This thread has been locked.

If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.

TDA4VM-Q1: Vulnerability of TDA4 linux SDK

Part Number: TDA4VM-Q1

Tool/software:

There are a lot of CVE vulnerabilities in the TDA4 linux SDK, Our customers need us to fix all of these vulnerabilities, we can find some patch in yocto website, but most of these vulnerabilities patches can't be found in yocto website, for these, How did you deal with it? 

  • Hi Zhu,

    Can you please be more specific?  

    Our customers need us to fix all of these vulnerabilities

    Can you list them?

    - Keerthy

  • Like: 

    Product Version CVE ID
    linux_kernel 5.4.106 CVE-2021-4154
    linux_kernel 5.4.106 CVE-2023-4128
    linux_kernel 5.4.106 CVE-2023-42753
    linux_kernel 5.4.106 CVE-2023-0461
    linux_kernel 5.4.106 CVE-2023-38428
    linux_kernel 5.4.106 CVE-2023-32250
    linux_kernel 5.4.106 CVE-2022-2978
    linux_kernel 5.4.106 CVE-2022-33740
    linux_kernel 5.4.106 CVE-2021-3773
    linux_kernel 5.4.106 CVE-2022-4378
    linux_kernel 5.4.106 CVE-2022-4139
    linux_kernel 5.4.106 CVE-2022-48425
    linux_kernel 5.4.106 CVE-2022-26365
    linux_kernel 5.4.106 CVE-2023-38431
    linux_kernel 5.4.106 CVE-2022-48423
    linux_kernel 5.4.106 CVE-2022-3176
    linux_kernel 5.4.106 CVE-2022-1012
    linux_kernel 5.4.106 CVE-2023-32247
    linux_kernel 5.4.106 CVE-2023-0240
    linux_kernel 5.4.106 CVE-2022-0492
    linux_kernel 5.4.106 CVE-2023-35824
    linux_kernel 5.4.106 CVE-2022-2977
    linuxptp 3.0 CVE-2021-3570
    linux_kernel 5.4.106 CVE-2023-38427
    linux_kernel 5.4.106 CVE-2023-38429
    linux_kernel 5.4.106 CVE-2023-32257
    linux_kernel 5.4.106 CVE-2023-35823
    linux_kernel 5.4.106 CVE-2021-38202
    linux_kernel 5.4.106 CVE-2023-26242
    linux_kernel 5.4.106 CVE-2023-32252
    linux_kernel 5.4.106 CVE-2023-4207
    linux_kernel 5.4.106 CVE-2022-3623
    linux_kernel 5.4.106 CVE-2023-1118
    linux_kernel 5.4.106 CVE-2023-1838
    linux_kernel 5.4.106 CVE-2023-1989
    linux_kernel 5.4.106 CVE-2023-3776
    linux_kernel 5.4.106 CVE-2022-0850
    linux_kernel 5.4.106 CVE-2023-5345
    linux_kernel 5.4.106 CVE-2022-3239
    linux_kernel 5.4.106 CVE-2022-3625
    linux_kernel 5.4.106 CVE-2023-2008
    linux_kernel 5.4.106 CVE-2022-1729
    linux_kernel 5.4.106 CVE-2023-3812
    linux_kernel 5.4.106 CVE-2023-1872
    linux_kernel 5.4.106 CVE-2023-32258
    linux_kernel 5.4.106 CVE-2022-36946
    linux_kernel 5.4.106 CVE-2021-3847
    linux_kernel 5.4.106 CVE-2023-32248
    linux_kernel 5.4.106 CVE-2021-35039
    linux_kernel 5.4.106 CVE-2023-44466
    linux_kernel 5.4.106 CVE-2022-33741
    linux_kernel 5.4.106 CVE-2023-38432
    linux_kernel 5.4.106 CVE-2023-26607
    linux_kernel 5.4.106 CVE-2021-38201
    linux_kernel 5.4.106 CVE-2023-32254
    linuxptp 3.0 CVE-2021-3571
    linux_kernel 5.4.106 CVE-2023-2007
    linux_kernel 5.4.106 CVE-2023-3567
    linux_kernel 5.4.106 CVE-2023-1829
    linux_kernel 5.4.106 CVE-2023-4622
    linux_kernel 5.4.106 CVE-2023-2163
    linux_kernel 5.4.106 CVE-2023-22995
    linux_kernel 5.4.106 CVE-2023-3269
    linux_kernel 5.4.106 CVE-2022-1419
    linux_kernel 5.4.106 CVE-2022-48502
    linux_kernel 5.4.106 CVE-2023-0266
    linux_kernel 5.4.106 CVE-2023-4004
    linux_kernel 5.4.106 CVE-2023-38426
    linux_kernel 5.4.106 CVE-2022-33742
    linux_kernel 5.4.106 CVE-2022-29582
    linux_kernel 5.4.106 CVE-2023-38430
  • Hello Zhu,

