Known Vulnerabilities for Linux Kernel by Linux

Listed below are 10 of the newest known vulnerabilities associated with the software "Linux Kernel" by "Linux".

These CVEs are retrieved based on exact matches on listed software and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-31916 An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module... Not Provided 2021-05-06 2021-05-06
CVE-2021-31829 kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of sta... Not Provided 2021-05-06 2021-05-06
CVE-2021-31795 The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allows at... Not Provided 2021-04-24 2021-04-24
CVE-2021-30178 An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereferenc... Not Provided 2021-04-07 2021-04-24
CVE-2021-30002 An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-c... Not Provided 2021-04-02 2021-04-02
CVE-2021-29650 An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of ser... Not Provided 2021-03-30 2021-04-02
CVE-2021-29649 An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak, rela... Not Provided 2021-03-30 2021-04-02
CVE-2021-29648 An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids an... Not Provided 2021-03-30 2021-04-02
CVE-2021-29647 An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensit... Not Provided 2021-03-30 2021-04-02
CVE-2021-29646 An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validat... Not Provided 2021-03-30 2021-04-02

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
LinuxLinux Kernel5.9.9AllAllAll
Operating
System
LinuxLinux Kernel5.9.7AllAllAll
Operating
System
LinuxLinux Kernel5.9.3AllAllAll
Operating
System
LinuxLinux Kernel5.9.2AllAllAll
Operating
System
LinuxLinux Kernel5.9.13AllAllAll
Operating
System
LinuxLinux Kernel5.9.1AllAllAll
Operating
System
LinuxLinux Kernel5.9.0-AllAll
Operating
System
LinuxLinux Kernel5.9.0rc1AllAll
Operating
System
LinuxLinux Kernel5.9.0rc2AllAll
Operating
System
LinuxLinux Kernel5.9.0rc3AllAll
Operating
System
LinuxLinux Kernel5.9.0rc4AllAll
Operating
System
LinuxLinux Kernel5.9.0rc5AllAll
Operating
System
LinuxLinux Kernel5.9.0rc6AllAll
Operating
System
LinuxLinux Kernel5.8.9AllAllAll
Operating
System
LinuxLinux Kernel5.8.8AllAllAll
Operating
System
LinuxLinux Kernel5.8.7AllAllAll
Operating
System
LinuxLinux Kernel5.8.6AllAllAll
Operating
System
LinuxLinux Kernel5.8.5AllAllAll
Operating
System
LinuxLinux Kernel5.8.4AllAllAll
Operating
System
LinuxLinux Kernel5.8.3AllAllAll

Popular searches for Linux Kernel


University of Minnesota banned from contributing to Linux kernel

www.theverge.com/2021/4/22/22398156/university-minnesota-linux-kernal-ban-research

D @University of Minnesota banned from contributing to Linux kernel University of Minnesota banned from contributing to Linux kernel - The Verge Email Illustration by Alex Castro / The Verge The University of Minnesota has been banned from contributing to the Linux kernel by one of its maintainers after researchers from the school apparently knowingly submitted code with security flaws. Earlier this year, two researchers from the university released a paper detailing how they had submitted known security vulnerabilities to the Linux kernel in order to show how potentially malicious code could get through the approval process. Now, after another student from the university submitted code that reportedly does nothing, kernel maintainer and Linux Foundation fellow Greg Kroah-Hartman has released a statement calling for all kernel maintainers to reject any code submissions from anyone using a umn.edu email address. In addition to not accepting any new code from the university, all of the code submitted in the past is being removed and re-reviewed. It seems like it will be a massive amount of work, but Kroah-Hartman has made it clear that the developer community doesnt appreciate being experimented on and that all of the code from the university has been called into question due to the research. The possibility of bugs slipping through is well-known in the open-source software community The university has put out a statement, saying its been made aware of the research and its subsequent ban from contributing. It says it has suspended that line of research and will be investigating how the study was approved and carried out. In a statement meant to clarify the study, the researchers said they intended to bring attention to issues with the submission process mainly, the fact that bugs, including ones that were potentially maliciously crafted, could slip through. Kernel developer Laura Abbot countered this in a blog post, saying that the possibility of bugs slipping through is well-known in the open-source software community. In what appears to be a private message, the person who submitted the reportedly nonfunctional code called Kroah-Hartmans accusations that the code was known to be invalid wild and bordering on slander. Its unclear if that submission which kicked off the current controversy was actually part of a research project. The person who submitted it did so with their umn.edu email address, while the patches submitted in the study were done through random Gmail addresses, and the submitter claimed that the faulty code was created by a tool. Kroah-Hartmans response basically said that he found it unlikely that a tool had created the code, and, given the research, he couldnt trust that the patch was made in good faith either way. Theres been criticism from some in the open-source community, saying that Kroah-Hartman deciding to pull any patches submitted by U of M personal is an overreaction, which could lead to bugs fixed by legitimate patches being reintroduced. It is worth noting, however, that the plan is to re-review the patches and to resubmit them if theyre found to be valid. Next Up In Policy Sign up for the newsletter Verge Deals Subscribe to get the best Verge-approved tech deals of the week. Email required By signing up, you agree to our Privacy Notice and European users agree to the data transfer policy. Loading comments...

Linux kernel The Verge University of Minnesota Source code Software bug Patch (computing) Kernel (operating system) Vulnerability (computing) Research Email Email address Open-source software Software maintainer Malware Programmer

Linux.org

www.linux.org

Linux.org Friendly Linux Forum

www.weblio.jp/redirect?etd=fbc3555661e192f4&url=http%3A%2F%2Fwww.linux.org%2F lugip.org www.lugip.org Linux Software Installation (computer programs) CentOS Exhibition game Calibre (software) Application software Internet forum Log file E-book APT (software) Ubuntu Glossary of video game terms Software repository Command (computing) Cross-platform software Data storage Computer program Pre-installed software Go (programming language)

© CVE.report 2021 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report