Upstream information

CVE-2023-52452 at MITRE

Description

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix accesses to uninit stack slots

Privileged programs are supposed to be able to read uninitialized stack
memory (ever since 6715df8d5) but, before this patch, these accesses
were permitted inconsistently. In particular, accesses were permitted
above state->allocated_stack, but not below it. In other words, if the
stack was already "large enough", the access was permitted, but
otherwise the access was rejected instead of being allowed to "grow the
stack". This undesired rejection was happening in two places:
- in check_stack_slot_within_bounds()
- in check_stack_range_initialized()
This patch arranges for these accesses to be permitted. A bunch of tests
that were relying on the old rejection had to change; all of them were
changed to add also run unprivileged, in which case the old behavior
persists. One tests couldn't be updated - global_func16 - because it
can't run unprivileged for other reasons.

This patch also fixes the tracking of the stack size for variable-offset
reads. This second fix is bundled in the same commit as the first one
because they're inter-related. Before this patch, writes to the stack
using registers containing a variable offset (as opposed to registers
with fixed, known values) were not properly contributing to the
function's needed stack size. As a result, it was possible for a program
to verify, but then to attempt to read out-of-bounds data at runtime
because a too small stack had been allocated for it.

Each function tracks the size of the stack it needs in
bpf_subprog_info.stack_depth, which is maintained by
update_stack_depth(). For regular memory accesses, check_mem_access()
was calling update_state_depth() but it was passing in only the fixed
part of the offset register, ignoring the variable offset. This was
incorrect; the minimum possible value of that register should be used
instead.

This tracking is now fixed by centralizing the tracking of stack size in
grow_stack_state(), and by lifting the calls to grow_stack_state() to
check_stack_access_within_bounds() as suggested by Andrii. The code is
now simpler and more convincingly tracks the correct maximum stack size.
check_stack_range_initialized() can now rely on enough stack having been
allocated for the access; this helps with the fix for the first issue.

A few tests were changed to also check the stack depth computation. The
one that fails without this patch is verifier_var_off:stack_write_priv_vs_unpriv.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v3 Scores
  National Vulnerability Database SUSE
Base Score 7.8 4.4
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector Local Local
Attack Complexity Low Low
Privileges Required Low High
User Interaction None None
Scope Unchanged Unchanged
Confidentiality Impact High High
Integrity Impact High None
Availability Impact High None
CVSSv3 Version 3.1 3.1

Note from the SUSE Security Team on the kernel-default package

SUSE will no longer fix all CVEs in the Linux Kernel anymore, but declare some bug classes as won't fix. Please refer to TID 21496 for more details.

