Security update for the Linux Kernel
Announcement ID: | SUSE-SU-2024:4082-1 |
---|---|
Release Date: | 2024-11-27T14:23:31Z |
Rating: | important |
References: |
|
Cross-References: |
|
CVSS scores: |
|
Affected Products: |
|
An update that solves 101 vulnerabilities and has 15 security fixes can now be installed.
Description:
The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security bugfixes.
The following security bugs were fixed:
- CVE-2022-48879: efi: fix NULL-deref in init error path (bsc#1229556).
- CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1231893).
- CVE-2022-48959: net: dsa: sja1105: fix memory leak in sja1105_setup_devlink_regions() (bsc#1231976).
- CVE-2022-48960: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() (bsc#1231979).
- CVE-2022-48962: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() (bsc#1232286).
- CVE-2022-48991: mm/khugepaged: fix collapse_pte_mapped_thp() to allow anon_vma (bsc#1232070).
- CVE-2022-49015: net: hsr: Fix potential use-after-free (bsc#1231938).
- CVE-2024-45013: nvme: move stopping keep-alive into nvme_uninit_ctrl() (bsc#1230442).
- CVE-2024-45016: netem: fix return value if duplicate enqueue fails (bsc#1230429).
- CVE-2024-45026: s390/dasd: fix error recovery leading to data corruption on ESE devices (bsc#1230454).
- CVE-2024-46716: dmaengine: altera-msgdma: properly free descriptor in msgdma_free_descriptor (bsc#1230715).
- CVE-2024-46813: drm/amd/display: Check link_index before accessing dc->links (bsc#1231191).
- CVE-2024-46814: drm/amd/display: Check msg_id before processing transcation (bsc#1231193).
- CVE-2024-46815: drm/amd/display: Check num_valid_sets before accessing reader_wm_sets (bsc#1231195).
- CVE-2024-46816: drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links (bsc#1231197).
- CVE-2024-46817: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6 (bsc#1231200).
- CVE-2024-46818: drm/amd/display: Check gpio_id before used as array index (bsc#1231203).
- CVE-2024-46849: ASoC: meson: axg-card: fix 'use-after-free' (bsc#1231073).
- CVE-2024-47668: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() (bsc#1231502).
- CVE-2024-47674: mm: avoid leaving partial pfn mappings around in error case (bsc#1231673).
- CVE-2024-47684: tcp: check skb is non-NULL in tcp_rto_delta_us() (bsc#1231987).
- CVE-2024-47706: block, bfq: fix possible UAF for bfqq->bic with merge chain (bsc#1231942).
- CVE-2024-47747: net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition (bsc#1232145).
- CVE-2024-47748: vhost_vdpa: assign irq bypass producer token correctly (bsc#1232174).
- CVE-2024-49860: ACPI: sysfs: validate return type of _STR method (bsc#1231861).
- CVE-2024-49930: wifi: ath11k: fix array out-of-bound access in SoC stats (bsc#1232260).
- CVE-2024-49936: net/xen-netback: prevent UAF in xenvif_flush_hash() (bsc#1232424).
- CVE-2024-49960: ext4: fix timer use-after-free on failed mount (bsc#1232395).
- CVE-2024-49969: drm/amd/display: Fix index out of bounds in DCN30 color transformation (bsc#1232519).
- CVE-2024-49974: NFSD: Force all NFSv4.2 COPY requests to be synchronous (bsc#1232383).
- CVE-2024-49991: drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer (bsc#1232282).
- CVE-2024-49995: tipc: guard against string buffer overrun (bsc#1232432).
- CVE-2024-50047: smb: client: fix UAF in async decryption (bsc#1232418).
The following non-security bugs were fixed:
- NFSv3: only use NFS timeout for MOUNT when protocols are compatible (bsc#1231016).
- PKCS#7: Check codeSigning EKU of certificates in PKCS#7 (bsc#1226666).
- RDMA/mana_ib: use the correct page size for mapping user-mode doorbell page (bsc#1232036).
- bpf: Fix pointer-leak due to insufficient speculative store bypass mitigation (bsc#1231375).
- dn_route: set rt neigh to blackhole_netdev instead of loopback_dev in ifdown (bsc#1216813).
