gpp_maybe
Security update for the linux kernel
SUSE-SLE-Live-Patching-12-SP5-2025-565
The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2021-47222: net: bridge: fix vlan tunnel dst refcnt when egressing (bsc#1224857). - CVE-2021-47223: net: bridge: fix vlan tunnel dst null pointer dereference (bsc#1224856). - CVE-2024-26644: btrfs: do not abort filesystem when attempting to snapshot deleted subvolume (bsc#1222072). - CVE-2024-47809: dlm: fix possible lkb_resource null dereference (bsc#1235714). - CVE-2024-48881: bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again (bsc#1235727). - CVE-2024-49948: net: add more sanity checks to qdisc_pkt_len_init() (bsc#1232161). - CVE-2024-50142: xfrm: validate new SA's prefixlen using SA family when sel.family is unset (bsc#1233028). - CVE-2024-52332: igb: Fix potential invalid memory access in igb_init_module() (bsc#1235700). - CVE-2024-53155: ocfs2: fix uninitialized value in ocfs2_file_read_iter() (bsc#1234855). - CVE-2024-53185: smb: client: fix NULL ptr deref in crypto_aead_setkey() (bsc#1234901). - CVE-2024-53197: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (bsc#1235464). - CVE-2024-53227: scsi: bfa: Fix use-after-free in bfad_im_module_exit() (bsc#1235011). - CVE-2024-55916: Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet (bsc#1235747). - CVE-2024-56369: drm/modes: Avoid divide by zero harder in drm_mode_vrefresh() (bsc#1235750). - CVE-2024-56532: ALSA: us122l: Use snd_card_free_when_closed() at disconnection (bsc#1235059). - CVE-2024-56533: ALSA: usx2y: Use snd_card_free_when_closed() at disconnection (bsc#1235053). - CVE-2024-56539: wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan() (bsc#1234963). - CVE-2024-56574: media: ts2020: fix null-ptr-deref in ts2020_probe() (bsc#1235040). - CVE-2024-56593: wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw() (bsc#1235252). - CVE-2024-56594: drm/amdgpu: set the right AMDGPU sg segment limitation (bsc#1235413). - CVE-2024-56600: net: inet6: do not leave a dangling sk pointer in inet6_create() (bsc#1235217). - CVE-2024-56601: net: inet: do not leave a dangling sk pointer in inet_create() (bsc#1235230). - CVE-2024-56615: bpf: fix OOB devmap writes when deleting elements (bsc#1235426). - CVE-2024-56623: scsi: qla2xxx: Fix use after free on unload (bsc#1235466). - CVE-2024-56630: ocfs2: free inode when ocfs2_get_init_inode() fails (bsc#1235479). - CVE-2024-56637: netfilter: ipset: Hold module reference while requesting a module (bsc#1235523). - CVE-2024-56641: net/smc: initialize close_work early to avoid warning (bsc#1235526). - CVE-2024-56643: dccp: Fix memory leak in dccp_feat_change_recv (bsc#1235132). - CVE-2024-56650: netfilter: x_tables: fix LED ID check in led_tg_check() (bsc#1235430). - CVE-2024-56662: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl (bsc#1235533). - CVE-2024-56681: crypto: bcm - add error check in the ahash_hmac_init function (bsc#1235557). - CVE-2024-56700: media: wl128x: Fix atomicity violation in fmc_send_cmd() (bsc#1235500). - CVE-2024-56722: RDMA/hns: Fix cpu stuck caused by printings during reset (bsc#1235570). - CVE-2024-56739: rtc: check if __rtc_read_time was successful in rtc_timer_do_work() (bsc#1235611). - CVE-2024-56747: scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb() (bsc#1234934). - CVE-2024-56748: scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb() (bsc#1235627). - CVE-2024-56759: btrfs: fix use-after-free when COWing tree bock and tracing is enabled (bsc#1235645). - CVE-2024-56763: tracing: Prevent bad count for tracing_cpumask_write (bsc#1235638). - CVE-2024-56769: media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg (bsc#1235155). - CVE-2024-57884: mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim() (bsc#1235948). - CVE-2024-57890: RDMA/uverbs: Prevent integer overflow issue (bsc#1235919). - CVE-2024-57896: btrfs: flush delalloc workers queue before stopping cleaner kthread during unmount (bsc#1235965). - CVE-2024-57899: wifi: mac80211: fix mbss changed flags corruption on 32 bit systems (bsc#1235924). - CVE-2024-57903: net: restrict SO_REUSEPORT to inet sockets (bsc#1235967). - CVE-2024-57922: drm/amd/display: Add check for granularity in dml ceil/floor helpers (bsc#1236080). - CVE-2024-57929: dm array: fix releasing a faulty array block twice in dm_array_cursor_end (bsc#1236096). - CVE-2024-57931: selinux: ignore unknown extended permissions (bsc#1236192). - CVE-2024-57932: gve: guard XDP xmit NDO on existence of xdp queues (bsc#1236190). - CVE-2024-57938: net/sctp: Prevent autoclose integer overflow in sctp_association_init() (bsc#1236182). - CVE-2025-21653: net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute (bsc#1236161). - CVE-2025-21664: dm thin: make get_first_thin use rcu-safe list first function (bsc#1236262). - CVE-2025-21678: gtp: Destroy device along with udp socket's netns dismantle (bsc#1236698). - CVE-2025-21682: eth: bnxt: always recalculate features after XDP clearing, fix null-deref (bsc#1236703). The following non-security bugs were fixed: - ALSA: usb-audio: Fix a DMA to stack memory bug (git-fixes). - drm/modes: Switch to 64bit maths to avoid integer overflow (bsc#1235750). - vfio/pci: Lock external INTx masking ops (bsc#1222803). - btrfs: fstests btrfs/309 fails on btrfs (bsc#1221282).
