gpp_maybe
Security update for the linux kernel rt (live patch 3 for sle 15 sp5)
SUSE-SLE-Module-Live-Patching-15-SP5-2024-986
This update for the Linux Kernel 5.14.21-150500_13_11 fixes several issues. The following security issues were fixed: - CVE-2023-6531: Fixed a use-after-free flaw due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic()on the socket that the SKB is queued on (bsc#1218487). - CVE-2023-46813: Fixed a local privilege escalation with user-space programs that have access to MMIO regions (bsc#1216898). - CVE-2023-39191: Fixed a lack of validation of dynamic pointers within user-supplied eBPF programs that may have allowed an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code. (bsc#1215863) - CVE-2023-51779: Fixed a use-after-free because of a bt_sock_ioctl race condition in bt_sock_recvmsg (bsc#1218610).
-
Release DateMar 25 2024
-
ReferencesBugzilla: 1215887, 1216898, 1218487, 1218610
CVEs: CVE-2023-39191, CVE-2023-46813, CVE-2023-51779, CVE-2023-6531 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Live Patching 15.5 x86_64
-
Packageskernel-livepatch-5_14_21-150500_13_11-rt
Kernel live patch modulekernel-livepatch-SLE15-SP5-RT_Update_37-150500.2.2 lock rpm
Kernel live patch module7-150500.2.2 lock src