A vulnerability was found in Linux Kernel up to 5.14.5 (Operating System). It has been declared as critical. Affected by this vulnerability is the function aspeed_lpc_ctrl_mmap
of the file drivers/soc/aspeed/aspeed-lpc-ctrl.c of the component Aspeed LPC Control Interface. Upgrading to version 5.14.6 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at git.kernel.org. The best possible mitigation is suggested to be upgrading to the latest version.
Linux Kernel up to 5.14.5 Aspeed LPC Control Interface aspeed-lpc-ctrl.c aspeed_lpc_ctrl_mmap comparison
- Virtual Patching
- October 12, 2021
- 9:05 am
CVE-2024-49592 : MCAFEE TRIAL INSTALLER 16.0.53 ACCESS CONTROL
Description McAfee Trial Installer 16.0.53 has Incorrect Access Control that leads to Local Escalation of Privileges. References https://www.mcafee.com/support/s/article/000002516?language=en_US For More
CVE-2024-10934 : OPENBSD UP TO 7.4 ERRATA 020/7.5 ERRATA 007 NFS CLIENT/NFS SERVER DOUBLE FREE
Description In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS
CVE-2024-40638 : GLPI UP TO 10.0.16 SQL INJECTION
Description GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities.