gpp_maybe
Security update for the linux kernel
SUSE-SLE-Module-Live-Patching-15-SP3-2024-3585
The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2021-47069: Fixed a crash due to relying on a stack reference past its expiry in ipc/mqueue, ipc/msg, ipc/sem (bsc#1220826). - CVE-2022-48911: kabi: add __nf_queue_get_refs() for kabi compliance. (bsc#1229633). - CVE-2022-48945: media: vivid: fix compose size exceed boundary (bsc#1230398). - CVE-2024-41087: Fix double free on error (bsc#1228466). - CVE-2024-44946: kcm: Serialise kcm_sendmsg() for the same socket (bsc#1230015). - CVE-2024-45003: Don't evict inode under the inode lru traversing context (bsc#1230245). - CVE-2024-45021: memcg_write_event_control(): fix a user-triggerable oops (bsc#1230434). - CVE-2024-46695: selinux,smack: do not bypass permissions check in inode_setsecctx hook (bsc#1230519). - CVE-2024-36971: Fixed __dst_negative_advice() race (bsc#1226145). The following non-security bugs were fixed: - ext4: add check to prevent attempting to resize an fs with sparse_super2 (bsc#1230326). - ext4: add reserved GDT blocks check (bsc#1230326). - ext4: consolidate checks for resize of bigalloc into ext4_resize_begin (bsc#1230326). - ext4: fix bug_on ext4_mb_use_inode_pa (bsc#1230326). - kabi: add __nf_queue_get_refs() for kabi compliance. - PKCS#7: Check codeSigning EKU of certificates in PKCS#7 (bsc#1226666). - Revert "ext4: consolidate checks for resize of bigalloc into ext4_resize_begin" (bsc#1230326).
-
Release DateOct 10 2024
-
ReferencesBugzilla: 1220826, 1226666, 1227487, 1228466, 1229633, 1230015, 1230245, 1230326, 1230398, 1230434, 1230519, 1230767, 1226145
CVEs: CVE-2024-46774, CVE-2022-48945, CVE-2022-48911, CVE-2021-47069, CVE-2024-44946, CVE-2024-46695, CVE-2024-45021, CVE-2024-41087, CVE-2024-45003, CVE-2024-36971 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Live Patching 15.3 s390x
-
Packageskernel-default
The Standard Kernelkernel-default-livepatch5.3.18-150300.59.179.1 lock nosrc
Metapackage to pull in matching kernel-livepatch packagekernel-default-livepatch-devel5.3.18-150300.59.179.1 lock rpm
Kernel symbols file used during kGraft patch developmentkernel-livepatch-5_3_18-150300_59_179-default5.3.18-150300.59.179.1 lock rpm
Kernel live patch modulekernel-livepatch-SLE15-SP3_Update_491-150300.7.3.2 lock rpm
Kernel live patch module1-150300.7.3.2 lock src
SUSE Linux Enterprise Live Patching 15.3 ppc64le
-
Packageskernel-default
The Standard Kernelkernel-default-livepatch5.3.18-150300.59.179.1 lock nosrc
Metapackage to pull in matching kernel-livepatch packagekernel-default-livepatch-devel5.3.18-150300.59.179.1 lock rpm
Kernel symbols file used during kGraft patch developmentkernel-livepatch-5_3_18-150300_59_179-default5.3.18-150300.59.179.1 lock rpm
Kernel live patch modulekernel-livepatch-SLE15-SP3_Update_491-150300.7.3.2 lock rpm
Kernel live patch module1-150300.7.3.2 lock src
SUSE Linux Enterprise Live Patching 15.3 x86_64
-
Packageskernel-default
The Standard Kernelkernel-default-livepatch5.3.18-150300.59.179.1 lock nosrc
Metapackage to pull in matching kernel-livepatch packagekernel-default-livepatch-devel5.3.18-150300.59.179.1 lock rpm
Kernel symbols file used during kGraft patch developmentkernel-livepatch-5_3_18-150300_59_179-default5.3.18-150300.59.179.1 lock rpm
Kernel live patch modulekernel-livepatch-SLE15-SP3_Update_491-150300.7.3.2 lock rpm
Kernel live patch module1-150300.7.3.2 lock src