Security update for the Linux Kernel
Announcement ID: | SUSE-SU-2025:0555-1 |
---|---|
Release Date: | 2025-02-14T15:25:28Z |
Rating: | important |
References: |
|
Cross-References: |
|
CVSS scores: |
|
Affected Products: |
|
An update that solves 28 vulnerabilities and has two security fixes can now be installed.
Description:
The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security bugfixes.
The following security bugs were fixed:
- CVE-2024-50199: mm/swapfile: skip HugeTLB pages for unuse_vma (bsc#1233112).
- CVE-2024-53104: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (bsc#1234025).
- CVE-2024-53166: block, bfq: fix bfqq uaf in bfq_limit_depth() (bsc#1234884).
- CVE-2024-53177: smb: prevent use-after-free due to open_cached_dir error paths (bsc#1234896).
- CVE-2024-56600: net: inet6: do not leave a dangling sk pointer in inet6_create() (bsc#1235217).
- CVE-2024-56601: net: inet: do not leave a dangling sk pointer in inet_create() (bsc#1235230).
- CVE-2024-56602: net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() (bsc#1235521).
- CVE-2024-56623: scsi: qla2xxx: Fix use after free on unload (bsc#1235466).
- CVE-2024-56631: scsi: sg: Fix slab-use-after-free read in sg_release() (bsc#1235480).
- CVE-2024-56642: tipc: Fix use-after-free of kernel socket in cleanup_bearer() (bsc#1235433).
- CVE-2024-56645: can: j1939: j1939_session_new(): fix skb reference counting (bsc#1235134).
- CVE-2024-56648: net: hsr: avoid potential out-of-bound access in fill_frame_info() (bsc#1235451).
- CVE-2024-56650: netfilter: x_tables: fix LED ID check in led_tg_check() (bsc#1235430).
- CVE-2024-56658: net: defer final 'struct net' free in netns dismantle (bsc#1235441).
- CVE-2024-56664: bpf, sockmap: Fix race between element replace and close() (bsc#1235249).
- CVE-2024-56704: 9p/xen: fix release of IRQ (bsc#1235584).
- CVE-2024-56759: btrfs: fix use-after-free when COWing tree bock and tracing is enabled (bsc#1235645).
- CVE-2024-57791: net/smc: check return value of sock_recvmsg when draining clc data (bsc#1235759).
- CVE-2024-57792: power: supply: gpio-charger: Fix set charge current limits (bsc#1235764).
- CVE-2024-57798: drm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req() (bsc#1235818).
- CVE-2024-57849: s390/cpum_sf: Handle CPU hotplug remove during sampling (bsc#1235814).
- CVE-2024-57893: ALSA: seq: oss: Fix races at processing SysEx messages (bsc#1235920).
- CVE-2024-57897: drm/amdkfd: Correct the migration DMA map direction (bsc#1235969).
The following non-security bugs were fixed:
- NFS: Adjust the amount of readahead performed by NFS readdir (bsc#1231847).
- NFS: Do not flush the readdir cache in nfs_dentry_iput() (bsc#1231847).
- NFS: Improve heuristic for readdirplus (bsc#1231847).
- NFS: Trigger the "ls -l" readdir heuristic sooner (bsc#1231847).
- tipc: fix NULL deref in cleanup_bearer() (bsc#1235433).
- x86/static-call: Remove early_boot_irqs_disabled check to fix Xen PVH dom0 (git-fixes).