SUSE Bugzilla entry: 1220257 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
Container bci/bci-sle15-kernel-module-devel:15.5
  • kernel-default-devel >= 5.14.21-150500.55.52.1
  • kernel-devel >= 5.14.21-150500.55.52.1
  • kernel-macros >= 5.14.21-150500.55.52.1
  • kernel-syms >= 5.14.21-150500.55.52.1
Container rancher/elemental-teal-rt/5.4:1.2.3-2.2.132
  • kernel-rt >= 5.14.21-150400.15.71.1
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:15.5.11.8.2
Container suse/sle-micro/base-5.5:2.0.4-5.8.118
Image SLES15-SP5-BYOS-Azure
Image SLES15-SP5-BYOS-EC2
Image SLES15-SP5-BYOS-GCE
Image SLES15-SP5-CHOST-BYOS-Aliyun
Image SLES15-SP5-CHOST-BYOS-Azure
Image SLES15-SP5-CHOST-BYOS-EC2
Image SLES15-SP5-CHOST-BYOS-GCE
Image SLES15-SP5-CHOST-BYOS-GDC
Image SLES15-SP5-CHOST-BYOS-SAP-CCloud
Image SLES15-SP5-EC2
Image SLES15-SP5-GCE
Image SLES15-SP5-HPC-BYOS-Azure
Image SLES15-SP5-HPC-BYOS-EC2
Image SLES15-SP5-HPC-BYOS-GCE
Image SLES15-SP5-Hardened-BYOS-Azure
Image SLES15-SP5-Hardened-BYOS-EC2
Image SLES15-SP5-Hardened-BYOS-GCE
Image SLES15-SP5-Manager-Proxy-5-0-BYOS
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-Azure
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-EC2
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-GCE
Image SLES15-SP5-Manager-Server-5-0-BYOS
Image SLES15-SP5-Manager-Server-5-0-BYOS-Azure
Image SLES15-SP5-Manager-Server-5-0-BYOS-EC2
Image SLES15-SP5-Manager-Server-5-0-BYOS-GCE
Image SLES15-SP5-Micro-5-5
Image SLES15-SP5-Micro-5-5-Azure
Image SLES15-SP5-Micro-5-5-BYOS
Image SLES15-SP5-Micro-5-5-BYOS-Azure
Image SLES15-SP5-Micro-5-5-BYOS-EC2
Image SLES15-SP5-Micro-5-5-BYOS-GCE
Image SLES15-SP5-Micro-5-5-EC2
Image SLES15-SP5-Micro-5-5-GCE
Image SLES15-SP5-SAPCAL-Azure
Image SLES15-SP5-SAPCAL-EC2
Image SLES15-SP5-SAPCAL-GCE
  • kernel-default >= 5.14.21-150500.55.52.1
Container suse/sle-micro-rancher/5.3:latest
Container suse/sle-micro-rancher/5.4:latest
Image SLES15-SP4-BYOS
Image SLES15-SP4-BYOS-Azure
Image SLES15-SP4-BYOS-EC2
Image SLES15-SP4-BYOS-GCE
Image SLES15-SP4-CHOST-BYOS
Image SLES15-SP4-CHOST-BYOS-Aliyun
Image SLES15-SP4-CHOST-BYOS-Azure
Image SLES15-SP4-CHOST-BYOS-EC2
Image SLES15-SP4-CHOST-BYOS-GCE
Image SLES15-SP4-CHOST-BYOS-SAP-CCloud
Image SLES15-SP4-HPC-BYOS
Image SLES15-SP4-HPC-BYOS-Azure
Image SLES15-SP4-HPC-BYOS-EC2
Image SLES15-SP4-HPC-BYOS-GCE
Image SLES15-SP4-HPC-EC2
Image SLES15-SP4-HPC-GCE
Image SLES15-SP4-Hardened-BYOS
Image SLES15-SP4-Hardened-BYOS-Azure
Image SLES15-SP4-Hardened-BYOS-EC2
Image SLES15-SP4-Hardened-BYOS-GCE
Image SLES15-SP4-Manager-Proxy-4-3-BYOS
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE
Image SLES15-SP4-Manager-Server-4-3
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
Image SLES15-SP4-Manager-Server-4-3-BYOS
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
Image SLES15-SP4-Micro-5-3
Image SLES15-SP4-Micro-5-3-BYOS
Image SLES15-SP4-Micro-5-3-BYOS-Azure
Image SLES15-SP4-Micro-5-3-BYOS-EC2
Image SLES15-SP4-Micro-5-3-BYOS-GCE
Image SLES15-SP4-Micro-5-3-EC2
Image SLES15-SP4-Micro-5-4
Image SLES15-SP4-Micro-5-4-BYOS
Image SLES15-SP4-Micro-5-4-BYOS-Azure
Image SLES15-SP4-Micro-5-4-BYOS-EC2
Image SLES15-SP4-Micro-5-4-BYOS-GCE
Image SLES15-SP4-Micro-5-4-EC2
Image SLES15-SP4-Micro-5-4-GCE
Image SLES15-SP4-SAP
Image SLES15-SP4-SAP-Azure
Image SLES15-SP4-SAP-EC2
Image SLES15-SP4-SAP-GCE
Image SLES15-SP4-SAPCAL
Image SLES15-SP4-SAPCAL-Azure
Image SLES15-SP4-SAPCAL-EC2
Image SLES15-SP4-SAPCAL-GCE
  • kernel-default >= 5.14.21-150400.24.111.2
Container suse/sle-micro/kvm-5.5:2.0.2-2.2.85
  • kernel-default-base >= 5.14.21-150500.55.52.1.150500.6.23.1
Container suse/sle-micro/rt-5.5:2.0.2-3.2.86
  • kernel-rt >= 5.14.21-150500.13.38.1
Image SLES15-SP4-SAP-Azure-LI-BYOS
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
Image SLES15-SP4-SAP-Azure-VLI-BYOS
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP4-SAP-BYOS
Image SLES15-SP4-SAP-BYOS-Azure
Image SLES15-SP4-SAP-BYOS-EC2
Image SLES15-SP4-SAP-BYOS-GCE
Image SLES15-SP4-SAP-Hardened
Image SLES15-SP4-SAP-Hardened-Azure
Image SLES15-SP4-SAP-Hardened-BYOS
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
Image SLES15-SP4-SAP-Hardened-BYOS-EC2
Image SLES15-SP4-SAP-Hardened-BYOS-GCE
Image SLES15-SP4-SAP-Hardened-GCE
  • cluster-md-kmp-default >= 5.14.21-150400.24.111.2
  • dlm-kmp-default >= 5.14.21-150400.24.111.2
  • gfs2-kmp-default >= 5.14.21-150400.24.111.2
  • kernel-default >= 5.14.21-150400.24.111.2
  • ocfs2-kmp-default >= 5.14.21-150400.24.111.2
Image SLES15-SP5-Azure-Basic
Image SLES15-SP5-Azure-Standard
Image SLES15-SP5-HPC-Azure
  • kernel-azure >= 5.14.21-150500.33.37.1
Image SLES15-SP5-SAP-Azure-LI-BYOS
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
Image SLES15-SP5-SAP-Azure-VLI-BYOS
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP5-SAP-BYOS-Azure
Image SLES15-SP5-SAP-BYOS-EC2
Image SLES15-SP5-SAP-BYOS-GCE
Image SLES15-SP5-SAP-Hardened-Azure
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
Image SLES15-SP5-SAP-Hardened-GCE
  • cluster-md-kmp-default >= 5.14.21-150500.55.52.1
  • dlm-kmp-default >= 5.14.21-150500.55.52.1
  • gfs2-kmp-default >= 5.14.21-150500.55.52.1
  • kernel-default >= 5.14.21-150500.55.52.1
  • ocfs2-kmp-default >= 5.14.21-150500.55.52.1
SUSE Linux Enterprise Desktop 15 SP5
  • kernel-64kb >= 5.14.21-150500.55.52.1
  • kernel-64kb-devel >= 5.14.21-150500.55.52.1
  • kernel-default >= 5.14.21-150500.55.52.1
  • kernel-default-base >= 5.14.21-150500.55.52.1.150500.6.23.1
  • kernel-default-devel >= 5.14.21-150500.55.52.1
  • kernel-default-extra >= 5.14.21-150500.55.52.1
  • kernel-devel >= 5.14.21-150500.55.52.1
  • kernel-docs >= 5.14.21-150500.55.52.1
  • kernel-macros >= 5.14.21-150500.55.52.1
  • kernel-obs-build >= 5.14.21-150500.55.52.1
  • kernel-source >= 5.14.21-150500.55.52.1
  • kernel-syms >= 5.14.21-150500.55.52.1
  • kernel-zfcpdump >= 5.14.21-150500.55.52.1
Patchnames:
SUSE-SLE-Module-Basesystem-15-SP5-2024-858
SUSE-SLE-Module-Development-Tools-15-SP5-2024-858
SUSE-SLE-Product-WE-15-SP5-2024-858
SUSE Linux Enterprise Desktop 15 SP6
  • kernel-64kb >= 6.4.0-150600.21.2
  • kernel-64kb-devel >= 6.4.0-150600.21.2
  • kernel-default >= 6.4.0-150600.21.3
  • kernel-default-devel >= 6.4.0-150600.21.3
  • kernel-devel >= 6.4.0-150600.21.2
  • kernel-docs >= 6.4.0-150600.21.1
  • kernel-macros >= 6.4.0-150600.21.2
  • kernel-obs-build >= 6.4.0-150600.21.2
  • kernel-source >= 6.4.0-150600.21.2
  • kernel-syms >= 6.4.0-150600.21.1
  • kernel-zfcpdump >= 6.4.0-150600.21.2
Patchnames:
SUSE Linux Enterprise Module for Basesystem 15 SP6 GA kernel-64kb-6.4.0-150600.21.2
SUSE Linux Enterprise Module for Development Tools 15 SP6 GA kernel-docs-6.4.0-150600.21.1
SUSE Linux Enterprise High Availability Extension 15 SP4
  • cluster-md-kmp-default >= 5.14.21-150400.24.111.2
  • dlm-kmp-default >= 5.14.21-150400.24.111.2
