gpp_maybe Security update for the linux kernel
SUSE-SLE-Micro-5.5-2025-2173


The SUSE Linux Enterprise 15 SP5 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-49775: tcp: cdg: allow tcp_cdg_release() to be called multiple times (bsc#1242245). - CVE-2024-53168: net: make sock_inuse_add() available (bsc#1234887). - CVE-2024-56558: nfsd: make sure exp active before svc_export_show (bsc#1235100). - CVE-2025-21999: proc: fix UAF in proc_get_inode() (bsc#1240802). - CVE-2025-22056: netfilter: nft_tunnel: fix geneve_opt type confusion addition (bsc#1241525). - CVE-2025-23145: mptcp: fix NULL pointer in can_accept_new_subflow (bsc#1242596). - CVE-2025-37789: net: openvswitch: fix nested key length validation in the set() action (bsc#1242762). - CVE-2024-28956: x86/its: Add support for ITS-safe indirect thunk (bsc#1242006). - CVE-2025-37785: ext4: fix OOB read when checking dotdot dir (bsc#1241640). The following non-security bugs were fixed: - Drivers: hv: Allow vmbus_sendpacket_mpb_desc() to create multiple ranges (bsc#1243737). - Move upstreamed sched/membarrier patch into sorted section - Remove debug flavor (bsc#1243919). This is only released in Leap, and we do not have Leap 15.4 anymore. - Remove debug flavor (bsc#1243919). This is only released in Leap, and we do not have Leap 15.5 anymore. - Use gcc-13 for build on SLE16 (jsc#PED-10028). - arm64: bpf: Add BHB mitigation to the epilogue for cBPF programs (bsc#1242778). - arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users (bsc#1242778). - arm64: insn: Add support for encoding DSB (bsc#1242778). - arm64: proton-pack: Add new CPUs 'k' values for branch mitigation (bsc#1242778). - arm64: proton-pack: Expose whether the branchy loop k value (bsc#1242778). - arm64: proton-pack: Expose whether the platform is mitigated by firmware (bsc#1242778). - hv_netvsc: Preserve contiguous PFN grouping in the page buffer array (bsc#1243737). - hv_netvsc: Remove rmsg_pgcnt (bsc#1243737). - hv_netvsc: Use vmbus_sendpacket_mpb_desc() to send VMBus messages (bsc#1243737). - mtd: phram: Add the kernel lock down check (bsc#1232649). - net :mana :Add remaining GDMA stats for MANA to ethtool (bsc#1234395). - net :mana :Request a V2 response version for MANA_QUERY_GF_STAT (bsc#1234395). - net: mana: Add gdma stats to ethtool output for mana (bsc#1234395). - nvme-pci: acquire cq_poll_lock in nvme_poll_irqdisable (bsc#1223096). - ocfs2: fix the issue with discontiguous allocation in the global_bitmap (git-fixes). - powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW (bsc#1218470 ltc#204531). - rpm/kernel-binary.spec.in: Also order against update-bootloader (boo#1228659, boo#1240785, boo#1241038). - rpm/kernel-binary.spec.in: Fix missing 20-kernel-default-extra.conf (bsc#1239986) - rpm/kernel-binary.spec.in: fix KMPs build on 6.13+ (bsc#1234454) - rpm/kernel-docs.spec.in: Workaround for reproducible builds (bsc#1238303) - rpm/release-projects: Update the ALP projects again (bsc#1231293). - rpm/split-modules: Fix optional splitting with usrmerge (bsc#1238570) - scsi: core: Fix unremoved procfs host directory regression (git-fixes). - tcp: Dump bound-only sockets in inet_diag (bsc#1204562). - tpm, tpm_tis: Workaround failed command reception on Infineon devices (bsc#1235870). - tpm: tis: Double the timeout B to 4s (bsc#1235870). - x86/bhi: Do not set BHI_DIS_S in 32-bit mode (bsc#1242778). - x86/bpf: Add IBHF call at end of classic BPF (bsc#1242778). - x86/bpf: Call branch history clearing sequence on exit (bsc#1242778).


cloud_download Downloads

SUSE Linux Enterprise Micro 5.5 s390x
  • Packages
    kernel-default
    The Standard Kernel
    5.14.21-150500.55.110.1 lock rpm lock nosrc
SUSE Linux Enterprise Micro 5.5 aarch64
  • Packages
    kernel-default
    The Standard Kernel
    5.14.21-150500.55.110.1 lock rpm lock nosrc
    kernel-default-base
    The Standard Kernel - base modules
    5.14.21-150500.55.110.1.150500.6.51.3 lock rpm lock src
SUSE Linux Enterprise Micro 5.5 ppc64le
  • Packages
    kernel-default
    The Standard Kernel
    5.14.21-150500.55.110.1 lock rpm lock nosrc
SUSE Linux Enterprise Micro 5.5 x86_64
  • Packages
    kernel-default
    The Standard Kernel
    5.14.21-150500.55.110.1 lock rpm lock nosrc
    kernel-default-base
    The Standard Kernel - base modules
    5.14.21-150500.55.110.1.150500.6.51.3 lock rpm lock src
    kernel-macros
    RPM macros for building Kernel Module Packages
    5.14.21-150500.55.110.1 lock rpm
    kernel-source
    The Linux Kernel Sources
    5.14.21-150500.55.110.1 lock src