Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE
handler in rxrpc_verify_response() copy the skb to a linear one ...
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decrypt on shared skb frags
MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths ...
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.
There is no benefit in operating in-place in algif_aead since ...
A vulnerability classified as problematic was found in Linux Kernel up to 6.12.12/6.13.1. Affected by this issue is some unknown functionality. The manipulation results in insufficient verification of data authenticity.
This vulnerability was named CVE-2024-57999. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability described as critical has been identified in Linux Kernel up to 6.6.75/6.12.12/6.13.1. This vulnerability affects the function _read_freq. Such manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2024-57998. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Linux Kernel up to 6.13.1. This issue affects the function array_index_nospec. Performing a manipulation results in infinite loop.
This vulnerability is reported as CVE-2024-58000. The attacker must have access to the local network to execute the attack. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability marked as problematic has been reported in Linux Kernel up to 6.1.128/6.6.75/6.12.12/6.13.1. This impacts an unknown function of the file net/sched/sch_sfq.c of the component net_sched. Performing a manipulation results in improper validation of array index.
This vulnerability is known as CVE-2024-57996. Access to the local network is required for this attack. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability marked as problematic has been reported in Linux Kernel up to 6.1.128/6.6.75/6.12.12/6.13.1. This issue affects the function wcn->chan_survey. This manipulation causes improper initialization.
This vulnerability appears as CVE-2024-57997. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.12.12/6.13.1. This affects the function ptr_ring_resize_multiple of the file net/core/page_pool.c. This manipulation causes reachable assertion.
The identification of this vulnerability is CVE-2024-57994. The attack needs to be done within the local network. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.1.128/6.6.75/6.12.12/6.13.1. Affected by this issue is the function thrustmaster_probe. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2024-57993. The attack must originate from the local network. There is no exploit available.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.13.1. This affects the function ath12k_mac_assign_vif_to_vdev. This manipulation causes use after free.
This vulnerability is registered as CVE-2024-57995. The attack requires access to the local network. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.12/6.13.1. It has been rated as problematic. This impacts the function mt7925_load_clc. Performing a manipulation results in off-by-one.
This vulnerability is identified as CVE-2024-57990. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.13.1. Affected is the function rtw89_entity_recalc_mgnt_roles of the file chan.c. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2024-57991. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.13.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to denial of service.
This vulnerability is listed as CVE-2024-57992. The attack must be carried out from within the local network. There is no available exploit.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.12/6.13.1. It has been classified as critical. The impacted element is the function btbcm_get_board_name. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2024-57988. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.12.12/6.13.1. It has been declared as critical. This affects the function mt7925_change_vif_links of the component mt76. Such manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2024-57989. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.128/6.6.75/6.12.12/6.13.1. This vulnerability affects the function hid_apply_multipler. The manipulation results in infinite loop.
This vulnerability is reported as CVE-2024-57986. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
A vulnerability was found in Linux Kernel up to 6.12.12/6.13.1 and classified as critical. The affected element is the function btrtl_setup_realtek. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2024-57987. The attack needs to be approached within the local network. There is no available exploit.
It is suggested to upgrade the affected component.