gpp_maybe Security update for the linux kernel
SUSE-SLE-Micro-5.4-2025-2262


The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-49110: netfilter: conntrack: revisit gc autotuning (bsc#1237981). - CVE-2022-49139: Bluetooth: fix null ptr deref on hci_sync_conn_complete_evt (bsc#1238032). - CVE-2022-49767: 9p/trans_fd: always use O_NONBLOCK read/write (bsc#1242493). - CVE-2022-49775: tcp: cdg: allow tcp_cdg_release() to be called multiple times (bsc#1242245). - CVE-2022-49858: octeontx2-pf: Fix SQE threshold checking (bsc#1242589). - CVE-2023-53058: net/mlx5: E-Switch, Fix an Oops in error handling code (bsc#1242237). - CVE-2023-53060: igb: revert rtnl_lock() that causes deadlock (bsc#1242241). - CVE-2023-53064: iavf: Fix hang on reboot with ice (bsc#1242222). - CVE-2023-53066: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info (bsc#1242227). - CVE-2023-53079: net/mlx5: Fix steering rules cleanup (bsc#1242765). - CVE-2023-53114: i40e: Fix kernel crash during reboot when adapter is in recovery mode (bsc#1242398). - CVE-2023-53134: bnxt_en: Avoid order-5 memory allocation for TPA data (bsc#1242380) - CVE-2024-53168: net: make sock_inuse_add() available (bsc#1234887). - CVE-2024-56558: nfsd: make sure exp active before svc_export_show (bsc#1235100). - CVE-2025-21888: RDMA/mlx5: Fix a WARN during dereg_mr for DM type (bsc#1240177). - CVE-2025-21999: proc: fix UAF in proc_get_inode() (bsc#1240802). - CVE-2025-22056: netfilter: nft_tunnel: fix geneve_opt type confusion addition (bsc#1241525). - CVE-2025-22060: net: mvpp2: Prevent parser TCAM memory corruption (bsc#1241526). - CVE-2025-23138: watch_queue: fix pipe accounting mismatch (bsc#1241648). - CVE-2025-23145: mptcp: fix NULL pointer in can_accept_new_subflow (bsc#1242596). - CVE-2025-37785: ext4: fix OOB read when checking dotdot dir (bsc#1241640). - CVE-2025-37789: net: openvswitch: fix nested key length validation in the set() action (bsc#1242762). The following non-security bugs were fixed: - Refresh fixes for cBPF issue (bsc#1242778) - Remove debug flavor (bsc#1243919). - Update metadata and put them into the sorted part of the series - arm64: bpf: Add BHB mitigation to the epilogue for cBPF programs (bsc#1242778). - arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users (bsc#1242778). - arm64: insn: Add support for encoding DSB (bsc#1242778). - arm64: proton-pack: Add new CPUs 'k' values for branch mitigation (bsc#1242778). - arm64: proton-pack: Expose whether the branchy loop k value (bsc#1242778). - arm64: proton-pack: Expose whether the platform is mitigated by firmware (bsc#1242778). - hv: Allow vmbus_sendpacket_mpb_desc() to create multiple ranges (bsc#1243737). - hv_netvsc: Preserve contiguous PFN grouping in the page buffer array (bsc#1243737). - hv_netvsc: Remove rmsg_pgcnt (bsc#1243737). - hv_netvsc: Use vmbus_sendpacket_mpb_desc() to send VMBus messages (bsc#1243737). - mtd: phram: Add the kernel lock down check (bsc#1232649). - ocfs2: fix the issue with discontiguous allocation in the global_bitmap (git-fixes). - powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW (bsc#1218470 ltc#204531). - scsi: core: Fix unremoved procfs host directory regression (git-fixes). - scsi: storvsc: Set correct data length for sending SCSI command without payload (git-fixes). - x86/bhi: Do not set BHI_DIS_S in 32-bit mode (bsc#1242778). - x86/bpf: Add IBHF call at end of classic BPF (bsc#1242778). - x86/bpf: Call branch history clearing sequence on exit (bsc#1242778).


cloud_download Downloads

SUSE Linux Enterprise Micro 5.4 s390x
  • Packages
    kernel-default
    The Standard Kernel
    5.14.21-150400.24.167.1 lock rpm lock nosrc
SUSE Linux Enterprise Micro 5.4 x86_64
  • Packages
    kernel-default
    The Standard Kernel
    5.14.21-150400.24.167.1 lock rpm lock nosrc
    kernel-default-base
    The Standard Kernel - base modules
    5.14.21-150400.24.167.1.150400.24.84.1 lock rpm lock src
SUSE Linux Enterprise Micro 5.4 aarch64
  • Packages
    kernel-default
    The Standard Kernel
    5.14.21-150400.24.167.1 lock rpm lock nosrc
    kernel-default-base
    The Standard Kernel - base modules
    5.14.21-150400.24.167.1.150400.24.84.1 lock rpm lock src