- ipv6: blackhole_netdev needs snmp6 counters (bsc#1216813).
- ipv6: give an IPv6 dev to blackhole_netdev (bsc#1216813).
- net: mana: Fix the extra HZ in mana_hwc_send_request (bsc#1232033).
- xfrm: set dst dev to blackhole_netdev instead of loopback_dev in ifdown (bsc#1216813).
Special Instructions and Notes:
- Please reboot the system after installing this update.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2024-4082=1
-
SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2024-4082=1
-
SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2024-4082=1
-
SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2024-4082=1
Package List:
-
SUSE Linux Enterprise Micro for Rancher 5.4 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64)
- kernel-rt-debugsource-5.14.21-150400.15.100.1
- kernel-rt-debuginfo-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro for Rancher 5.4 (noarch)
- kernel-source-rt-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro 5.4 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro 5.4 (x86_64)
- kernel-rt-debugsource-5.14.21-150400.15.100.1
- kernel-rt-debuginfo-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro 5.4 (noarch)
- kernel-source-rt-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro for Rancher 5.3 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64)
- kernel-rt-debugsource-5.14.21-150400.15.100.1
- kernel-rt-debuginfo-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)
- kernel-source-rt-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro 5.3 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro 5.3 (x86_64)
- kernel-rt-debugsource-5.14.21-150400.15.100.1
- kernel-rt-debuginfo-5.14.21-150400.15.100.1
-
SUSE Linux Enterprise Micro 5.3 (noarch)
- kernel-source-rt-5.14.21-150400.15.100.1
References:
- https://www.suse.com/security/cve/CVE-2021-47416.html
- https://www.suse.com/security/cve/CVE-2021-47534.html
- https://www.suse.com/security/cve/CVE-2022-3435.html
- https://www.suse.com/security/cve/CVE-2022-45934.html
- https://www.suse.com/security/cve/CVE-2022-48664.html
- https://www.suse.com/security/cve/CVE-2022-48879.html
- https://www.suse.com/security/cve/CVE-2022-48946.html
- https://www.suse.com/security/cve/CVE-2022-48947.html
- https://www.suse.com/security/cve/CVE-2022-48948.html
- https://www.suse.com/security/cve/CVE-2022-48949.html
- https://www.suse.com/security/cve/CVE-2022-48951.html
- https://www.suse.com/security/cve/CVE-2022-48953.html
- https://www.suse.com/security/cve/CVE-2022-48954.html
- https://www.suse.com/security/cve/CVE-2022-48955.html
- https://www.suse.com/security/cve/CVE-2022-48956.html
- https://www.suse.com/security/cve/CVE-2022-48959.html
- https://www.suse.com/security/cve/CVE-2022-48960.html
- https://www.suse.com/security/cve/CVE-2022-48961.html
- https://www.suse.com/security/cve/CVE-2022-48962.html
- https://www.suse.com/security/cve/CVE-2022-48967.html
- https://www.suse.com/security/cve/CVE-2022-48968.html
- https://www.suse.com/security/cve/CVE-2022-48969.html
- https://www.suse.com/security/cve/CVE-2022-48970.html
- https://www.suse.com/security/cve/CVE-2022-48971.html
- https://www.suse.com/security/cve/CVE-2022-48972.html
- https://www.suse.com/security/cve/CVE-2022-48973.html
- https://www.suse.com/security/cve/CVE-2022-48975.html
- https://www.suse.com/security/cve/CVE-2022-48977.html
