ALAS2LIVEPATCH-2020-002 --- kernel-livepatch-4.14.165-133.209ID: oval:org.secpod.oval:def:1700484 | Date: (C)2020-11-24 (M)2024-04-17 |
Class: PATCH | Family: unix |
An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely updated after a change from smb30 to smb21.In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
Product: |
kernel-livepatch-4.14.165-133.209 |