It was discovered that the NTFS file system implementation in the Linux
kernel did not properly validate MFT flags in certain situations. An
attacker could use this to construct a malicious NTFS image that, when
mounted and operated on, could cause a denial of service (system crash).
(CVE-2022-48425)
Zi Fan Tan discovered that the binder IPC implementation in the Linux
kernel contained a use-after-free vulnerability. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2023-21255)
It was discovered that a race condition existed in the f2fs file system in
the Linux kernel, leading to a null pointer dereference vulnerability. An
attacker could use this to construct a malicious f2fs image that, when
mounted and operated on, could cause a denial of service (system crash).
(CVE-2023-2898)
It was discovered that the DVB Core driver in the Linux kernel did not
properly handle locking events in certain situations. A local attacker
could use this to cause a denial of service (kernel deadlock).
(CVE-2023-31084)
Yang Lan discovered that the GFS2 file system implementation in the Linux
kernel could attempt to dereference a null pointer in some situations. An
attacker could use this to construct a malicious GFS2 image that, when
mounted and operated on, could cause a denial of service (system crash).
(CVE-2023-3212)
It was discovered that the KSMBD implementation in the Linux kernel did not
properly validate buffer sizes in certain operations, leading to an out-of-
bounds read vulnerability. A remote attacker could use this to cause a
denial of service (system crash) or possibly expose sensitive information.
(CVE-2023-38426, CVE-2023-38428)
It was discovered that the KSMBD implementation in the Linux kernel did not
properly calculate the size of certain buffers. A remote attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2023-38429)
More Stories
CVE-2022-35908
Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent. Read More
thunderbird-115.3.1-1.fc39
FEDORA-2023-1afa208698 Packages in this update: thunderbird-115.3.1-1.fc39 Update description: Update to 115.3.1 ; https://www.thunderbird.net/en-US/thunderbird/115.3.1/releasenotes/ ; https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/ Update to 115.3.0 ; https://www.thunderbird.net/en-US/thunderbird/115.3.0/releasenotes/...
libptytty-2.0-4.el7 rxvt-unicode-9.31-1.el7
FEDORA-EPEL-2023-a99c56df6a Packages in this update: libptytty-2.0-4.el7 rxvt-unicode-9.31-1.el7 Update description: The last update for rxvt-unicode stripped it down to just the...
libvpx-1.13.0-5.fc39
FEDORA-2023-10ff82e497 Packages in this update: libvpx-1.13.0-5.fc39 Update description: Security fix for CVE-2023-5217 Read More
libvpx-1.12.0-3.fc37
FEDORA-2023-f696934fbf Packages in this update: libvpx-1.12.0-3.fc37 Update description: Security fix for CVE-2023-5217 Read More
libvpx-1.13.0-5.fc38
FEDORA-2023-c896cf87db Packages in this update: libvpx-1.13.0-5.fc38 Update description: Security fix for CVE-2023-5217 Read More