- https://www.suse.com/security/cve/CVE-2022-48978.html
- https://www.suse.com/security/cve/CVE-2022-48981.html
- https://www.suse.com/security/cve/CVE-2022-48985.html
- https://www.suse.com/security/cve/CVE-2022-48987.html
- https://www.suse.com/security/cve/CVE-2022-48988.html
- https://www.suse.com/security/cve/CVE-2022-48991.html
- https://www.suse.com/security/cve/CVE-2022-48992.html
- https://www.suse.com/security/cve/CVE-2022-48994.html
- https://www.suse.com/security/cve/CVE-2022-48995.html
- https://www.suse.com/security/cve/CVE-2022-48997.html
- https://www.suse.com/security/cve/CVE-2022-48999.html
- https://www.suse.com/security/cve/CVE-2022-49000.html
- https://www.suse.com/security/cve/CVE-2022-49002.html
- https://www.suse.com/security/cve/CVE-2022-49003.html
- https://www.suse.com/security/cve/CVE-2022-49005.html
- https://www.suse.com/security/cve/CVE-2022-49006.html
- https://www.suse.com/security/cve/CVE-2022-49007.html
- https://www.suse.com/security/cve/CVE-2022-49010.html
- https://www.suse.com/security/cve/CVE-2022-49011.html
- https://www.suse.com/security/cve/CVE-2022-49012.html
- https://www.suse.com/security/cve/CVE-2022-49014.html
- https://www.suse.com/security/cve/CVE-2022-49015.html
- https://www.suse.com/security/cve/CVE-2022-49016.html
- https://www.suse.com/security/cve/CVE-2022-49019.html
- https://www.suse.com/security/cve/CVE-2022-49021.html
- https://www.suse.com/security/cve/CVE-2022-49022.html
- https://www.suse.com/security/cve/CVE-2022-49023.html
- https://www.suse.com/security/cve/CVE-2022-49024.html
- https://www.suse.com/security/cve/CVE-2022-49025.html
- https://www.suse.com/security/cve/CVE-2022-49026.html
- https://www.suse.com/security/cve/CVE-2022-49027.html
- https://www.suse.com/security/cve/CVE-2022-49028.html
- https://www.suse.com/security/cve/CVE-2022-49029.html
- https://www.suse.com/security/cve/CVE-2022-49031.html
- https://www.suse.com/security/cve/CVE-2022-49032.html
- https://www.suse.com/security/cve/CVE-2023-2166.html
- https://www.suse.com/security/cve/CVE-2023-28327.html
- https://www.suse.com/security/cve/CVE-2023-52766.html
- https://www.suse.com/security/cve/CVE-2023-52800.html
- https://www.suse.com/security/cve/CVE-2023-52881.html
- https://www.suse.com/security/cve/CVE-2023-52919.html
- https://www.suse.com/security/cve/CVE-2023-6270.html
- https://www.suse.com/security/cve/CVE-2024-27043.html
- https://www.suse.com/security/cve/CVE-2024-42145.html
- https://www.suse.com/security/cve/CVE-2024-44947.html
- https://www.suse.com/security/cve/CVE-2024-45013.html
- https://www.suse.com/security/cve/CVE-2024-45016.html
- https://www.suse.com/security/cve/CVE-2024-45026.html
- https://www.suse.com/security/cve/CVE-2024-46716.html
- https://www.suse.com/security/cve/CVE-2024-46813.html
- https://www.suse.com/security/cve/CVE-2024-46814.html
- https://www.suse.com/security/cve/CVE-2024-46815.html
- https://www.suse.com/security/cve/CVE-2024-46816.html
- https://www.suse.com/security/cve/CVE-2024-46817.html
- https://www.suse.com/security/cve/CVE-2024-46818.html
- https://www.suse.com/security/cve/CVE-2024-46849.html
- https://www.suse.com/security/cve/CVE-2024-47668.html
- https://www.suse.com/security/cve/CVE-2024-47674.html
- https://www.suse.com/security/cve/CVE-2024-47684.html
- https://www.suse.com/security/cve/CVE-2024-47706.html
