gpp_maybe
Security update for the linux kernel
SUSE-SLE-Module-Live-Patching-15-SP4-2025-835
The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-49080: mm/mempolicy: fix mpol_new leak in shared_policy_replace (bsc#1238033). - CVE-2024-35949: btrfs: make sure that WRITTEN is set on all metadata blocks (bsc#1224700). - CVE-2024-50128: net: wwan: fix global oob in wwan_rtnl_policy (bsc#1232905). - CVE-2024-53135: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN (bsc#1234154). - CVE-2024-57948: mac802154: check local interfaces before deleting sdata list (bsc#1236677). - CVE-2025-21690: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service (bsc#1237025). - CVE-2025-21692: net: sched: fix ets qdisc OOB Indexing (bsc#1237028). - CVE-2025-21699: gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag (bsc#1237139). The following non-security bugs were fixed: - idpf: call set_real_num_queues in idpf_open (bsc#1236661 bsc#1237316). - ipv4/tcp: do not use per netns ctl sockets (bsc#1237693). - net: mana: Add get_link and get_link_ksettings in ethtool (bsc#1236761). - net: mana: Cleanup "mana" debugfs dir after cleanup of all children (bsc#1236760). - net: mana: Enable debugfs files for MANA device (bsc#1236758). - net: netvsc: Update default VMBus channels (bsc#1236757). - scsi: storvsc: Use scsi_cmd_to_rq() instead of scsi_cmnd.request (git-fixes). - x86/kvm: fix is_stale_page_fault() (bsc#1236675). - x86/xen: add FRAME_END to xen_hypercall_hvm() (git-fixes). - x86/xen: fix xen_hypercall_hvm() to not clobber %rbx (git-fixes).
-
Release DateMar 11 2025
-
ReferencesBugzilla: 1208995, 1220946, 1224700, 1225742, 1232905, 1232919, 1234154, 1234853, 1234891, 1234963, 1235054, 1235061, 1235073, 1236661, 1236675, 1236677, 1236757, 1236758, 1236760, 1236761, 1237025, 1237028, 1237139, 1237316, 1237693, 1238033
CVEs: CVE-2022-49080, CVE-2023-1192, CVE-2023-52572, CVE-2024-35949, CVE-2024-50115, CVE-2024-50128, CVE-2024-53135, CVE-2024-53173, CVE-2024-53239, CVE-2024-56539, CVE-2024-56548, CVE-2024-56605, CVE-2024-57948, CVE-2025-21690, CVE-2025-21692, CVE-2025-21699 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Live Patching 15.4 s390x
-
Packageskernel-default
The Standard Kernelkernel-default-livepatch5.14.21-150400.24.153.1 lock nosrc
Metapackage to pull in matching kernel-livepatch packagekernel-default-livepatch-devel5.14.21-150400.24.153.1 lock rpm
Kernel symbols file used during kGraft patch developmentkernel-livepatch-5_14_21-150400_24_153-default5.14.21-150400.24.153.1 lock rpm
Kernel live patch modulekernel-livepatch-SLE15-SP4_Update_371-150400.9.3.1 lock rpm
Kernel live patch module1-150400.9.3.1 lock src
SUSE Linux Enterprise Live Patching 15.4 x86_64
-
Packageskernel-default
The Standard Kernelkernel-default-livepatch5.14.21-150400.24.153.1 lock nosrc
Metapackage to pull in matching kernel-livepatch packagekernel-default-livepatch-devel5.14.21-150400.24.153.1 lock rpm
Kernel symbols file used during kGraft patch developmentkernel-livepatch-5_14_21-150400_24_153-default5.14.21-150400.24.153.1 lock rpm
Kernel live patch modulekernel-livepatch-SLE15-SP4_Update_371-150400.9.3.1 lock rpm
Kernel live patch module1-150400.9.3.1 lock src
SUSE Linux Enterprise Live Patching 15.4 ppc64le
-
Packageskernel-default
The Standard Kernelkernel-default-livepatch5.14.21-150400.24.153.1 lock nosrc
Metapackage to pull in matching kernel-livepatch packagekernel-default-livepatch-devel5.14.21-150400.24.153.1 lock rpm
Kernel symbols file used during kGraft patch developmentkernel-livepatch-5_14_21-150400_24_153-default5.14.21-150400.24.153.1 lock rpm
Kernel live patch modulekernel-livepatch-SLE15-SP4_Update_371-150400.9.3.1 lock rpm
Kernel live patch module1-150400.9.3.1 lock src