 +98408,6 @@ "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, - "CVE-2022-1012": { - "cmt_msg": "secure_seq: use the 64 bits of the siphash for port offset calculation" - }, "CVE-2021-26934": { "cmt_msg": "" }, @@ -97190,6 +98513,9 @@ "CVE-2021-4159": { "cmt_msg": "bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds()" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2021-0695": { "cmt_msg": "" }, @@ -97202,6 +98528,9 @@ "CVE-2021-28951": { "cmt_msg": "io_uring: ensure that SQPOLL thread is started for exit" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2020-14304": { "cmt_msg": "" }, @@ -97238,6 +98567,9 @@ "CVE-2020-12364": { "cmt_msg": "drm/i915/guc: Update to use firmware v49.0.1" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-0500": { "cmt_msg": "bpf: Introduce MEM_RDONLY flag" }, @@ -97307,6 +98639,9 @@ "CVE-2020-36385": { "cmt_msg": "RDMA/ucma: Rework ucma_migrate_id() to avoid races with destroy" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2021-3542": { "cmt_msg": "" }, @@ -97361,6 +98696,9 @@ "CVE-2021-32078": { "cmt_msg": "ARM: footbridge: remove personal server platform" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2020-27835": { "cmt_msg": "IB/hfi1: Ensure correct mm is used at all times" } @@ -97883,12 +99221,18 @@ "CVE-2019-19070": { "cmt_msg": "spi: gpio: prevent memory leak in spi_gpio_probe" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2022-23038": { "cmt_msg": "xen/grant-table: add gnttab_try_end_foreign_access()" }, "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-45868": { "cmt_msg": "quota: check block number when reading the block in quota file" }, @@ -97946,6 +99290,9 @@ "CVE-2020-15436": { "cmt_msg": "block: Fix use-after-free in blkdev_get()" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -98201,8 +99548,8 @@ "CVE-2022-23042": { "cmt_msg": "xen/netfront: react properly to failing gnttab_end_foreign_access_ref()" }, - "CVE-2022-25636": { - "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" }, "CVE-2022-0494": { "cmt_msg": "block-map: add __GFP_ZERO flag for alloc_page in function bio_copy_kern" @@ -98279,6 +99626,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2019-18812": { "cmt_msg": "ASoC: SOF: Fix memory leak in sof_dfsentry_write" }, @@ -98312,6 +99662,9 @@ "CVE-2019-19768": { "cmt_msg": "blktrace: Protect q->blk_trace with RCU" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -98414,6 +99767,9 @@ "CVE-2021-3739": { "cmt_msg": "btrfs: fix NULL pointer dereference when deleting device by invalid id" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2021-3732": { "cmt_msg": "ovl: prevent private clone if bind mount is not allowed" }, @@ -98852,6 +100208,9 @@ "CVE-2020-29374": { "cmt_msg": "gup: document and work around \"COW can break either way\" issue" }, + "CVE-2022-25636": { + "cmt_msg": "netfilter: nf_tables_offload: incorrect flow offload action array size" + }, "CVE-2019-19378": { "cmt_msg": "" }, @@ -98912,6 +100271,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -99020,9 +100382,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-20292": { "cmt_msg": "drm/ttm/nouveau: don't call tt destroy callback on alloc failure." }, @@ -99510,6 +100881,9 @@ "CVE-2021-32399": { "cmt_msg": "bluetooth: eliminate the potential race condition when removing the HCI controller" }, + "CVE-2022-20153": { + "cmt_msg": "io_uring: return back safer