- https://www.suse.com/security/cve/CVE-2024-47747.html
- https://www.suse.com/security/cve/CVE-2024-47748.html
- https://www.suse.com/security/cve/CVE-2024-49860.html
- https://www.suse.com/security/cve/CVE-2024-49867.html
- https://www.suse.com/security/cve/CVE-2024-49930.html
- https://www.suse.com/security/cve/CVE-2024-49936.html
- https://www.suse.com/security/cve/CVE-2024-49960.html
- https://www.suse.com/security/cve/CVE-2024-49969.html
- https://www.suse.com/security/cve/CVE-2024-49974.html
- https://www.suse.com/security/cve/CVE-2024-49982.html
- https://www.suse.com/security/cve/CVE-2024-49991.html
- https://www.suse.com/security/cve/CVE-2024-49995.html
- https://www.suse.com/security/cve/CVE-2024-50047.html
- https://bugzilla.suse.com/show_bug.cgi?id=1204171
- https://bugzilla.suse.com/show_bug.cgi?id=1205796
- https://bugzilla.suse.com/show_bug.cgi?id=1206188
- https://bugzilla.suse.com/show_bug.cgi?id=1206344
- https://bugzilla.suse.com/show_bug.cgi?id=1209290
- https://bugzilla.suse.com/show_bug.cgi?id=1210449
- https://bugzilla.suse.com/show_bug.cgi?id=1210627
- https://bugzilla.suse.com/show_bug.cgi?id=1213034
- https://bugzilla.suse.com/show_bug.cgi?id=1216223
- https://bugzilla.suse.com/show_bug.cgi?id=1216813
- https://bugzilla.suse.com/show_bug.cgi?id=1218562
- https://bugzilla.suse.com/show_bug.cgi?id=1223384
- https://bugzilla.suse.com/show_bug.cgi?id=1223524
- https://bugzilla.suse.com/show_bug.cgi?id=1223824
- https://bugzilla.suse.com/show_bug.cgi?id=1225189
- https://bugzilla.suse.com/show_bug.cgi?id=1225336
- https://bugzilla.suse.com/show_bug.cgi?id=1225611
- https://bugzilla.suse.com/show_bug.cgi?id=1226666
- https://bugzilla.suse.com/show_bug.cgi?id=1228743
- https://bugzilla.suse.com/show_bug.cgi?id=1229454
- https://bugzilla.suse.com/show_bug.cgi?id=1229456
- https://bugzilla.suse.com/show_bug.cgi?id=1229556
- https://bugzilla.suse.com/show_bug.cgi?id=1230429
- https://bugzilla.suse.com/show_bug.cgi?id=1230442
- https://bugzilla.suse.com/show_bug.cgi?id=1230454
- https://bugzilla.suse.com/show_bug.cgi?id=1230600
- https://bugzilla.suse.com/show_bug.cgi?id=1230620
- https://bugzilla.suse.com/show_bug.cgi?id=1230715
- https://bugzilla.suse.com/show_bug.cgi?id=1230903
- https://bugzilla.suse.com/show_bug.cgi?id=1231016
- https://bugzilla.suse.com/show_bug.cgi?id=1231073
- https://bugzilla.suse.com/show_bug.cgi?id=1231191
- https://bugzilla.suse.com/show_bug.cgi?id=1231193
- https://bugzilla.suse.com/show_bug.cgi?id=1231195
- https://bugzilla.suse.com/show_bug.cgi?id=1231197
- https://bugzilla.suse.com/show_bug.cgi?id=1231200
- https://bugzilla.suse.com/show_bug.cgi?id=1231203
- https://bugzilla.suse.com/show_bug.cgi?id=1231293
- https://bugzilla.suse.com/show_bug.cgi?id=1231375
- https://bugzilla.suse.com/show_bug.cgi?id=1231502
- https://bugzilla.suse.com/show_bug.cgi?id=1231673
- https://bugzilla.suse.com/show_bug.cgi?id=1231861
- https://bugzilla.suse.com/show_bug.cgi?id=1231883
- https://bugzilla.suse.com/show_bug.cgi?id=1231885
- https://bugzilla.suse.com/show_bug.cgi?id=1231887
- https://bugzilla.suse.com/show_bug.cgi?id=1231888
- https://bugzilla.suse.com/show_bug.cgi?id=1231890
- https://bugzilla.suse.com/show_bug.cgi?id=1231892
- https://bugzilla.suse.com/show_bug.cgi?id=1231893
- https://bugzilla.suse.com/show_bug.cgi?id=1231895
- https://bugzilla.suse.com/show_bug.cgi?id=1231896