    May I know the source for this and what each corresponds to. This needs to be evaluated by internal team. More details will help us.

    - Keerthy

  • hi Keerthy,

    For more details about these CVE vulnerabilities, pls search it in CVE website.

    Product
    Version CVE ID Description Published Date
    linux_kernel 5.4.106 CVE-2021-4154 A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system. 2022-02-04T23:15Z
    linux_kernel 5.4.106 CVE-2023-4128 A use-after-free flaw was found in net/sched/cls_fw.c in classifiers (cls_fw, cls_u32, and cls_route) in the Linux Kernel. This flaw allows a local attacker to perform a local privilege escalation due to incorrect handling of the existing filter, leading to a kernel information leak issue. 2023-08-10T17:15Z
    linux_kernel 5.4.106 CVE-2023-42753 An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system. 2023-09-25T21:15Z
    linux_kernel 5.4.106 CVE-2023-0461 There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not require any privilege.

    There is a use-after-free bug of icsk_ulp_data of a struct inet_connection_sock.

    When CONFIG_TLS is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable.

    The setsockopt TCP_ULP operation does not require any privilege.

    We recommend upgrading past commit 2c02d41d71f90a5168391b6a5f2954112ba2307c
    2023-02-28T15:15Z
    linux_kernel 5.4.106 CVE-2023-38428 An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read. 2023-07-18T00:15Z
    linux_kernel 5.4.106 CVE-2023-32250 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. 2023-07-10T16:15Z
    linux_kernel 5.4.106 CVE-2022-2978 A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system. 2022-08-24T16:15Z
    linux_kernel 5.4.106 CVE-2022-33740 Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742). 2022-07-05T13:15Z
    linux_kernel 5.4.106 CVE-2021-3773 A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks. 2022-02-16T19:15Z
    linux_kernel 5.4.106 CVE-2022-4378 A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system. 2023-01-05T16:15Z
    linux_kernel 5.4.106 CVE-2022-4139 An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system. 2023-01-27T18:15Z
    linux_kernel 5.4.106 CVE-2022-48425 In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs. 2023-03-19T03:15Z
    linux_kernel 5.4.106 CVE-2022-26365 Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742). 2022-07-05T13:15Z
    linux_kernel 5.4.106 CVE-2023-38431 An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to an out-of-bounds read. 2023-07-18T00:15Z
    linux_kernel 5.4.106 CVE-2022-48423 In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur. 2023-03-19T03:15Z
    linux_kernel 5.4.106 CVE-2022-3176 There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle POLLFREE. This allows a use-after-free to occur if a signalfd or binder fd is polled with io_uring poll, and the waitqueue gets freed. We recommend upgrading past commit fc78b2fc21f10c4c9c4d5d659a685710ffa63659 2022-09-16T14:15Z
    linux_kernel 5.4.106 CVE-2022-1012 A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem. 2022-08-05T16:15Z
    linux_kernel 5.4.106 CVE-2023-32247 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_SESSION_SETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. 2023-07-24T16:15Z
    linux_kernel 5.4.106 CVE-2023-0240 There is a logic error in io_uring's implementation which can be used to trigger a use-after-free vulnerability leading to privilege escalation. In the io_prep_async_work function the assumption that the last io_grab_identity call cannot return false is not true, and in this case the function will use the init_cred or the previous linked requests identity to do operations instead of using the current identity. This can lead to reference counting issues causing use-after-free. We recommend upgrading past version 5.10.161. 2023-01-30T14:15Z
    linux_kernel 5.4.106 CVE-2022-0492 A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly. 2022-03-03T19:15Z
    linux_kernel 5.4.106 CVE-2023-35824 An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c. 2023-06-18T22:15Z
    linux_kernel 5.4.106 CVE-2022-2977 A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possible to escalate privileges on the system. 2022-09-14T21:15Z
    linuxptp 3.0 CVE-2021-3570 A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw affects linuxptp versions before 3.1.1, before 2.0.1, before 1.9.3, before 1.8.1, before 1.7.1, before 1.6.1 and before 1.5.1. 2021-07-09T11:15Z
    linux_kernel 5.4.106 CVE-2023-38427 An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts. 2023-07-18T00:15Z
    linux_kernel 5.4.106 CVE-2023-38429 An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access. 2023-07-18T00:15Z
    linux_kernel 5.4.106 CVE-2023-32257 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. 2023-07-24T16:15Z
    linux_kernel 5.4.106 CVE-2023-35823 An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c. 2023-06-18T22:15Z
    linux_kernel 5.4.106 CVE-2021-38202 fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. 2021-08-08T20:15Z
    linux_kernel 5.4.106 CVE-2023-26242 afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow. 2023-02-21T01:15Z
    linux_kernel 5.4.106 CVE-2023-32252 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. 2023-07-24T16:15Z
    linux_kernel 5.4.106 CVE-2023-4207 A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation.