  • gfs2-kmp-default >= 5.14.21-150400.24.111.2
  • ocfs2-kmp-default >= 5.14.21-150400.24.111.2
Patchnames:
SUSE-SLE-Product-HA-15-SP4-2024-900
SUSE Linux Enterprise High Availability Extension 15 SP5
  • cluster-md-kmp-default >= 5.14.21-150500.55.52.1
  • dlm-kmp-default >= 5.14.21-150500.55.52.1
  • gfs2-kmp-default >= 5.14.21-150500.55.52.1
  • ocfs2-kmp-default >= 5.14.21-150500.55.52.1
Patchnames:
SUSE-SLE-Product-HA-15-SP5-2024-858
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
  • kernel-64kb >= 5.14.21-150400.24.111.2
  • kernel-64kb-devel >= 5.14.21-150400.24.111.2
  • kernel-default >= 5.14.21-150400.24.111.2
  • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
  • kernel-default-devel >= 5.14.21-150400.24.111.2
  • kernel-devel >= 5.14.21-150400.24.111.1
  • kernel-docs >= 5.14.21-150400.24.111.2
  • kernel-macros >= 5.14.21-150400.24.111.1
  • kernel-obs-build >= 5.14.21-150400.24.111.1
  • kernel-source >= 5.14.21-150400.24.111.1
  • kernel-syms >= 5.14.21-150400.24.111.1
  • reiserfs-kmp-default >= 5.14.21-150400.24.111.2
Patchnames:
SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-900
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
  • kernel-64kb >= 5.14.21-150400.24.111.2
  • kernel-64kb-devel >= 5.14.21-150400.24.111.2
  • kernel-default >= 5.14.21-150400.24.111.2
  • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
  • kernel-default-devel >= 5.14.21-150400.24.111.2
  • kernel-devel >= 5.14.21-150400.24.111.1
  • kernel-docs >= 5.14.21-150400.24.111.2
  • kernel-macros >= 5.14.21-150400.24.111.1
  • kernel-obs-build >= 5.14.21-150400.24.111.1
  • kernel-source >= 5.14.21-150400.24.111.1
  • kernel-syms >= 5.14.21-150400.24.111.1
  • reiserfs-kmp-default >= 5.14.21-150400.24.111.2
Patchnames:
SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-900
SUSE Linux Enterprise High Performance Computing 15 SP5
  • kernel-64kb >= 5.14.21-150500.55.52.1
  • kernel-64kb-devel >= 5.14.21-150500.55.52.1
  • kernel-azure >= 5.14.21-150500.33.37.1
  • kernel-azure-devel >= 5.14.21-150500.33.37.1
  • kernel-default >= 5.14.21-150500.55.52.1
  • kernel-default-base >= 5.14.21-150500.55.52.1.150500.6.23.1
  • kernel-default-devel >= 5.14.21-150500.55.52.1
  • kernel-devel >= 5.14.21-150500.55.52.1
  • kernel-devel-azure >= 5.14.21-150500.33.37.1
  • kernel-docs >= 5.14.21-150500.55.52.1
  • kernel-macros >= 5.14.21-150500.55.52.1
  • kernel-obs-build >= 5.14.21-150500.55.52.1
  • kernel-source >= 5.14.21-150500.55.52.1
  • kernel-source-azure >= 5.14.21-150500.33.37.1
  • kernel-syms >= 5.14.21-150500.55.52.1
  • kernel-syms-azure >= 5.14.21-150500.33.37.1
  • kernel-zfcpdump >= 5.14.21-150500.55.52.1
  • reiserfs-kmp-default >= 5.14.21-150500.55.52.1
Patchnames:
SUSE-SLE-Module-Basesystem-15-SP5-2024-858
SUSE-SLE-Module-Development-Tools-15-SP5-2024-858
SUSE-SLE-Module-Legacy-15-SP5-2024-858
SUSE-SLE-Module-Public-Cloud-15-SP5-2024-855
SUSE Linux Enterprise High Performance Computing 15 SP6
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15 SP6
  • kernel-64kb >= 6.4.0-150600.21.2
  • kernel-64kb-devel >= 6.4.0-150600.21.2
  • kernel-azure >= 6.4.0-150600.6.3
  • kernel-azure-devel >= 6.4.0-150600.6.3
  • kernel-default >= 6.4.0-150600.21.3
  • kernel-default-devel >= 6.4.0-150600.21.3
  • kernel-devel >= 6.4.0-150600.21.2
  • kernel-devel-azure >= 6.4.0-150600.6.2
  • kernel-docs >= 6.4.0-150600.21.1
  • kernel-macros >= 6.4.0-150600.21.2
  • kernel-obs-build >= 6.4.0-150600.21.2
  • kernel-source >= 6.4.0-150600.21.2
  • kernel-source-azure >= 6.4.0-150600.6.2
  • kernel-syms >= 6.4.0-150600.21.1
  • kernel-syms-azure >= 6.4.0-150600.6.1
  • kernel-zfcpdump >= 6.4.0-150600.21.2
  • reiserfs-kmp-default >= 6.4.0-150600.21.3
Patchnames:
SUSE Linux Enterprise Module for Basesystem 15 SP6 GA kernel-64kb-6.4.0-150600.21.2
SUSE Linux Enterprise Module for Development Tools 15 SP6 GA kernel-docs-6.4.0-150600.21.1
SUSE Linux Enterprise Module for Legacy 15 SP6 GA reiserfs-kmp-default-6.4.0-150600.21.3
SUSE Linux Enterprise Module for Public Cloud 15 SP6 GA kernel-azure-6.4.0-150600.6.3
SUSE Linux Enterprise Live Patching 15 SP4
    Patchnames:
    SUSE-SLE-Module-Live-Patching-15-SP4-2024-900
    SUSE-SLE-Module-Live-Patching-15-SP4-2024-977
    SUSE Linux Enterprise Live Patching 15 SP5
      Patchnames:
      SUSE-SLE-Module-Live-Patching-15-SP5-2024-858
      SUSE-SLE-Module-Live-Patching-15-SP5-2024-910
      SUSE Linux Enterprise Micro 5.3
      • kernel-default >= 5.14.21-150400.24.111.2
      • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
      • kernel-rt >= 5.14.21-150400.15.71.1
      • kernel-source-rt >= 5.14.21-150400.15.71.1
      Patchnames:
      SUSE-SLE-Micro-5.3-2024-900
      SUSE-SLE-Micro-5.3-2024-977
      SUSE Linux Enterprise Micro 5.4
      • kernel-default >= 5.14.21-150400.24.111.2
      • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
      • kernel-rt >= 5.14.21-150400.15.71.1
      • kernel-source-rt >= 5.14.21-150400.15.71.1
      Patchnames:
      SUSE-SLE-Micro-5.4-2024-900
      SUSE-SLE-Micro-5.4-2024-977
      SUSE Linux Enterprise Micro 5.5
      • kernel-default >= 5.14.21-150500.55.52.1
      • kernel-default-base >= 5.14.21-150500.55.52.1.150500.6.23.1
      • kernel-rt >= 5.14.21-150500.13.38.1
      • kernel-source-rt >= 5.14.21-150500.13.38.1
      Patchnames:
      SUSE-SLE-Micro-5.5-2024-858
      SUSE-SLE-Micro-5.5-2024-910
      SUSE Linux Enterprise Module for Basesystem 15 SP5
      • kernel-64kb >= 5.14.21-150500.55.52.1
      • kernel-64kb-devel >= 5.14.21-150500.55.52.1
      • kernel-default >= 5.14.21-150500.55.52.1
      • kernel-default-base >= 5.14.21-150500.55.52.1.150500.6.23.1
      • kernel-default-devel >= 5.14.21-150500.55.52.1
      • kernel-devel >= 5.14.21-150500.55.52.1
      • kernel-macros >= 5.14.21-150500.55.52.1
      • kernel-zfcpdump >= 5.14.21-150500.55.52.1
      Patchnames:
      SUSE-SLE-Module-Basesystem-15-SP5-2024-858
      SUSE Linux Enterprise Module for Basesystem 15 SP6
      • kernel-64kb >= 6.4.0-150600.21.2
      • kernel-64kb-devel >= 6.4.0-150600.21.2
      • kernel-default >= 6.4.0-150600.21.3
      • kernel-default-devel >= 6.4.0-150600.21.3
      • kernel-devel >= 6.4.0-150600.21.2
      • kernel-macros >= 6.4.0-150600.21.2
      • kernel-zfcpdump >= 6.4.0-150600.21.2
      Patchnames:
      SUSE Linux Enterprise Module for Basesystem 15 SP6 GA kernel-64kb-6.4.0-150600.21.2
      SUSE Linux Enterprise Module for Development Tools 15 SP5
      • kernel-docs >= 5.14.21-150500.55.52.1
      • kernel-obs-build >= 5.14.21-150500.55.52.1
      • kernel-source >= 5.14.21-150500.55.52.1
      • kernel-syms >= 5.14.21-150500.55.52.1
      Patchnames:
      SUSE-SLE-Module-Development-Tools-15-SP5-2024-858
      SUSE Linux Enterprise Module for Development Tools 15 SP6