- https://bugzilla.suse.com/show_bug.cgi?id=1231897
- https://bugzilla.suse.com/show_bug.cgi?id=1231929
- https://bugzilla.suse.com/show_bug.cgi?id=1231936
- https://bugzilla.suse.com/show_bug.cgi?id=1231937
- https://bugzilla.suse.com/show_bug.cgi?id=1231938
- https://bugzilla.suse.com/show_bug.cgi?id=1231939
- https://bugzilla.suse.com/show_bug.cgi?id=1231940
- https://bugzilla.suse.com/show_bug.cgi?id=1231941
- https://bugzilla.suse.com/show_bug.cgi?id=1231942
- https://bugzilla.suse.com/show_bug.cgi?id=1231958
- https://bugzilla.suse.com/show_bug.cgi?id=1231960
- https://bugzilla.suse.com/show_bug.cgi?id=1231961
- https://bugzilla.suse.com/show_bug.cgi?id=1231962
- https://bugzilla.suse.com/show_bug.cgi?id=1231972
- https://bugzilla.suse.com/show_bug.cgi?id=1231976
- https://bugzilla.suse.com/show_bug.cgi?id=1231979
- https://bugzilla.suse.com/show_bug.cgi?id=1231987
- https://bugzilla.suse.com/show_bug.cgi?id=1231988
- https://bugzilla.suse.com/show_bug.cgi?id=1231991
- https://bugzilla.suse.com/show_bug.cgi?id=1231992
- https://bugzilla.suse.com/show_bug.cgi?id=1231995
- https://bugzilla.suse.com/show_bug.cgi?id=1231996
- https://bugzilla.suse.com/show_bug.cgi?id=1231997
- https://bugzilla.suse.com/show_bug.cgi?id=1232001
- https://bugzilla.suse.com/show_bug.cgi?id=1232005
- https://bugzilla.suse.com/show_bug.cgi?id=1232006
- https://bugzilla.suse.com/show_bug.cgi?id=1232007
- https://bugzilla.suse.com/show_bug.cgi?id=1232025
- https://bugzilla.suse.com/show_bug.cgi?id=1232026
- https://bugzilla.suse.com/show_bug.cgi?id=1232033
- https://bugzilla.suse.com/show_bug.cgi?id=1232035
- https://bugzilla.suse.com/show_bug.cgi?id=1232036
- https://bugzilla.suse.com/show_bug.cgi?id=1232037
- https://bugzilla.suse.com/show_bug.cgi?id=1232038
- https://bugzilla.suse.com/show_bug.cgi?id=1232039
- https://bugzilla.suse.com/show_bug.cgi?id=1232067
- https://bugzilla.suse.com/show_bug.cgi?id=1232069
- https://bugzilla.suse.com/show_bug.cgi?id=1232070
- https://bugzilla.suse.com/show_bug.cgi?id=1232071
- https://bugzilla.suse.com/show_bug.cgi?id=1232097
- https://bugzilla.suse.com/show_bug.cgi?id=1232108
- https://bugzilla.suse.com/show_bug.cgi?id=1232119
- https://bugzilla.suse.com/show_bug.cgi?id=1232120
- https://bugzilla.suse.com/show_bug.cgi?id=1232123
- https://bugzilla.suse.com/show_bug.cgi?id=1232133
- https://bugzilla.suse.com/show_bug.cgi?id=1232136
- https://bugzilla.suse.com/show_bug.cgi?id=1232145
- https://bugzilla.suse.com/show_bug.cgi?id=1232150
- https://bugzilla.suse.com/show_bug.cgi?id=1232163
- https://bugzilla.suse.com/show_bug.cgi?id=1232170
- https://bugzilla.suse.com/show_bug.cgi?id=1232172
- https://bugzilla.suse.com/show_bug.cgi?id=1232174
- https://bugzilla.suse.com/show_bug.cgi?id=1232229
- https://bugzilla.suse.com/show_bug.cgi?id=1232237
- https://bugzilla.suse.com/show_bug.cgi?id=1232260
- https://bugzilla.suse.com/show_bug.cgi?id=1232262
- https://bugzilla.suse.com/show_bug.cgi?id=1232282
- https://bugzilla.suse.com/show_bug.cgi?id=1232286
- https://bugzilla.suse.com/show_bug.cgi?id=1232304
- https://bugzilla.suse.com/show_bug.cgi?id=1232383
- https://bugzilla.suse.com/show_bug.cgi?id=1232395
- https://bugzilla.suse.com/show_bug.cgi?id=1232418
- https://bugzilla.suse.com/show_bug.cgi?id=1232424
- https://bugzilla.suse.com/show_bug.cgi?id=1232432
- https://bugzilla.suse.com/show_bug.cgi?id=1232519