    When fw_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free.

    We recommend upgrading past commit 76e42ae831991c828cffa8c37736ebfb831ad5ec.
    2023-09-06T14:15Z
    linux_kernel 5.4.106 CVE-2022-3623 A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function follow_page_pte of the file mm/gup.c of the component BPF. The manipulation leads to race condition. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211921 was assigned to this vulnerability. 2022-10-20T20:15Z
    linux_kernel 5.4.106 CVE-2023-1118 A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device. A local user could use this flaw to crash the system or potentially escalate their privileges on the system. 2023-03-02T18:15Z
    linux_kernel 5.4.106 CVE-2023-1838 A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash the system, and could even lead to a kernel information leak problem. 2023-04-05T19:15Z
    linux_kernel 5.4.106 CVE-2023-1989 A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race problem leading to a UAF on hdev devices. 2023-04-11T21:15Z
    linux_kernel 5.4.106 CVE-2023-3776 A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation.

    If tcf_change_indev() fails, fw_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.

    We recommend upgrading past commit 0323bce598eea038714f941ce2b22541c46d488f.
    2023-07-21T21:15Z
    linux_kernel 5.4.106 CVE-2022-0850 A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace. 2022-08-29T15:15Z
    linux_kernel 5.4.106 CVE-2023-5345 A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation.

    In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free.

    We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705.
    2023-10-03T03:15Z
    linux_kernel 5.4.106 CVE-2022-3239 A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards. A local user could use this flaw to crash the system or potentially escalate their privileges on the system. 2022-09-19T20:15Z
    linux_kernel 5.4.106 CVE-2022-3625 A vulnerability was found in Linux Kernel. It has been classified as critical. This affects the function devlink_param_set/devlink_param_get of the file net/core/devlink.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211929 was assigned to this vulnerability. 2022-10-21T06:15Z
    linux_kernel 5.4.106 CVE-2023-2008 A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an array. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. 2023-04-14T21:15Z
    linux_kernel 5.4.106 CVE-2022-1729 A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc. 2022-09-01T21:15Z
    linux_kernel 5.4.106 CVE-2023-3812 An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system. 2023-07-24T16:15Z
    linux_kernel 5.4.106 CVE-2023-1872 A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation.

    The io_file_get_fixed function lacks the presence of ctx->uring_lock which can lead to a Use-After-Free vulnerability due a race condition with fixed files getting unregistered.