Special Instructions and Notes:
- Please reboot the system after installing this update.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-555=1
-
SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-555=1
-
SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-555=1
-
SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-555=1
Package List:
-
SUSE Linux Enterprise Micro for Rancher 5.3 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64)
- kernel-rt-debuginfo-5.14.21-150400.15.109.1
- kernel-rt-debugsource-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)
- kernel-source-rt-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro 5.3 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro 5.3 (x86_64)
- kernel-rt-debuginfo-5.14.21-150400.15.109.1
- kernel-rt-debugsource-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro 5.3 (noarch)
- kernel-source-rt-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro for Rancher 5.4 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64)
- kernel-rt-debuginfo-5.14.21-150400.15.109.1
- kernel-rt-debugsource-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro for Rancher 5.4 (noarch)
- kernel-source-rt-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro 5.4 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro 5.4 (x86_64)
- kernel-rt-debuginfo-5.14.21-150400.15.109.1
- kernel-rt-debugsource-5.14.21-150400.15.109.1
-
SUSE Linux Enterprise Micro 5.4 (noarch)
- kernel-source-rt-5.14.21-150400.15.109.1
References:
- https://www.suse.com/security/cve/CVE-2024-50199.html
- https://www.suse.com/security/cve/CVE-2024-53095.html
- https://www.suse.com/security/cve/CVE-2024-53104.html
- https://www.suse.com/security/cve/CVE-2024-53144.html
- https://www.suse.com/security/cve/CVE-2024-53166.html
- https://www.suse.com/security/cve/CVE-2024-53177.html
- https://www.suse.com/security/cve/CVE-2024-54680.html
- https://www.suse.com/security/cve/CVE-2024-56600.html
- https://www.suse.com/security/cve/CVE-2024-56601.html
- https://www.suse.com/security/cve/CVE-2024-56602.html
- https://www.suse.com/security/cve/CVE-2024-56623.html
- https://www.suse.com/security/cve/CVE-2024-56631.html
- https://www.suse.com/security/cve/CVE-2024-56642.html
- https://www.suse.com/security/cve/CVE-2024-56645.html
- https://www.suse.com/security/cve/CVE-2024-56648.html
- https://www.suse.com/security/cve/CVE-2024-56650.html
- https://www.suse.com/security/cve/CVE-2024-56658.html
- https://www.suse.com/security/cve/CVE-2024-56661.html
- https://www.suse.com/security/cve/CVE-2024-56664.html
- https://www.suse.com/security/cve/CVE-2024-56704.html
- https://www.suse.com/security/cve/CVE-2024-56759.html
- https://www.suse.com/security/cve/CVE-2024-57791.html
- https://www.suse.com/security/cve/CVE-2024-57792.html
- https://www.suse.com/security/cve/CVE-2024-57798.html
- https://www.suse.com/security/cve/CVE-2024-57849.html
- https://www.suse.com/security/cve/CVE-2024-57893.html
- https://www.suse.com/security/cve/CVE-2024-57897.html
- https://www.suse.com/security/cve/CVE-2024-8805.html
- https://bugzilla.suse.com/show_bug.cgi?id=1230697
- https://bugzilla.suse.com/show_bug.cgi?id=1231847
- https://bugzilla.suse.com/show_bug.cgi?id=1233112
- https://bugzilla.suse.com/show_bug.cgi?id=1233642
- https://bugzilla.suse.com/show_bug.cgi?id=1234025
- https://bugzilla.suse.com/show_bug.cgi?id=1234690
- https://bugzilla.suse.com/show_bug.cgi?id=1234884
- https://bugzilla.suse.com/show_bug.cgi?id=1234896
- https://bugzilla.suse.com/show_bug.cgi?id=1234931
- https://bugzilla.suse.com/show_bug.cgi?id=1235134
- https://bugzilla.suse.com/show_bug.cgi?id=1235217
- https://bugzilla.suse.com/show_bug.cgi?id=1235230
- https://bugzilla.suse.com/show_bug.cgi?id=1235249
- https://bugzilla.suse.com/show_bug.cgi?id=1235430
- https://bugzilla.suse.com/show_bug.cgi?id=1235433
- https://bugzilla.suse.com/show_bug.cgi?id=1235441
- https://bugzilla.suse.com/show_bug.cgi?id=1235451
- https://bugzilla.suse.com/show_bug.cgi?id=1235466
- https://bugzilla.suse.com/show_bug.cgi?id=1235480
- https://bugzilla.suse.com/show_bug.cgi?id=1235521
- https://bugzilla.suse.com/show_bug.cgi?id=1235584
- https://bugzilla.suse.com/show_bug.cgi?id=1235645
- https://bugzilla.suse.com/show_bug.cgi?id=1235723
- https://bugzilla.suse.com/show_bug.cgi?id=1235759
- https://bugzilla.suse.com/show_bug.cgi?id=1235764
- https://bugzilla.suse.com/show_bug.cgi?id=1235814
- https://bugzilla.suse.com/show_bug.cgi?id=1235818
- https://bugzilla.suse.com/show_bug.cgi?id=1235920
- https://bugzilla.suse.com/show_bug.cgi?id=1235969
- https://bugzilla.suse.com/show_bug.cgi?id=1236628