gpp_maybe
Security update for the linux kernel
SUSE-SLE-Module-Live-Patching-15-SP4-2025-1195
The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-49053: scsi: target: tcmu: Fix possible page UAF (bsc#1237918). - CVE-2022-49465: blk-throttle: Set BIO_THROTTLED when bio has been throttled (bsc#1238919). - CVE-2022-49739: gfs2: Always check inode size of inline inodes (bsc#1240207). - CVE-2023-52935: mm/khugepaged: fix ->anon_vma race (bsc#1240276). - CVE-2024-53064: idpf: fix idpf_vc_core_init error path (bsc#1233558 bsc#1234464). - CVE-2024-56651: can: hi311x: hi3110_can_ist(): fix potential use-after-free (bsc#1235528). - CVE-2024-58083: KVM: Explicitly verify target vCPU is online in kvm_get_vcpu() (bsc#1239036). - CVE-2025-21693: mm: zswap: properly synchronize freeing resources during CPU hotunplug (bsc#1237029). - CVE-2025-21714: RDMA/mlx5: Fix implicit ODP use after free (bsc#1237890). - CVE-2025-21732: RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error (bsc#1237877). - CVE-2025-21753: btrfs: fix use-after-free when attempting to join an aborted transaction (bsc#1237875). - CVE-2025-21772: partitions: mac: fix handling of bogus partition table (bsc#1238911). The following non-security bugs were fixed: - ACPI: processor: idle: Return an error if both P_LVL{2,3} idle states are invalid (bsc#1237530). - RDMA/mana_ib: Prefer struct_size over open coded arithmetic (bsc#1239016). - RDMA/mana_ib: Use v2 version of cfg_rx_steer_req to enable RX coalescing (bsc#1239016). - RDMA/mlx5: Fix implicit ODP hang on parent deregistration (git-fixes) - btrfs: defrag: do not use merged extent map for their generation check (bsc#1239968). - btrfs: fix defrag not merging contiguous extents due to merged extent maps (bsc#1239968). - btrfs: fix extent map merging not happening for adjacent extents (bsc#1239968). - btrfs: send: allow cloning non-aligned extent if it ends at i_size (bsc#1239969). - btrfs: send: fix invalid clone operation for file that got its size decreased (bsc#1239969). - gfs2: Fix inode height consistency check (git-fixes). - mm/mmu_notifier.c: fix race in mmu_interval_notifier_remove() (bsc#1239126). - mm: zswap: move allocations during CPU init outside the lock (git-fixes). - net: mana: Add flex array to struct mana_cfg_rx_steer_req_v2 (bsc#1239016). - net: mana: Allow variable size indirection table (bsc#1239016). - net: mana: Avoid open coded arithmetic (bsc#1239016). - net: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup (bsc#1240195). - net: mana: Support holes in device list reply msg (bsc#1240133).
-
Release DateApr 10 2025
-
ReferencesBugzilla: 1193629, 1197227, 1207034, 1207186, 1207878, 1209262, 1209547, 1209788, 1210647, 1213167, 1225742, 1231375, 1233479, 1233557, 1233558, 1234464, 1235528, 1237029, 1237530, 1237875, 1237877, 1237890, 1237918, 1238911, 1238919, 1239016, 1239036, 1239061, 1239126, 1239452, 1239454, 1239968, 1239969, 1240133, 1240195, 1240205, 1240207, 1240208, 1240210, 1240212, 1240213, 1240218, 1240220, 1240227, 1240229, 1240231, 1240242, 1240245, 1240247, 1240250, 1240254, 1240256, 1240264, 1240266, 1240272, 1240275, 1240276, 1240278, 1240279, 1240280, 1240281, 1240282, 1240283, 1240284, 1240286, 1240288, 1240290, 1240292, 1240293, 1240297, 1240304, 1240308, 1240309, 1240317, 1240318, 1240322
CVEs: CVE-2023-52988, CVE-2017-5753, CVE-2021-4454, CVE-2022-1016, CVE-2022-49053, CVE-2022-49293, CVE-2022-49465, CVE-2022-49650, CVE-2022-49739, CVE-2022-49746, CVE-2022-49748, CVE-2022-49751, CVE-2022-49753, CVE-2022-49755, CVE-2022-49759, CVE-2023-0179, CVE-2023-1652, CVE-2023-2162, CVE-2023-3567, CVE-2023-52930, CVE-2023-52933, CVE-2023-52935, CVE-2023-52939, CVE-2023-52941, CVE-2023-52973, CVE-2023-52974, CVE-2023-52975, CVE-2023-52976, CVE-2023-52979, CVE-2023-52983, CVE-2023-52984, CVE-2023-52989, CVE-2023-52992, CVE-2023-52993, CVE-2023-53000, CVE-2023-53005, CVE-2023-53006, CVE-2023-53007, CVE-2023-53008, CVE-2023-53010, CVE-2023-53015, CVE-2023-53016, CVE-2023-53019, CVE-2023-53023, CVE-2023-53024, CVE-2023-53025, CVE-2023-53026, CVE-2023-53028, CVE-2023-53029, CVE-2023-53030, CVE-2023-53033, CVE-2024-50290, CVE-2024-53063, CVE-2024-53064, CVE-2024-56651, CVE-2024-58083, CVE-2025-21693, CVE-2025-21714, CVE-2025-21732, CVE-2025-21753, CVE-2025-21772, CVE-2025-21839 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Live Patching 15.4 ppc64le
-
Packageskernel-default
The Standard Kernelkernel-default-livepatch5.14.21-150400.24.161.1 lock nosrc
Metapackage to pull in matching kernel-livepatch packagekernel-default-livepatch-devel5.14.21-150400.24.161.1 lock rpm
Kernel symbols file used during kGraft patch developmentkernel-livepatch-5_14_21-150400_24_161-default5.14.21-150400.24.161.1 lock rpm
Kernel live patch modulekernel-livepatch-SLE15-SP4_Update_391-150400.9.3.1 lock rpm
Kernel live patch module1-150400.9.3.1 lock src
SUSE Linux Enterprise Live Patching 15.4 s390x
-
Packageskernel-default
The Standard Kernelkernel-default-livepatch5.14.21-150400.24.161.1 lock nosrc
Metapackage to pull in matching kernel-livepatch packagekernel-default-livepatch-devel5.14.21-150400.24.161.1 lock rpm
Kernel symbols file used during kGraft patch developmentkernel-livepatch-5_14_21-150400_24_161-default5.14.21-150400.24.161.1 lock rpm
Kernel live patch modulekernel-livepatch-SLE15-SP4_Update_391-150400.9.3.1 lock rpm
Kernel live patch module1-150400.9.3.1 lock src
SUSE Linux Enterprise Live Patching 15.4 x86_64
-
Packageskernel-default
The Standard Kernelkernel-default-livepatch5.14.21-150400.24.161.1 lock nosrc
Metapackage to pull in matching kernel-livepatch packagekernel-default-livepatch-devel5.14.21-150400.24.161.1 lock rpm
Kernel symbols file used during kGraft patch developmentkernel-livepatch-5_14_21-150400_24_161-default5.14.21-150400.24.161.1 lock rpm
Kernel live patch modulekernel-livepatch-SLE15-SP4_Update_391-150400.9.3.1 lock rpm
Kernel live patch module1-150400.9.3.1 lock src