Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Yang Lan discovered that the GFS2 file system implementation in the Linux
kernel could attempt to dereference a null pointer in some situations. An
attacker could use this to construct a malicious GFS2 image that, when
mounted and operated on, could cause a denial of service (system crash).
(CVE-2023-3212)
It was discovered that the NET/ROM protocol implementation in the Linux
kernel contained a race condition in some situations, leading to a use-
after-free vulnerability. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2023-32269)
It was discovered that the NFC implementation in the Linux kernel contained
a use-after-free vulnerability when performing peer-to-peer communication
in certain conditions. A privileged attacker could use this to cause a
denial of service (system crash) or possibly expose sensitive information
(kernel memory). (CVE-2023-3863)
It was discovered that the bluetooth subsystem in the Linux kernel did not
properly handle L2CAP socket release, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-40283)
It was discovered that some network classifier implementations in the Linux
kernel contained use-after-free vulnerabilities. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2023-4128)
It was discovered that the JFS file system implementation in the Linux
kernel did not properly validate memory allocations in certain situations,
leading to a null pointer dereference vulnerability. An attacker could use
this to construct a malicious JFS image that, when mounted, could cause a
denial of service (system crash). (CVE-2023-4385)
It was discovered that the VMware VMXNET3 ethernet driver in the Linux
kernel contained a use-after-free vulnerability in certain situations. A
local attacker in a guest VM could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-4387)
It was discovered that the VMware VMXNET3 ethernet driver in the Linux
kernel did not properly handle errors in certain situations, leading to a
null pointer dereference vulnerability. A local attacker in a guest VM
could use this to cause a denial of service (system crash). (CVE-2023-4459)
More Stories
CVE-2022-35908
Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent. Read More
thunderbird-115.3.1-1.fc39
FEDORA-2023-1afa208698 Packages in this update: thunderbird-115.3.1-1.fc39 Update description: Update to 115.3.1 ; https://www.thunderbird.net/en-US/thunderbird/115.3.1/releasenotes/ ; https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/ Update to 115.3.0 ; https://www.thunderbird.net/en-US/thunderbird/115.3.0/releasenotes/...
libptytty-2.0-4.el7 rxvt-unicode-9.31-1.el7
FEDORA-EPEL-2023-a99c56df6a Packages in this update: libptytty-2.0-4.el7 rxvt-unicode-9.31-1.el7 Update description: The last update for rxvt-unicode stripped it down to just the...
libvpx-1.13.0-5.fc39
FEDORA-2023-10ff82e497 Packages in this update: libvpx-1.13.0-5.fc39 Update description: Security fix for CVE-2023-5217 Read More
libvpx-1.12.0-3.fc37
FEDORA-2023-f696934fbf Packages in this update: libvpx-1.12.0-3.fc37 Update description: Security fix for CVE-2023-5217 Read More
libvpx-1.13.0-5.fc38
FEDORA-2023-c896cf87db Packages in this update: libvpx-1.13.0-5.fc38 Update description: Security fix for CVE-2023-5217 Read More