resurrect" + }, "CVE-2021-27364": { "cmt_msg": "scsi: iscsi: Restrict sessions and handles to admin capabilities" }, @@ -99519,6 +100893,9 @@ "CVE-2022-23039": { "cmt_msg": "xen/gntalloc: don't use gnttab_query_foreign_access()" }, + "CVE-2022-20154": { + "cmt_msg": "sctp: use call_rcu to free endpoint" + }, "CVE-2021-45868": { "cmt_msg": "quota: check block number when reading the block in quota file" }, @@ -99564,6 +100941,9 @@ "CVE-2022-29582": { "cmt_msg": "io_uring: fix race between timeout flush and removal" }, + "CVE-2022-32296": { + "cmt_msg": "tcp: increase source port perturb table to 2^16" + }, "CVE-2020-28974": { "cmt_msg": "vt: Disable KD_FONT_OP_COPY" }, @@ -99828,6 +101208,9 @@ "CVE-2020-24394": { "cmt_msg": "nfsd: apply umask on fs without ACL support" }, + "CVE-2022-20148": { + "cmt_msg": "f2fs: fix UAF in f2fs_available_free_memory" + }, "CVE-2013-7445": { "cmt_msg": "" }, @@ -99846,6 +101229,9 @@ "CVE-2022-1158": { "cmt_msg": "KVM: x86/mmu: do compare-and-exchange of gPTE via the user address" }, + "CVE-2022-20141": { + "cmt_msg": "igmp: Add ip_mc_list lock in ip_check_mc_rcu" + }, "CVE-2020-25704": { "cmt_msg": "perf/core: Fix a memory leak in perf_event_parse_addr_filter()" }, @@ -99927,6 +101313,9 @@ "CVE-2021-3739": { "cmt_msg": "btrfs: fix NULL pointer dereference when deleting device by invalid id" }, + "CVE-2022-20166": { + "cmt_msg": "drivers core: Use sysfs_emit and sysfs_emit_at for show(device *...) functions" + }, "CVE-2021-3732": { "cmt_msg": "ovl: prevent private clone if bind mount is not allowed" }, @@ -100011,6 +101400,9 @@ "CVE-2020-14356": { "cmt_msg": "cgroup: fix cgroup_sk_alloc() for sk_clone_lock()" }, + "CVE-2022-20132": { + "cmt_msg": "HID: add hid_is_usb() function to make it simpler for USB detection" + }, "CVE-2020-0423": { "cmt_msg": "binder: fix UAF when releasing todo list" }, @@ -100329,6 +101721,9 @@ "CVE-2021-41864": { "cmt_msg": "bpf: Fix integer overflow in prealloc_elems_and_freelist()" }, + "CVE-2022-1998": { + "cmt_msg": "fanotify: Fix stale file descriptor in copy_event_to_user()" + }, "CVE-2022-1852": { "cmt_msg": "KVM: x86: avoid calling x86 emulator without a decoded instruction" }, @@ -100401,9 +101796,18 @@ "CVE-2021-3573": { "cmt_msg": "Bluetooth: use correct lock to prevent UAF of hdev object" }, + "CVE-2022-1974": { + "cmt_msg": "nfc: replace improper check device_is_registered() in netlink related functions" + }, + "CVE-2022-1975": { + "cmt_msg": "NFC: netlink: fix sleep in atomic bug when firmware download timeout" + }, "CVE-2022-1972": { "cmt_msg": "netfilter: nf_tables: sanitize nft_set_desc_concat_parse()" }, + "CVE-2022-1973": { + "cmt_msg": "fs/ntfs3: Fix invalid free in log_replay" + }, "CVE-2021-28972": { "cmt_msg": "PCI: rpadlpar: Fix potential drc_name corruption in store functions" },
diff --git a/data/stream_fixes.json b/data/stream_fixes.json index 0bd3c8d..2afe000 100644 --- a/data/stream_fixes.json +++ b/data/stream_fixes.json