      • kernel-docs >= 6.4.0-150600.21.1
      • kernel-obs-build >= 6.4.0-150600.21.2
      • kernel-source >= 6.4.0-150600.21.2
      • kernel-syms >= 6.4.0-150600.21.1
      Patchnames:
      SUSE Linux Enterprise Module for Development Tools 15 SP6 GA kernel-docs-6.4.0-150600.21.1
      SUSE Linux Enterprise Module for Legacy 15 SP5
      • reiserfs-kmp-default >= 5.14.21-150500.55.52.1
      Patchnames:
      SUSE-SLE-Module-Legacy-15-SP5-2024-858
      SUSE Linux Enterprise Module for Legacy 15 SP6
      • reiserfs-kmp-default >= 6.4.0-150600.21.3
      Patchnames:
      SUSE Linux Enterprise Module for Legacy 15 SP6 GA reiserfs-kmp-default-6.4.0-150600.21.3
      SUSE Linux Enterprise Module for Public Cloud 15 SP5
      • kernel-azure >= 5.14.21-150500.33.37.1
      • kernel-azure-devel >= 5.14.21-150500.33.37.1
      • kernel-devel-azure >= 5.14.21-150500.33.37.1
      • kernel-source-azure >= 5.14.21-150500.33.37.1
      • kernel-syms-azure >= 5.14.21-150500.33.37.1
      Patchnames:
      SUSE-SLE-Module-Public-Cloud-15-SP5-2024-855
      SUSE Linux Enterprise Module for Public Cloud 15 SP6
      • kernel-azure >= 6.4.0-150600.6.3
      • kernel-azure-devel >= 6.4.0-150600.6.3
      • kernel-devel-azure >= 6.4.0-150600.6.2
      • kernel-source-azure >= 6.4.0-150600.6.2
      • kernel-syms-azure >= 6.4.0-150600.6.1
      Patchnames:
      SUSE Linux Enterprise Module for Public Cloud 15 SP6 GA kernel-azure-6.4.0-150600.6.3
      SUSE Linux Enterprise Real Time 15 SP5
      SUSE Real Time Module 15 SP5
      • cluster-md-kmp-rt >= 5.14.21-150500.13.38.1
      • dlm-kmp-rt >= 5.14.21-150500.13.38.1
      • gfs2-kmp-rt >= 5.14.21-150500.13.38.1
      • kernel-devel-rt >= 5.14.21-150500.13.38.1
      • kernel-rt >= 5.14.21-150500.13.38.1
      • kernel-rt-devel >= 5.14.21-150500.13.38.1
      • kernel-rt-vdso >= 5.14.21-150500.13.38.1
      • kernel-rt_debug >= 5.14.21-150500.13.38.1
      • kernel-rt_debug-devel >= 5.14.21-150500.13.38.1
      • kernel-rt_debug-vdso >= 5.14.21-150500.13.38.1
      • kernel-source-rt >= 5.14.21-150500.13.38.1
      • kernel-syms-rt >= 5.14.21-150500.13.38.1
      • ocfs2-kmp-rt >= 5.14.21-150500.13.38.1
      Patchnames:
      SUSE-SLE-Module-RT-15-SP5-2024-910
      SUSE Linux Enterprise Server 15 SP4-LTSS
      • kernel-64kb >= 5.14.21-150400.24.111.2
      • kernel-64kb-devel >= 5.14.21-150400.24.111.2
      • kernel-default >= 5.14.21-150400.24.111.2
      • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
      • kernel-default-devel >= 5.14.21-150400.24.111.2
      • kernel-devel >= 5.14.21-150400.24.111.1
      • kernel-docs >= 5.14.21-150400.24.111.2
      • kernel-macros >= 5.14.21-150400.24.111.1
      • kernel-obs-build >= 5.14.21-150400.24.111.1
      • kernel-source >= 5.14.21-150400.24.111.1
      • kernel-syms >= 5.14.21-150400.24.111.1
      • kernel-zfcpdump >= 5.14.21-150400.24.111.2
      • reiserfs-kmp-default >= 5.14.21-150400.24.111.2
      Patchnames:
      SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-900
      SUSE Linux Enterprise Server 15 SP5
      SUSE Linux Enterprise Server for SAP Applications 15 SP5
      • kernel-64kb >= 5.14.21-150500.55.52.1
      • kernel-64kb-devel >= 5.14.21-150500.55.52.1
      • kernel-azure >= 5.14.21-150500.33.37.1
      • kernel-azure-devel >= 5.14.21-150500.33.37.1
      • kernel-default >= 5.14.21-150500.55.52.1
      • kernel-default-base >= 5.14.21-150500.55.52.1.150500.6.23.1
      • kernel-default-devel >= 5.14.21-150500.55.52.1
      • kernel-default-extra >= 5.14.21-150500.55.52.1
      • kernel-devel >= 5.14.21-150500.55.52.1
      • kernel-devel-azure >= 5.14.21-150500.33.37.1
      • kernel-docs >= 5.14.21-150500.55.52.1
      • kernel-macros >= 5.14.21-150500.55.52.1
      • kernel-obs-build >= 5.14.21-150500.55.52.1
      • kernel-source >= 5.14.21-150500.55.52.1
      • kernel-source-azure >= 5.14.21-150500.33.37.1
      • kernel-syms >= 5.14.21-150500.55.52.1
      • kernel-syms-azure >= 5.14.21-150500.33.37.1
      • kernel-zfcpdump >= 5.14.21-150500.55.52.1
      • reiserfs-kmp-default >= 5.14.21-150500.55.52.1
      Patchnames:
      SUSE-SLE-Module-Basesystem-15-SP5-2024-858
      SUSE-SLE-Module-Development-Tools-15-SP5-2024-858
      SUSE-SLE-Module-Legacy-15-SP5-2024-858
      SUSE-SLE-Module-Public-Cloud-15-SP5-2024-855
      SUSE-SLE-Product-WE-15-SP5-2024-858
      SUSE Linux Enterprise Server for SAP Applications 15 SP4
      • kernel-default >= 5.14.21-150400.24.111.2
      • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
      • kernel-default-devel >= 5.14.21-150400.24.111.2
      • kernel-devel >= 5.14.21-150400.24.111.1
      • kernel-docs >= 5.14.21-150400.24.111.2
      • kernel-macros >= 5.14.21-150400.24.111.1
      • kernel-obs-build >= 5.14.21-150400.24.111.1
      • kernel-source >= 5.14.21-150400.24.111.1
      • kernel-syms >= 5.14.21-150400.24.111.1
      • reiserfs-kmp-default >= 5.14.21-150400.24.111.2
      Patchnames:
      SUSE-SLE-Product-SLES_SAP-15-SP4-2024-900
      SUSE Linux Enterprise Workstation Extension 15 SP5
      • kernel-default-extra >= 5.14.21-150500.55.52.1
      Patchnames:
      SUSE-SLE-Product-WE-15-SP5-2024-858
      SUSE Linux Micro 6.0
      • kernel-default >= 6.4.0-17.1
      • kernel-default-extra >= 6.4.0-17.1
      • kernel-rt >= 6.4.0-8.1
      Patchnames:
      SUSE Linux Micro 6.0 GA kernel-default-6.4.0-17.1
      SUSE Linux Micro 6.0 GA kernel-rt-6.4.0-8.1
      SUSE Linux Micro 6.1
      • kernel-default >= 6.4.0-19.1
      • kernel-default-devel >= 6.4.0-19.1
      • kernel-default-extra >= 6.4.0-19.1
      • kernel-default-livepatch >= 6.4.0-19.1
      • kernel-devel >= 6.4.0-19.1
      • kernel-devel-rt >= 6.4.0-10.1
      • kernel-kvmsmall >= 6.4.0-19.1
      • kernel-macros >= 6.4.0-19.1
      • kernel-rt >= 6.4.0-10.1
      • kernel-rt-devel >= 6.4.0-10.1
      • kernel-source >= 6.4.0-19.1
      • kernel-source-rt >= 6.4.0-10.1
      Patchnames:
      SUSE Linux Micro 6.1 GA kernel-default-6.4.0-19.1
      SUSE Manager Proxy 4.3
      • kernel-default >= 5.14.21-150400.24.111.2
      • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
      • kernel-default-devel >= 5.14.21-150400.24.111.2
      • kernel-devel >= 5.14.21-150400.24.111.1
      • kernel-macros >= 5.14.21-150400.24.111.1
      • kernel-source >= 5.14.21-150400.24.111.1
      • kernel-syms >= 5.14.21-150400.24.111.1
      Patchnames:
      SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-900
      SUSE Manager Retail Branch Server 4.3
      • kernel-default >= 5.14.21-150400.24.111.2
      • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
      • kernel-default-devel >= 5.14.21-150400.24.111.2
      • kernel-devel >= 5.14.21-150400.24.111.1
      • kernel-macros >= 5.14.21-150400.24.111.1
      Patchnames:
      SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.3-2024-900
      SUSE Manager Server 4.3
      • kernel-default >= 5.14.21-150400.24.111.2
      • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
      • kernel-default-devel >= 5.14.21-150400.24.111.2
      • kernel-devel >= 5.14.21-150400.24.111.1
      • kernel-macros >= 5.14.21-150400.24.111.1
      • kernel-source >= 5.14.21-150400.24.111.1
      • kernel-syms >= 5.14.21-150400.24.111.1
      • kernel-zfcpdump >= 5.14.21-150400.24.111.2
      Patchnames:
      SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-900
      openSUSE Leap 15.5
      • cluster-md-kmp-64kb >= 5.14.21-150500.55.52.1
      • cluster-md-kmp-azure >= 5.14.21-150500.33.37.1
      • cluster-md-kmp-default >= 5.14.21-150500.55.52.1
      • cluster-md-kmp-rt >= 5.14.21-150500.13.38.1
      • dlm-kmp-64kb >= 5.14.21-150500.55.52.1
      • dlm-kmp-azure >= 5.14.21-150500.33.37.1
      • dlm-kmp-default >= 5.14.21-150500.55.52.1
      • dlm-kmp-rt >= 5.14.21-150500.13.38.1
      • dtb-allwinner >= 5.14.21-150500.55.52.1
      • dtb-altera >= 5.14.21-150500.55.52.1
      • dtb-amazon >= 5.14.21-150500.55.52.1
      • dtb-amd >= 5.14.21-150500.55.52.1
      • dtb-amlogic >= 5.14.21-150500.55.52.1
      • dtb-apm >= 5.14.21-150500.55.52.1
      • dtb-apple >= 5.14.21-150500.55.52.1
      • dtb-arm >= 5.14.21-150500.55.52.1
      • dtb-broadcom >= 5.14.21-150500.55.52.1
      • dtb-cavium >= 5.14.21-150500.55.52.1
      • dtb-exynos >= 5.14.21-150500.55.52.1
      • dtb-freescale >= 5.14.21-150500.55.52.1
      • dtb-hisilicon >= 5.14.21-150500.55.52.1
      • dtb-lg >= 5.14.21-150500.55.52.1
      • dtb-marvell >= 5.14.21-150500.55.52.1
      • dtb-mediatek >= 5.14.21-150500.55.52.1
      • dtb-nvidia >= 5.14.21-150500.55.52.1
      • dtb-qcom >= 5.14.21-150500.55.52.1
      • dtb-renesas >= 5.14.21-150500.55.52.1
      • dtb-rockchip >= 5.14.21-150500.55.52.1
      • dtb-socionext >= 5.14.21-150500.55.52.1
      • dtb-sprd >= 5.14.21-150500.55.52.1
      • dtb-xilinx >= 5.14.21-150500.55.52.1
      • gfs2-kmp-64kb >= 5.14.21-150500.55.52.1
      • gfs2-kmp-azure >= 5.14.21-150500.33.37.1
      • gfs2-kmp-default >= 5.14.21-150500.55.52.1
      • gfs2-kmp-rt >= 5.14.21-150500.13.38.1
      • kernel-64kb >= 5.14.21-150500.55.52.1
      • kernel-64kb-devel >= 5.14.21-150500.55.52.1
      • kernel-64kb-extra >= 5.14.21-150500.55.52.1
      • kernel-64kb-livepatch-devel >= 5.14.21-150500.55.52.1
      • kernel-64kb-optional >= 5.14.21-150500.55.52.1
      • kernel-azure >= 5.14.21-150500.33.37.1
      • kernel-azure-devel >= 5.14.21-150500.33.37.1
      • kernel-azure-extra >= 5.14.21-150500.33.37.1
      • kernel-azure-livepatch-devel >= 5.14.21-150500.33.37.1
      • kernel-azure-optional >= 5.14.21-150500.33.37.1
      • kernel-azure-vdso >= 5.14.21-150500.33.37.1
      • kernel-debug >= 5.14.21-150500.55.52.1
      • kernel-debug-devel >= 5.14.21-150500.55.52.1
      • kernel-debug-livepatch-devel >= 5.14.21-150500.55.52.1
      • kernel-debug-vdso >= 5.14.21-150500.55.52.1
      • kernel-default >= 5.14.21-150500.55.52.1
      • kernel-default-base >= 5.14.21-150500.55.52.1.150500.6.23.1
      • kernel-default-base-rebuild >= 5.14.21-150500.55.52.1.150500.6.23.1
      • kernel-default-devel >= 5.14.21-150500.55.52.1
      • kernel-default-extra >= 5.14.21-150500.55.52.1
      • kernel-default-livepatch >= 5.14.21-150500.55.52.1
      • kernel-default-livepatch-devel >= 5.14.21-150500.55.52.1
      • kernel-default-optional >= 5.14.21-150500.55.52.1
      • kernel-default-vdso >= 5.14.21-150500.55.52.1
      • kernel-devel >= 5.14.21-150500.55.52.1
      • kernel-devel-azure >= 5.14.21-150500.33.37.1
      • kernel-devel-rt >= 5.14.21-150500.13.38.1
      • kernel-docs >= 5.14.21-150500.55.52.1
      • kernel-docs-html >= 5.14.21-150500.55.52.1
      • kernel-kvmsmall >= 5.14.21-150500.55.52.1
      • kernel-kvmsmall-devel >= 5.14.21-150500.55.52.1
      • kernel-kvmsmall-livepatch-devel >= 5.14.21-150500.55.52.1
      • kernel-kvmsmall-vdso >= 5.14.21-150500.55.52.1
      • kernel-macros >= 5.14.21-150500.55.52.1
      • kernel-obs-build >= 5.14.21-150500.55.52.1
      • kernel-obs-qa >= 5.14.21-150500.55.52.1
      • kernel-rt >= 5.14.21-150500.13.38.1
      • kernel-rt-devel >= 5.14.21-150500.13.38.1
      • kernel-rt-extra >= 5.14.21-150500.13.38.1
      • kernel-rt-livepatch >= 5.14.21-150500.13.38.1
      • kernel-rt-livepatch-devel >= 5.14.21-150500.13.38.1
      • kernel-rt-optional >= 5.14.21-150500.13.38.1
      • kernel-rt-vdso >= 5.14.21-150500.13.38.1
      • kernel-rt_debug >= 5.14.21-150500.13.38.1
      • kernel-rt_debug-devel >= 5.14.21-150500.13.38.1
      • kernel-rt_debug-livepatch-devel >= 5.14.21-150500.13.38.1
      • kernel-rt_debug-vdso >= 5.14.21-150500.13.38.1
      • kernel-source >= 5.14.21-150500.55.52.1
      • kernel-source-azure >= 5.14.21-150500.33.37.1
      • kernel-source-rt >= 5.14.21-150500.13.38.1
      • kernel-source-vanilla >= 5.14.21-150500.55.52.1
      • kernel-syms >= 5.14.21-150500.55.52.1
      • kernel-syms-azure >= 5.14.21-150500.33.37.1
      • kernel-syms-rt >= 5.14.21-150500.13.38.1
      • kernel-zfcpdump >= 5.14.21-150500.55.52.1
      • kselftests-kmp-64kb >= 5.14.21-150500.55.52.1
      • kselftests-kmp-azure >= 5.14.21-150500.33.37.1
      • kselftests-kmp-default >= 5.14.21-150500.55.52.1
      • kselftests-kmp-rt >= 5.14.21-150500.13.38.1
      • ocfs2-kmp-64kb >= 5.14.21-150500.55.52.1
      • ocfs2-kmp-azure >= 5.14.21-150500.33.37.1
      • ocfs2-kmp-default >= 5.14.21-150500.55.52.1
      • ocfs2-kmp-rt >= 5.14.21-150500.13.38.1
      • reiserfs-kmp-64kb >= 5.14.21-150500.55.52.1
      • reiserfs-kmp-azure >= 5.14.21-150500.33.37.1
      • reiserfs-kmp-default >= 5.14.21-150500.55.52.1
      • reiserfs-kmp-rt >= 5.14.21-150500.13.38.1
      Patchnames:
      openSUSE-SLE-15.5-2024-855
      openSUSE-SLE-15.5-2024-858
      openSUSE-SLE-15.5-2024-910
      openSUSE Leap Micro 5.3
      • kernel-default >= 5.14.21-150400.24.111.2
      • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
      • kernel-rt >= 5.14.21-150400.15.71.1
      Patchnames:
      openSUSE-Leap-Micro-5.3-2024-900
      openSUSE-Leap-Micro-5.3-2024-977
      openSUSE Leap Micro 5.4
      • kernel-default >= 5.14.21-150400.24.111.2
      • kernel-default-base >= 5.14.21-150400.24.111.2.150400.24.52.1
      • kernel-rt >= 5.14.21-150400.15.71.1
      Patchnames:
      openSUSE-Leap-Micro-5.4-2024-900
      openSUSE-Leap-Micro-5.4-2024-977
      openSUSE Leap Micro 5.5
      • kernel-default >= 5.14.21-150500.55.52.1
      • kernel-default-base >= 5.14.21-150500.55.52.1.150500.6.23.1
      • kernel-rt >= 5.14.21-150500.13.38.1
      Patchnames:
      openSUSE-Leap-Micro-5.5-2024-858
      openSUSE-Leap-Micro-5.5-2024-910