    We recommend upgrading past commit da24142b1ef9fd5d36b76e36bab328a5b27523e8.
    2023-04-12T16:15Z
    linux_kernel 5.4.106 CVE-2023-32258 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. 2023-07-24T16:15Z
    linux_kernel 5.4.106 CVE-2022-36946 nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len. 2022-07-27T20:15Z
    linux_kernel 5.4.106 CVE-2021-3847 An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system. 2022-04-01T23:15Z
    linux_kernel 5.4.106 CVE-2023-32248 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. 2023-07-24T16:15Z
    linux_kernel 5.4.106 CVE-2021-35039 kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument. 2021-07-07T01:15Z
    linux_kernel 5.4.106 CVE-2023-44466 An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32. 2023-09-29T06:15Z
    linux_kernel 5.4.106 CVE-2022-33741 Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742). 2022-07-05T13:15Z
    linux_kernel 5.4.106 CVE-2023-38432 An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read. 2023-07-18T00:15Z
    linux_kernel 5.4.106 CVE-2023-26607 In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. 2023-02-26T23:15Z
    linux_kernel 5.4.106 CVE-2021-38201 net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations. 2021-08-08T20:15Z
    linux_kernel 5.4.106 CVE-2023-32254 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel. 2023-07-10T16:15Z
    linuxptp 3.0 CVE-2021-3571 A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1. 2021-07-09T11:15Z
    linux_kernel 5.4.106 CVE-2023-2007 The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel. 2023-04-24T23:15Z
    linux_kernel 5.4.106 CVE-2023-3567 A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. 2023-07-24T16:15Z
    linux_kernel 5.4.106 CVE-2023-1829 A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root.
    We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.
    2023-04-12T12:15Z
    linux_kernel 5.4.106 CVE-2023-4622 A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation.

    The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free.

    We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.
    2023-09-06T14:15Z
    linux_kernel 5.4.106 CVE-2023-2163 Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe
    code paths being incorrectly marked as safe, resulting in arbitrary read/write in
    kernel memory, lateral privilege escalation, and container escape.
    2023-09-20T06:15Z
    linux_kernel 5.4.106 CVE-2023-22995 In the Linux kernel before 5.17, an error path in dwc3_qcom_acpi_register_core in drivers/usb/dwc3/dwc3-qcom.c lacks certain platform_device_put and kfree calls. 2023-02-28T05:15Z
    linux_kernel 5.4.106 CVE-2023-3269 A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges. 2023-07-11T12:15Z
    linux_kernel 5.4.106 CVE-2022-1419 The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_gem_object *(created in *vgem_gem_dumb_create*) concurrently, and *vgem_gem_dumb_create *will access the freed drm_vgem_gem_object. 2022-06-02T14:15Z
    linux_kernel 5.4.106 CVE-2022-48502 An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c. 2023-05-31T20:15Z
    linux_kernel 5.4.106 CVE-2023-0266 A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e 2023-01-30T14:15Z
    linux_kernel 5.4.106 CVE-2023-4004 A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system. 2023-07-31T17:15Z
    linux_kernel 5.4.106 CVE-2023-38426 An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length. 2023-07-18T00:15Z
    linux_kernel 5.4.106 CVE-2022-33742 Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend (CVE-2022-33741, CVE-2022-33742). 2022-07-05T13:15Z
    linux_kernel 5.4.106 CVE-2022-29582 In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently. 2022-04-22T16:15Z
    linux_kernel 5.4.106 CVE-2023-38430 An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an out-of-bounds read. 2023-07-18T00:15Z
  • Thanks for the details. I will get back to you after I discuss with the internal team by end of next week.

    - Keerthy

  • Hi,

    These are generic Linux kernel fixes. Typically the fixes are sent pushed to the older kernel branches as well. One thing that will help is to migrate to the latest LTS branch of the kernel and check for the fixes. 

    Best Regards,

    Keerthy 

  • But linux keneral for TDA4  is used yocto compiling environment, How does generic linux kernel fixes apply to TDA4? Do you have some fix suggestions? or Do you have already done in yocto website?

  • Zhu,

    Based on the LTS kernel version that you are using. Example: 9.x SDK has the 6.1 kernel version. You will need to pull the upstream lts stable branch on top. We have the SDK branched out of 6.1 tag.

    Best Regards,

    Keerthy