@@ -30232,6 +30232,18 @@ } }, "CVE-2022-0494": { + "4.14": { + "cmt_id": "4f3ea768c56e8dce55ae538f18b37420366c5c22", + "fixed_version": "4.14.282" + }, + "4.19": { + "cmt_id": "18243d8479fd77952bdb6340024169d30b173a40", + "fixed_version": "4.19.246" + }, + "4.9": { + "cmt_id": "d59073bedb7cf752b8cd4027dd0f67cf7ac4330f", + "fixed_version": "4.9.317" + }, "5.10": { "cmt_id": "a439819f4797f0846c7cffa9475f44aef23c541f", "fixed_version": "5.10.115" @@ -30468,6 +30480,14 @@ } }, "CVE-2022-1012": { + "4.14": { + "cmt_id": "40d20f3186ddd9b6b94598f4ef3d07644b0fa43c", + "fixed_version": "4.14.282" + }, + "4.19": { + "cmt_id": "695309c5c71526d32f5539f008bbf20ed2218528", + "fixed_version": "4.19.246" + }, "5.10": { "cmt_id": "a5c68f457fbf52c5564ca4eea03f84776ef14e41", "fixed_version": "5.10.119" @@ -30479,6 +30499,10 @@ "5.17": { "cmt_id": "6976724355f5fdada89de528730f9a7b4928f2e3", "fixed_version": "5.17.9" + }, + "5.4": { + "cmt_id": "ab5b00cfe0500f5f5a3648ca945b892156b839fb", + "fixed_version": "5.4.197" } }, "CVE-2022-1015": { @@ -30983,6 +31007,20 @@ "fixed_version": "5.4.192" } }, + "CVE-2022-1852": { + "5.10": { + "cmt_id": "3d8fc6e28f321d753ab727e3c3e740daf36a8fa3", + "fixed_version": "5.10.120" + }, + "5.15": { + "cmt_id": "531d1070d864c78283b7597449e60ddc53319d88", + "fixed_version": "5.15.45" + }, + "5.17": { + "cmt_id": "dca5ea67a3e627a3022fe58722a2807c1ef61c29", + "fixed_version": "5.17.13" + } + }, "CVE-2022-1943": { "5.15": { "cmt_id": "9e951f2d85c9430ea8ae0c8448e47e3c234f1580", @@ -30993,6 +31031,118 @@ "fixed_version": "5.17.8" } }, + "CVE-2022-1966": { + "5.10": { + "cmt_id": "ea62d169b6e731e0b54abda1d692406f6bc6a696", + "fixed_version": "5.10.120" + }, + "5.15": { + "cmt_id": "f692bcffd1f2ce5488d24fbcb8eab5f351abf79d", + "fixed_version": "5.15.45" + }, + "5.17": { + "cmt_id": "d8db0465bcc4d4b54ecfb67b820ed26eb1440da7", + "fixed_version": "5.17.13" + } + }, + "CVE-2022-1972": { + "5.10": { + "cmt_id": "c0aff1faf66b6b7a19103f83e6a5d0fdc64b9048", + "fixed_version": "5.10.120" + }, + "5.15": { + "cmt_id": "89ef50fe03a55feccf5681c237673a2f98161161", + "fixed_version": "5.15.45" + }, + "5.17": { + "cmt_id": "c88f3e3d243d701586239c5b69356ec2b1fd05f1", + "fixed_version": "5.17.13" + } + }, + "CVE-2022-1973": { + "5.15": { + "cmt_id": "61decb58486d7c0cbded25fe4d301ab4fa148cd8", + "fixed_version": "5.15.46" + }, + "5.17": { + "cmt_id": "2088cc00491e8d25a99d0f247df843e9c3df2040", + "fixed_version": "5.17.14" + } + }, + "CVE-2022-1974": { + "4.14": { + "cmt_id": "6f0ac4cd0377ab4e0b49b8f6efd37057c21336a9", + "fixed_version": "4.14.278" + }, + "4.19": { + "cmt_id": "7deebb94a311da0e02e621e765c3aef3d5936572", + "fixed_version": "4.19.242" + }, + "4.9": { + "cmt_id": "fa2217b66467917a623993c14d671661ad625fb6", + "fixed_version": "4.9.313" + }, + "5.10": { + "cmt_id": "8a9e7c64f4a02c4c397e55ba379609168ec7df4a", + "fixed_version": "5.10.115" + }, + "5.15": { + "cmt_id": "a2168fb3128a576d0175443403c15dcf8bf128f6", + "fixed_version": "5.15.39" + }, + "5.17": { + "cmt_id": "8b58d6e565d83443c51b3fc076bd4472674aca0c", + "fixed_version": "5.17.7" + }, + "5.4": { + "cmt_id": "85aecdef77f9c5b5c0d8988db6681960f0d46ab3", + "fixed_version": "5.4.193" + } + }, + "CVE-2022-1975": { + "4.14": { + "cmt_id": "c33b2afffe8ae90e0bd4790e0505edd92addf14c", + "fixed_version": "4.14.278" + }, + "4.19": { + "cmt_id": "d360fc8df363ecd7892d755d69ffc8c61d699e38", + "fixed_version": "4.19.242" + }, + "4.9": { + "cmt_id": "a93ea9595fde438996d7b9322749d4d1921162f7", + "fixed_version": "4.9.313" + }, + "5.10": { + "cmt_id": "879b075a9a364a325988d4484b74311edfef82a1", + "fixed_version": "5.10.115" + }, + "5.15": { + "cmt_id": "7bd81a05d48942ef2c48630e5e7963b187e95727", + "fixed_version": "5.15.39" + }, + "5.17": { + "cmt_id": "63a545103b77091f2309b44a8975cdf255bb99b2", + "fixed_version": "5.17.7" + }, + "5.4": { + "cmt_id": "01d4363dd7176fd780066cd020f66c0f55c4b6f9", + "fixed_version": "5.4.193" + } + }, + "CVE-2022-1998": { + "5.10": { + "cmt_id": "7b4741644cf718c422187e74fb07661ef1d68e85", + "fixed_version": "5.10.97" + }, + "5.15": { + "cmt_id": "60765e43e40fbf7a1df828116172440510fcc3e4", + "fixed_version": "5.15.20" + }, + "5.16": { + "cmt_id": "dea4fec0d87d4401b5d2717aa7c6c6cad050fb62", + "fixed_version": "5.16.6" + } + }, "CVE-2022-20008": { "4.19": { "cmt_id": "c91b06297563e84ac072464fe6cc141cc15435f0", @@ -31015,6 +31165,108 @@ "fixed_version": "5.4.181" } }, + "CVE-2022-20132": { + "4.14": { + "cmt_id": "43cc4686b15d7d3a2b65b125393ea3f3d477e7d1", + "fixed_version": "4.14.258" + }, + "4.19": { + "cmt_id": "b1efa723b986a84f84a95b6907cffe3a357338c9", + "fixed_version": "4.19.221" + }, + "4.4": { + "cmt_id": "6a0bc60a84cb5186a84e7501616dacfd9e991b54", + "fixed_version": "4.4.295" + }, + "4.9": { + "cmt_id": "28d8244f3ec961a11bfb4ad83cdc48ff9b8c47a7", + "fixed_version": "4.9.293" + }, + "5.10": { + "cmt_id": "61144329606cb9518642b7d2e940b21eb3214204", + "fixed_version": "5.10.85" + }, + "5.15": { + "cmt_id": "e1e21632a4c4d2f85587e204939883ce59d18447", + "fixed_version": "5.15.8" + }, + "5.4": { + "cmt_id": "6e1e0a01425810494ce00d7b800b69482790b198", + "fixed_version": "5.4.165" + } + }, + "CVE-2022-20141": { + "4.14": { + "cmt_id": "78967749984cf3614de346c90f3e259ff8272735", + "fixed_version": "4.14.247" + }, + "4.19": { + "cmt_id": "4768973dffed4d0126854514335ed4fe87bec1ab", + "fixed_version": "4.19.207" + }, + "4.4": { + "cmt_id": "b24065948ae6c48c9e20891f8cfe9850f1d748be", + "fixed_version": "4.4.284" + }, + "4.9": { + "cmt_id": "e9924c4204ede999b0515fd31a370a1e27f676bc", + "fixed_version": "4.9.283" + }, + "5.10": { + "cmt_id": "ddd7e8b7b84836c584a284b98ca9bd7a348a0558", + "fixed_version": "5.10.64" + }, + "5.13": { + "cmt_id": "961447ff60291b91e27d5c32fa549c1411ad3b70", + "fixed_version": "5.13.16" + }, + "5.14": { + "cmt_id": "d1a3c6d5925a8d00a32c5ef2d674dd9c0ce89c95", + "fixed_version": "5.14.3" + }, + "5.4": { + "cmt_id": "d84708451d9041dff8a81e3718f821f12d2eb6c5", + "fixed_version": "5.4.145" + } + }, + "CVE-2022-20148": { + "5.14": { + "cmt_id": "5b67adb7425e758655e464bda4eb4174ac88b625", + "fixed_version": "5.14.19" + }, + "5.15": { + "cmt_id": "5e1b901dd470659bcfeaa76811d2af9165579d77", + "fixed_version": "5.15.3" + } + }, + "CVE-2022-20153": { + "5.10": { + "cmt_id": "dc1163203ae6e24b86168390fe5b4a3295fcba7f", + "fixed_version": "5.10.107" + } + }, + "CVE-2022-20154": { + "4.14": { + "cmt_id": "8873140f95d4977bf37e4cf0d5c5e3f6e34cdd3e", + "fixed_version": "4.14.261" + }, + "4.19": { + "cmt_id": "af6e6e58f7ebf86b4e7201694b1e4f3a62cbc3ec", + "fixed_version": "4.19.224" + }, + "5.10": { + "cmt_id": "769d14abd35e0e153b5149c3e1e989a9d719e3ff", + "fixed_version": "5.10.90" + }, + "5.15": { + "cmt_id": "75799e71df1da11394740b43ae5686646179561d", + "fixed_version": "5.15.13" + }, + "5.4": { + "cmt_id": "831de271452b87657fcf8d715ee20519b79caef5", + "fixed_version": "5.4.170" + } + }, "CVE-2022-22942": { "4.14": { "cmt_id": "e8d092a62449dcfc73517ca43963d2b8f44d0516", @@ -31826,5 +32078,15 @@ "cmt_id": "2458ecd21f29a3e5571d7d97764c043083deed5e", "fixed_version": "5.4.189" } + }, + "CVE-2022-32296": { + "5.15": { + "cmt_id": "952a238d779eea4ecb2f8deb5004c8f56be79bc9", + "fixed_version": "5.15.41" + }, + "5.17": { + "cmt_id": "e3ee7bb47d6509c3e8a3e96e5d8e3bf21549b6e8", + "fixed_version": "5.17.9" + } } } \ No newline at end of file