      First public cloud image revisions this CVE is fixed in:


      Status of this issue by product and package

      Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification. The updates are grouped by state of their lifecycle. SUSE product lifecycles are documented on the lifecycle page.

      Product(s) Source package State
      Products under general support and receiving all security fixes.
      SLES15-SP5-CHOST-BYOS-Aliyun kernel-default Released
      SLES15-SP5-CHOST-BYOS-Azure kernel-default Released
      SLES15-SP5-CHOST-BYOS-EC2 kernel-default Released
      SLES15-SP5-CHOST-BYOS-GCE kernel-default Released
      SLES15-SP5-CHOST-BYOS-SAP-CCloud kernel-default Released
      SUSE Linux Enterprise Desktop 15 SP5 kernel-64kb Released
      SUSE Linux Enterprise Desktop 15 SP5 kernel-default Released
      SUSE Linux Enterprise Desktop 15 SP5 kernel-default-base Released
      SUSE Linux Enterprise Desktop 15 SP5 kernel-docs Released
      SUSE Linux Enterprise Desktop 15 SP5 kernel-obs-build Released
      SUSE Linux Enterprise Desktop 15 SP5 kernel-source Released
      SUSE Linux Enterprise Desktop 15 SP5 kernel-syms Released
      SUSE Linux Enterprise Desktop 15 SP5 kernel-zfcpdump Released
      SUSE Linux Enterprise Desktop 15 SP6 kernel-default Already fixed
      SUSE Linux Enterprise Desktop 15 SP6 kernel-source Already fixed
      SUSE Linux Enterprise High Availability Extension 15 SP5 kernel-default Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-64kb Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-azure Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-default Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-default-base Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-docs Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-obs-build Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-source Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-source-azure Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-syms Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-syms-azure Released
      SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-zfcpdump Released
      SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-default Affected
      SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-source Affected
      SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-default Released
      SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-source Released
      SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-default Already fixed
      SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-source Already fixed
      SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-source-azure Already fixed
      SUSE Linux Enterprise Live Patching 15 SP5 kernel-default Released
      SUSE Linux Enterprise Live Patching 15 SP5 kernel-livepatch-SLE15-SP5-RT_Update_11 Released
      SUSE Linux Enterprise Live Patching 15 SP5 kernel-livepatch-SLE15-SP5_Update_11 Released
      SUSE Linux Enterprise Micro 5.1 kernel-default Not affected
      SUSE Linux Enterprise Micro 5.1 kernel-rt Not affected
      SUSE Linux Enterprise Micro 5.1 kernel-source-rt Not affected
      SUSE Linux Enterprise Micro 5.2 kernel-default Not affected
      SUSE Linux Enterprise Micro 5.2 kernel-rt Not affected
      SUSE Linux Enterprise Micro 5.2 kernel-source-rt Not affected
      SUSE Linux Enterprise Micro 5.3 kernel-default Released
      SUSE Linux Enterprise Micro 5.3 kernel-default-base Released
      SUSE Linux Enterprise Micro 5.3 kernel-rt Released
      SUSE Linux Enterprise Micro 5.3 kernel-source-rt Released
      SUSE Linux Enterprise Micro 5.4 kernel-default Released
      SUSE Linux Enterprise Micro 5.4 kernel-default-base Released
      SUSE Linux Enterprise Micro 5.4 kernel-rt Released
      SUSE Linux Enterprise Micro 5.4 kernel-source-rt Released
      SUSE Linux Enterprise Micro 5.5 kernel-default Released
      SUSE Linux Enterprise Micro 5.5 kernel-default-base Released
      SUSE Linux Enterprise Micro 5.5 kernel-rt Released
      SUSE Linux Enterprise Micro 5.5 kernel-source-rt Released
      SUSE Linux Enterprise Micro for Rancher 5.3 kernel-source-rt Released
      SUSE Linux Enterprise Micro for Rancher 5.4 kernel-source-rt Released
      SUSE Linux Enterprise Module for Basesystem 15 SP5 kernel-64kb Released
      SUSE Linux Enterprise Module for Basesystem 15 SP5 kernel-default Released
      SUSE Linux Enterprise Module for Basesystem 15 SP5 kernel-default-base Released
      SUSE Linux Enterprise Module for Basesystem 15 SP5 kernel-source Released
      SUSE Linux Enterprise Module for Basesystem 15 SP5 kernel-zfcpdump Released
      SUSE Linux Enterprise Module for Basesystem 15 SP6 kernel-default Already fixed
      SUSE Linux Enterprise Module for Basesystem 15 SP6 kernel-source Already fixed
      SUSE Linux Enterprise Module for Development Tools 15 SP5 kernel-default Released
      SUSE Linux Enterprise Module for Development Tools 15 SP5 kernel-docs Released
      SUSE Linux Enterprise Module for Development Tools 15 SP5 kernel-obs-build Released
      SUSE Linux Enterprise Module for Development Tools 15 SP5 kernel-source Released
      SUSE Linux Enterprise Module for Development Tools 15 SP5 kernel-syms Released
      SUSE Linux Enterprise Module for Development Tools 15 SP6 kernel-default Already fixed
      SUSE Linux Enterprise Module for Development Tools 15 SP6 kernel-source Already fixed
      SUSE Linux Enterprise Module for Legacy 15 SP5 kernel-default Released
      SUSE Linux Enterprise Module for Public Cloud 15 SP5 kernel-azure Released
      SUSE Linux Enterprise Module for Public Cloud 15 SP5 kernel-source-azure Released
      SUSE Linux Enterprise Module for Public Cloud 15 SP5 kernel-syms-azure Released
      SUSE Linux Enterprise Module for Public Cloud 15 SP6 kernel-source-azure Already fixed
      SUSE Linux Enterprise Real Time 15 SP5 kernel-rt Released
      SUSE Linux Enterprise Real Time 15 SP5 kernel-rt_debug Released
      SUSE Linux Enterprise Real Time 15 SP5 kernel-source-rt Released
      SUSE Linux Enterprise Real Time 15 SP5 kernel-syms-rt Released
      SUSE Linux Enterprise Real Time 15 SP6 kernel-source-rt Already fixed
      SUSE Linux Enterprise Server 15 SP5 kernel-64kb Released
      SUSE Linux Enterprise Server 15 SP5 kernel-azure Released
      SUSE Linux Enterprise Server 15 SP5 kernel-default Released
      SUSE Linux Enterprise Server 15 SP5 kernel-default-base Released
      SUSE Linux Enterprise Server 15 SP5 kernel-docs Released
      SUSE Linux Enterprise Server 15 SP5 kernel-obs-build Released
      SUSE Linux Enterprise Server 15 SP5 kernel-source Released
      SUSE Linux Enterprise Server 15 SP5 kernel-source-azure Released
      SUSE Linux Enterprise Server 15 SP5 kernel-syms Released
      SUSE Linux Enterprise Server 15 SP5 kernel-syms-azure Released
      SUSE Linux Enterprise Server 15 SP5 kernel-zfcpdump Released
      SUSE Linux Enterprise Server 15 SP5-LTSS kernel-default Released
      SUSE Linux Enterprise Server 15 SP5-LTSS kernel-source Released
      SUSE Linux Enterprise Server 15 SP6 kernel-default Already fixed
      SUSE Linux Enterprise Server 15 SP6 kernel-source Already fixed
      SUSE Linux Enterprise Server 15 SP6 kernel-source-azure Already fixed
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-64kb Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-azure Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-default Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-default-base Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-docs Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-obs-build Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-source Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-source-azure Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-syms Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-syms-azure Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-zfcpdump Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-default Already fixed
      SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-source Already fixed
      SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-source-azure Already fixed
      SUSE Linux Enterprise Workstation Extension 15 SP5 kernel-default Released
      SUSE Linux Micro 6.0 kernel-default Released
      SUSE Linux Micro 6.0 kernel-source Released
      SUSE Linux Micro 6.0 kernel-source-rt Released
      SUSE Manager Proxy 4.3 kernel-default Released
      SUSE Manager Proxy 4.3 kernel-default-base Released
      SUSE Manager Proxy 4.3 kernel-source Released
      SUSE Manager Proxy 4.3 kernel-source-azure Unsupported
      SUSE Manager Proxy 4.3 kernel-syms Released
      SUSE Manager Retail Branch Server 4.3 kernel-default Released
      SUSE Manager Retail Branch Server 4.3 kernel-default-base Released
      SUSE Manager Retail Branch Server 4.3 kernel-source Released
      SUSE Manager Retail Branch Server 4.3 kernel-source-azure Unsupported
      SUSE Manager Server 4.3 kernel-default Released
      SUSE Manager Server 4.3 kernel-default-base Released
      SUSE Manager Server 4.3 kernel-source Released
      SUSE Manager Server 4.3 kernel-source-azure Unsupported
      SUSE Manager Server 4.3 kernel-syms Released
      SUSE Manager Server 4.3 kernel-zfcpdump Released
      SUSE Real Time Module 15 SP5 kernel-rt Released
      SUSE Real Time Module 15 SP5 kernel-rt_debug Released
      SUSE Real Time Module 15 SP5 kernel-source-rt Released
      SUSE Real Time Module 15 SP5 kernel-syms-rt Released
      SUSE Real Time Module 15 SP6 kernel-source-rt Already fixed
      openSUSE Leap 15.5 kernel-default Released
      openSUSE Leap 15.5 kernel-source Released
      openSUSE Leap 15.5 kernel-source-azure Released
      openSUSE Leap 15.5 kernel-source-rt Released
      openSUSE Leap 15.6 kernel-default Already fixed
      openSUSE Leap 15.6 kernel-source Already fixed
      openSUSE Leap 15.6 kernel-source-azure Already fixed
      openSUSE Leap 15.6 kernel-source-rt Already fixed
      openSUSE Leap Micro 5.5 kernel-default Affected
      Products under Long Term Service Pack support and receiving important and critical security fixes.
      SUSE Linux Enterprise Desktop 15 SP4 kernel-source Affected
      SUSE Linux Enterprise Desktop 15 SP4 LTSS kernel-default Released
      SUSE Linux Enterprise Desktop 15 SP4 LTSS kernel-source Released
      SUSE Linux Enterprise High Availability Extension 15 SP4 kernel-default Released
      SUSE Linux Enterprise High Performance Computing 12 SP5 kernel-default Not affected
      SUSE Linux Enterprise High Performance Computing 12 SP5 kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 12 SP5 kernel-source-azure Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP2 kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP2 kernel-source-azure Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS kernel-default Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP3 kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP3 kernel-source-azure Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-default Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP4 kernel-source Affected
      SUSE Linux Enterprise High Performance Computing 15 SP4 kernel-source-azure Unsupported
      SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS kernel-64kb Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS kernel-default Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS kernel-default-base Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS kernel-docs Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS kernel-obs-build Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS kernel-source Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS kernel-syms Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS kernel-64kb Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS kernel-default Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS kernel-default-base Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS kernel-docs Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS kernel-obs-build Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS kernel-source Released
      SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS kernel-syms Released
      SUSE Linux Enterprise Live Patching 15 SP4 kernel-default Released
      SUSE Linux Enterprise Live Patching 15 SP4 kernel-livepatch-SLE15-SP4-RT_Update_19 Released
      SUSE Linux Enterprise Live Patching 15 SP4 kernel-livepatch-SLE15-SP4_Update_24 Released
      SUSE Linux Enterprise Module for Basesystem 15 SP2 kernel-source Not affected
      SUSE Linux Enterprise Module for Basesystem 15 SP3 kernel-source Not affected
      SUSE Linux Enterprise Module for Basesystem 15 SP4 kernel-source Affected
      SUSE Linux Enterprise Module for Development Tools 15 SP2 kernel-source Not affected
      SUSE Linux Enterprise Module for Development Tools 15 SP3 kernel-source Not affected
      SUSE Linux Enterprise Module for Development Tools 15 SP4 kernel-source Affected
      SUSE Linux Enterprise Module for Public Cloud 15 SP4 kernel-source-azure Unsupported
      SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-default Not affected
      SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP5 kernel-default Not affected
      SUSE Linux Enterprise Server 12 SP5 kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP5 kernel-source-azure Not affected
      SUSE Linux Enterprise Server 12 SP5-LTSS kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP5-LTSS kernel-source-azure Not affected
      SUSE Linux Enterprise Server 15 SP2 kernel-source Not affected
      SUSE Linux Enterprise Server 15 SP2 kernel-source-azure Not affected
      SUSE Linux Enterprise Server 15 SP2-LTSS kernel-default Not affected
      SUSE Linux Enterprise Server 15 SP2-LTSS kernel-source Not affected
      SUSE Linux Enterprise Server 15 SP3 kernel-source Not affected
      SUSE Linux Enterprise Server 15 SP3 kernel-source-azure Not affected
      SUSE Linux Enterprise Server 15 SP3-LTSS kernel-default Not affected
      SUSE Linux Enterprise Server 15 SP3-LTSS kernel-source Not affected
      SUSE Linux Enterprise Server 15 SP4 kernel-source Affected
      SUSE Linux Enterprise Server 15 SP4 kernel-source-azure Unsupported
      SUSE Linux Enterprise Server 15 SP4-LTSS kernel-64kb Released
      SUSE Linux Enterprise Server 15 SP4-LTSS kernel-default Released
      SUSE Linux Enterprise Server 15 SP4-LTSS kernel-default-base Released
      SUSE Linux Enterprise Server 15 SP4-LTSS kernel-docs Released
      SUSE Linux Enterprise Server 15 SP4-LTSS kernel-obs-build Released
      SUSE Linux Enterprise Server 15 SP4-LTSS kernel-source Released
      SUSE Linux Enterprise Server 15 SP4-LTSS kernel-syms Released
      SUSE Linux Enterprise Server 15 SP4-LTSS kernel-zfcpdump Released
      SUSE Linux Enterprise Server LTSS Extended Security 12 SP5 kernel-source Not affected
      SUSE Linux Enterprise Server LTSS Extended Security 12 SP5 kernel-source-azure Not affected
      SUSE Linux Enterprise Server for SAP Applications 12 SP5 kernel-default Not affected
      SUSE Linux Enterprise Server for SAP Applications 12 SP5 kernel-source Not affected
      SUSE Linux Enterprise Server for SAP Applications 12 SP5 kernel-source-azure Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 SP2 kernel-default Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 SP2 kernel-source Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 SP2 kernel-source-azure Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 SP3 kernel-default Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 SP3 kernel-source Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 SP3 kernel-source-azure Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 SP4 kernel-default Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP4 kernel-default-base Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP4 kernel-docs Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP4 kernel-obs-build Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP4 kernel-source Released
