gpp_maybe
Security update for the linux kernel
SUSE-SLE-Micro-5.4-2024-4346
The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2024-26782: mptcp: fix double-free on socket dismantle (bsc#1222590). - CVE-2024-44932: idpf: fix UAFs when destroying the queues (bsc#1229808). - CVE-2024-44964: idpf: fix memory leaks and crashes while performing a soft reset (bsc#1230220). - CVE-2024-47757: nilfs2: fix potential oob read in nilfs_btree_check_delete() (bsc#1232187). - CVE-2024-50089: unicode: Do not special case ignorable code points (bsc#1232860). - CVE-2024-50115: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory (bsc#1232919). - CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout (bsc#1232928). - CVE-2024-50127: net: sched: fix use-after-free in taprio_change() (bsc#1232907). - CVE-2024-50154: tcp: Fix use-after-free of nreq in reqsk_timer_handler() (bsc#1233070). - CVE-2024-50205: ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size() (bsc#1233293). - CVE-2024-50259: netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write() (bsc#1233214). - CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans (bsc#1233453). - CVE-2024-50267: USB: serial: io_edgeport: fix use after free in debug printk (bsc#1233456). - CVE-2024-50274: idpf: avoid vport access in idpf_get_link_ksettings (bsc#1233463). - CVE-2024-50279: dm cache: fix out-of-bounds access to the dirty bitset when resizing (bsc#1233468). - CVE-2024-50290: media: cx24116: prevent overflows on SNR calculus (bsc#1233479). - CVE-2024-50301: security/keys: fix slab-out-of-bounds in key_task_permission (bsc#1233490). - CVE-2024-50302: HID: core: zero-initialize the report buffer (bsc#1233491). - CVE-2024-53061: media: s5p-jpeg: prevent buffer overflows (bsc#1233555). - CVE-2024-53063: media: dvbdev: prevent the risk of out of memory access (bsc#1233557). - CVE-2024-53068: firmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier() (bsc#1233561). The following non-security bugs were fixed: - Update config files (bsc#1218644). - Update config files. Enabled IDPF for ARM64 (bsc#1221309) - kernel-binary: Enable livepatch package only when livepatch is enabled Otherwise the filelist may be empty failing the build (bsc#1218644). - mm/memory: add non-anonymous page check in the copy_present_page() (bsc#1231646). - rpm/scripts: Remove obsolete Symbols.list Symbols.list is not longer needed by the new klp-convert implementation. (bsc#1218644)
-
Release DateDec 17 2024
-
ReferencesBugzilla: 1218644, 1220382, 1221309, 1222590, 1229808, 1230220, 1231646, 1232187, 1232312, 1232860, 1232907, 1232919, 1232928, 1233070, 1233214, 1233293, 1233453, 1233456, 1233463, 1233468, 1233479, 1233490, 1233491, 1233555, 1233557, 1233561, 1233977
CVEs: CVE-2023-52922, CVE-2024-26782, CVE-2024-44932, CVE-2024-44964, CVE-2024-47757, CVE-2024-50017, CVE-2024-50089, CVE-2024-50115, CVE-2024-50125, CVE-2024-50127, CVE-2024-50154, CVE-2024-50205, CVE-2024-50259, CVE-2024-50264, CVE-2024-50267, CVE-2024-50274, CVE-2024-50279, CVE-2024-50290, CVE-2024-50301, CVE-2024-50302, CVE-2024-53061, CVE-2024-53063, CVE-2024-53068 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Micro 5.4 aarch64
-
Packageskernel-default
The Standard Kernelkernel-default-base5.14.21-150400.24.144.1 lock rpm lock nosrc
The Standard Kernel - base modules5.14.21-150400.24.144.1.150400.24.70.1 lock rpm lock src
SUSE Linux Enterprise Micro 5.4 s390x
-
Packages
SUSE Linux Enterprise Micro 5.4 x86_64
-
Packageskernel-default
The Standard Kernelkernel-default-base5.14.21-150400.24.144.1 lock rpm lock nosrc
The Standard Kernel - base modules5.14.21-150400.24.144.1.150400.24.70.1 lock rpm lock src