-
Release DateFeb 17 2025
-
ReferencesBugzilla: 1221282, 1222072, 1222803, 1224856, 1224857, 1232161, 1233028, 1234855, 1234901, 1234931, 1234934, 1234963, 1235011, 1235040, 1235053, 1235059, 1235132, 1235155, 1235217, 1235230, 1235252, 1235413, 1235426, 1235430, 1235433, 1235464, 1235466, 1235479, 1235500, 1235523, 1235526, 1235533, 1235557, 1235570, 1235611, 1235627, 1235638, 1235645, 1235700, 1235714, 1235727, 1235747, 1235750, 1235919, 1235924, 1235948, 1235965, 1235967, 1236080, 1236096, 1236161, 1236182, 1236190, 1236192, 1236262, 1236698, 1236703
CVEs: CVE-2021-47222, CVE-2021-47223, CVE-2024-26644, CVE-2024-47809, CVE-2024-48881, CVE-2024-49948, CVE-2024-50142, CVE-2024-52332, CVE-2024-53155, CVE-2024-53185, CVE-2024-53197, CVE-2024-53227, CVE-2024-55916, CVE-2024-56369, CVE-2024-56532, CVE-2024-56533, CVE-2024-56539, CVE-2024-56574, CVE-2024-56593, CVE-2024-56594, CVE-2024-56600, CVE-2024-56601, CVE-2024-56615, CVE-2024-56623, CVE-2024-56630, CVE-2024-56637, CVE-2024-56641, CVE-2024-56643, CVE-2024-56650, CVE-2024-56661, CVE-2024-56662, CVE-2024-56681, CVE-2024-56700, CVE-2024-56722, CVE-2024-56739, CVE-2024-56747, CVE-2024-56748, CVE-2024-56759, CVE-2024-56763, CVE-2024-56769, CVE-2024-57884, CVE-2024-57890, CVE-2024-57896, CVE-2024-57899, CVE-2024-57903, CVE-2024-57922, CVE-2024-57929, CVE-2024-57931, CVE-2024-57932, CVE-2024-57938, CVE-2025-21653, CVE-2025-21664, CVE-2025-21678, CVE-2025-21682 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Live Patching 12.5 s390x
-
Packageskernel-default
The Standard Kernelkernel-default-kgraft4.12.14-122.247.1lock nosrc
Metapackage to pull in matching kgraft-patch packagekernel-default-kgraft-devel4.12.14-122.247.1lock rpm
Kernel symbols file used during kGraft patch developmentkgraft-patch-4_12_14-122_247-default4.12.14-122.247.1lock rpm
Kgraft patch modulekgraft-patch-SLE12-SP5_Update_651-8.3.1lock rpm
Kgraft patch module1-8.3.1lock src
SUSE Linux Enterprise Live Patching 12.5 ppc64le
-
Packageskernel-default
The Standard Kernelkernel-default-kgraft4.12.14-122.247.1lock nosrc
Metapackage to pull in matching kgraft-patch packagekernel-default-kgraft-devel4.12.14-122.247.1lock rpm
Kernel symbols file used during kGraft patch developmentkgraft-patch-4_12_14-122_247-default4.12.14-122.247.1lock rpm
Kgraft patch modulekgraft-patch-SLE12-SP5_Update_651-8.3.1lock rpm
Kgraft patch module1-8.3.1lock src
SUSE Linux Enterprise Live Patching 12.5 x86_64
-
Packageskernel-default
The Standard Kernelkernel-default-kgraft4.12.14-122.247.1lock nosrc
Metapackage to pull in matching kgraft-patch packagekernel-default-kgraft-devel4.12.14-122.247.1lock rpm
Kernel symbols file used during kGraft patch developmentkgraft-patch-4_12_14-122_247-default4.12.14-122.247.1lock rpm
Kgraft patch modulekgraft-patch-SLE12-SP5_Update_651-8.3.1lock rpm
Kgraft patch module1-8.3.1lock src