      SUSE Linux Enterprise Server for SAP Applications 15 SP4 kernel-source-azure Unsupported
      SUSE Linux Enterprise Server for SAP Applications 15 SP4 kernel-syms Released
      Products past their end of life and not receiving proactive updates anymore.
      HPE Helion OpenStack 8 kernel-source Not affected
      SUSE CaaS Platform 4.0 kernel-default Not affected
      SUSE CaaS Platform 4.0 kernel-source Not affected
      SUSE CaaS Platform Toolchain 3 kernel-source Not affected
      SUSE Enterprise Storage 6 kernel-source Not affected
      SUSE Enterprise Storage 7 kernel-source Not affected
      SUSE Enterprise Storage 7 kernel-source-azure Not affected
      SUSE Enterprise Storage 7.1 kernel-default Not affected
      SUSE Enterprise Storage 7.1 kernel-source Not affected
      SUSE Enterprise Storage 7.1 kernel-source-azure Not affected
      SUSE Linux Enterprise Desktop 11 SP4 kernel-source Not affected
      SUSE Linux Enterprise Desktop 12 SP2 kernel-source Not affected
      SUSE Linux Enterprise Desktop 12 SP3 kernel-source Not affected
      SUSE Linux Enterprise Desktop 12 SP4 kernel-source Not affected
      SUSE Linux Enterprise Desktop 15 kernel-source Not affected
      SUSE Linux Enterprise Desktop 15 SP1 kernel-source Not affected
      SUSE Linux Enterprise Desktop 15 SP2 kernel-source Not affected
      SUSE Linux Enterprise Desktop 15 SP3 kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP1 kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS kernel-default Not affected
      SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15-ESPOS kernel-source Not affected
      SUSE Linux Enterprise High Performance Computing 15-LTSS kernel-source Not affected
      SUSE Linux Enterprise Micro 5.0 kernel-default Not affected
      SUSE Linux Enterprise Module for Basesystem 15 kernel-source Not affected
      SUSE Linux Enterprise Module for Basesystem 15 SP1 kernel-source Not affected
      SUSE Linux Enterprise Module for Development Tools 15 kernel-source Not affected
      SUSE Linux Enterprise Module for Development Tools 15 SP1 kernel-source Not affected
      SUSE Linux Enterprise Module for Public Cloud 15 SP2 kernel-source-azure Not affected
      SUSE Linux Enterprise Module for Public Cloud 15 SP3 kernel-source-azure Not affected
      SUSE Linux Enterprise Point of Sale 12 SP2-CLIENT kernel-source Not affected
      SUSE Linux Enterprise Real Time 12 SP5 kernel-source-rt Not affected
      SUSE Linux Enterprise Real Time 15 SP2 kernel-source Not affected
      SUSE Linux Enterprise Real Time 15 SP3 kernel-source Not affected
      SUSE Linux Enterprise Real Time 15 SP3 kernel-source-rt Not affected
      SUSE Linux Enterprise Real Time 15 SP4 kernel-source Affected
      SUSE Linux Enterprise Real Time 15 SP4 kernel-source-rt Affected
      SUSE Linux Enterprise Server 11 SP4 kernel-source Not affected
      SUSE Linux Enterprise Server 11 SP4 LTSS kernel-default Not affected
      SUSE Linux Enterprise Server 11 SP4 LTSS kernel-source Not affected
      SUSE Linux Enterprise Server 11 SP4-LTSS kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP2 kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP2-BCL kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP2-ESPOS kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP2-LTSS kernel-default Not affected
      SUSE Linux Enterprise Server 12 SP2-LTSS kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP3 kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP3-BCL kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP3-ESPOS kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP3-LTSS kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP4 kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP4-ESPOS kernel-source Not affected
      SUSE Linux Enterprise Server 12 SP4-LTSS kernel-default Not affected
      SUSE Linux Enterprise Server 12 SP4-LTSS kernel-source Not affected
      SUSE Linux Enterprise Server 15 kernel-source Not affected
      SUSE Linux Enterprise Server 15 SP1 kernel-source Not affected
      SUSE Linux Enterprise Server 15 SP1-BCL kernel-source Not affected
      SUSE Linux Enterprise Server 15 SP1-LTSS kernel-default Not affected
      SUSE Linux Enterprise Server 15 SP1-LTSS kernel-source Not affected
      SUSE Linux Enterprise Server 15 SP2-BCL kernel-source Not affected
      SUSE Linux Enterprise Server 15 SP3-BCL kernel-source Not affected
      SUSE Linux Enterprise Server 15-LTSS kernel-default Not affected
      SUSE Linux Enterprise Server 15-LTSS kernel-source Not affected
      SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 kernel-source Not affected
      SUSE Linux Enterprise Server for SAP Applications 12 SP2 kernel-default Not affected
      SUSE Linux Enterprise Server for SAP Applications 12 SP2 kernel-source Not affected
      SUSE Linux Enterprise Server for SAP Applications 12 SP3 kernel-source Not affected
      SUSE Linux Enterprise Server for SAP Applications 12 SP4 kernel-default Not affected
      SUSE Linux Enterprise Server for SAP Applications 12 SP4 kernel-source Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 kernel-source Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 SP1 kernel-default Not affected
      SUSE Linux Enterprise Server for SAP Applications 15 SP1 kernel-source Not affected
      SUSE Manager Proxy 4.0 kernel-source Not affected
      SUSE Manager Proxy 4.1 kernel-source Not affected
      SUSE Manager Proxy 4.1 kernel-source-azure Not affected
      SUSE Manager Proxy 4.2 kernel-source Not affected
      SUSE Manager Proxy 4.2 kernel-source-azure Not affected
      SUSE Manager Retail Branch Server 4.0 kernel-source Not affected
      SUSE Manager Retail Branch Server 4.1 kernel-source Not affected
      SUSE Manager Retail Branch Server 4.1 kernel-source-azure Not affected
      SUSE Manager Retail Branch Server 4.2 kernel-source Not affected
      SUSE Manager Retail Branch Server 4.2 kernel-source-azure Not affected
      SUSE Manager Server 4.0 kernel-source Not affected
      SUSE Manager Server 4.1 kernel-source Not affected
      SUSE Manager Server 4.1 kernel-source-azure Not affected
      SUSE Manager Server 4.2 kernel-source Not affected
      SUSE Manager Server 4.2 kernel-source-azure Not affected
      SUSE OpenStack Cloud 7 kernel-source Not affected
      SUSE OpenStack Cloud 8 kernel-source Not affected
      SUSE OpenStack Cloud 9 kernel-default Not affected
      SUSE OpenStack Cloud 9 kernel-source Not affected
      SUSE OpenStack Cloud Crowbar 8 kernel-source Not affected
      SUSE OpenStack Cloud Crowbar 9 kernel-default Not affected
      SUSE OpenStack Cloud Crowbar 9 kernel-source Not affected
      SUSE Real Time Module 15 SP3 kernel-source-rt Not affected
      SUSE Real Time Module 15 SP4 kernel-source-rt Affected
      openSUSE Leap 15.3 kernel-source Not affected
      openSUSE Leap 15.3 kernel-source-azure Not affected
      openSUSE Leap 15.3 kernel-source-rt Not affected
      openSUSE Leap 15.4 kernel-default Released
      openSUSE Leap 15.4 kernel-source Released
      openSUSE Leap 15.4 kernel-source-azure Unsupported
      openSUSE Leap 15.4 kernel-source-rt Affected
      Products at an unknown state of their lifecycle.
      SLES15-SP5-CHOST-BYOS-GDC kernel-default Released
      Container Status
      suse/hpc/warewulf4-x86_64/sle-hpc-node
      suse/sle-micro/base-5.5
      kernel-defaultReleased


      SUSE Timeline for this CVE

      CVE page created: Thu Feb 22 19:00:20 2024
      CVE page last modified: Sat Dec 21 00:17:43 2024