Upstream information

CVE-2024-42270 at MITRE

Description

In the Linux kernel, the following vulnerability has been resolved:

netfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init().

We had a report that iptables-restore sometimes triggered null-ptr-deref
at boot time. [0]

The problem is that iptable_nat_table_init() is exposed to user space
before the kernel fully initialises netns.

In the small race window, a user could call iptable_nat_table_init()
that accesses net_generic(net, iptable_nat_net_id), which is available
only after registering iptable_nat_net_ops.

Let's call register_pernet_subsys() before xt_register_template().

[0]:
bpfilter: Loaded bpfilter_umh pid 11702
Started bpfilter
BUG: kernel NULL pointer dereference, address: 0000000000000013
PF: supervisor write access in kernel mode
PF: error_code(0x0002) - not-present page
PGD 0 P4D 0
PREEMPT SMP NOPTI
CPU: 2 PID: 11879 Comm: iptables-restor Not tainted 6.1.92-99.174.amzn2023.x86_64 #1
Hardware name: Amazon EC2 c6i.4xlarge/, BIOS 1.0 10/16/2017
RIP: 0010:iptable_nat_table_init (net/ipv4/netfilter/iptable_nat.c:87 net/ipv4/netfilter/iptable_nat.c:121) iptable_nat
Code: 10 4c 89 f6 48 89 ef e8 0b 19 bb ff 41 89 c4 85 c0 75 38 41 83 c7 01 49 83 c6 28 41 83 ff 04 75 dc 48 8b 44 24 08 48 8b 0c 24 <48> 89 08 4c 89 ef e8 a2 3b a2 cf 48 83 c4 10 44 89 e0 5b 5d 41 5c
RSP: 0018:ffffbef902843cd0 EFLAGS: 00010246
RAX: 0000000000000013 RBX: ffff9f4b052caa20 RCX: ffff9f4b20988d80
RDX: 0000000000000000 RSI: 0000000000000064 RDI: ffffffffc04201c0
RBP: ffff9f4b29394000 R08: ffff9f4b07f77258 R09: ffff9f4b07f77240
R10: 0000000000000000 R11: ffff9f4b09635388 R12: 0000000000000000
R13: ffff9f4b1a3c6c00 R14: ffff9f4b20988e20 R15: 0000000000000004
FS: 00007f6284340000(0000) GS:ffff9f51fe280000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000013 CR3: 00000001d10a6005 CR4: 00000000007706e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
PKRU: 55555554
Call Trace:
<TASK>
? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)
? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)
? xt_find_table_lock (net/netfilter/x_tables.c:1259)
? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420)
? page_fault_oops (arch/x86/mm/fault.c:727)
? exc_page_fault (./arch/x86/include/asm/irqflags.h:40 ./arch/x86/include/asm/irqflags.h:75 arch/x86/mm/fault.c:1470 arch/x86/mm/fault.c:1518)
? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:570)
? iptable_nat_table_init (net/ipv4/netfilter/iptable_nat.c:87 net/ipv4/netfilter/iptable_nat.c:121) iptable_nat
xt_find_table_lock (net/netfilter/x_tables.c:1259)
xt_request_find_table_lock (net/netfilter/x_tables.c:1287)
get_info (net/ipv4/netfilter/ip_tables.c:965)
? security_capable (security/security.c:809 (discriminator 13))
? ns_capable (kernel/capability.c:376 kernel/capability.c:397)
? do_ipt_get_ctl (net/ipv4/netfilter/ip_tables.c:1656)
? bpfilter_send_req (net/bpfilter/bpfilter_kern.c:52) bpfilter
nf_getsockopt (net/netfilter/nf_sockopt.c:116)
ip_getsockopt (net/ipv4/ip_sockglue.c:1827)
__sys_getsockopt (net/socket.c:2327)
__x64_sys_getsockopt (net/socket.c:2342 net/socket.c:2339 net/socket.c:2339)
do_syscall_64 (arch/x86/entry/common.c:51 arch/x86/entry/common.c:81)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
RIP: 0033:0x7f62844685ee
Code: 48 8b 0d 45 28 0f 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 49 89 ca b8 37 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 09
RSP: 002b:00007ffd1f83d638 EFLAGS: 00000246 ORIG_RAX: 0000000000000037
RAX: ffffffffffffffda RBX: 00007ffd1f83d680 RCX: 00007f62844685ee
RDX: 0000000000000040 RSI: 0000000000000000 RDI: 0000000000000004
RBP: 0000000000000004 R08: 00007ffd1f83d670 R09: 0000558798ffa2a0
R10: 00007ffd1f83d680 R11: 0000000000000246 R12: 00007ffd1f83e3b2
R13: 00007f6284
---truncated---

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v3 Scores
  National Vulnerability Database SUSE
Base Score 5.5 5.5
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local Local
Attack Complexity Low Low
Privileges Required Low Low
User Interaction None None
Scope Unchanged Unchanged
Confidentiality Impact None None
Integrity Impact None None
Availability Impact High High
CVSSv3 Version 3.1 3.1

Note from the SUSE Security Team on the kernel-default package

SUSE will no longer fix all CVEs in the Linux Kernel anymore, but declare some bug classes as won't fix. Please refer to TID 21496 for more details.

SUSE Bugzilla entry: 1229404 [IN_PROGRESS]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
Container bci/bci-sle15-kernel-module-devel:15.6.24.6
  • kernel-default-devel >= 6.4.0-150600.23.22.1
  • kernel-devel >= 6.4.0-150600.23.22.1
  • kernel-macros >= 6.4.0-150600.23.22.1
  • kernel-syms >= 6.4.0-150600.23.22.1
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:15.6.17.5.37
Image SLES15-SP6-CHOST-BYOS
Image SLES15-SP6-CHOST-BYOS-Aliyun
Image SLES15-SP6-CHOST-BYOS-Azure
Image SLES15-SP6-CHOST-BYOS-EC2
Image SLES15-SP6-CHOST-BYOS-GCE
Image SLES15-SP6-CHOST-BYOS-GDC
Image SLES15-SP6-CHOST-BYOS-SAP-CCloud
  • kernel-default >= 6.4.0-150600.23.22.1
Image SLES15-SP6-SAP-Azure-LI-BYOS
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production
Image SLES15-SP6-SAP-Azure-VLI-BYOS
Image SLES15-SP6-SAP-Azure-VLI-BYOS-Production
  • cluster-md-kmp-default >= 6.4.0-150600.23.22.1
  • dlm-kmp-default >= 6.4.0-150600.23.22.1
  • gfs2-kmp-default >= 6.4.0-150600.23.22.1
  • kernel-default >= 6.4.0-150600.23.22.1
  • ocfs2-kmp-default >= 6.4.0-150600.23.22.1
SUSE Linux Enterprise Desktop 15 SP6
  • kernel-64kb >= 6.4.0-150600.23.22.1
  • kernel-64kb-devel >= 6.4.0-150600.23.22.1
  • kernel-default >= 6.4.0-150600.23.22.1
  • kernel-default-base >= 6.4.0-150600.23.22.1.150600.12.8.3
  • kernel-default-devel >= 6.4.0-150600.23.22.1
  • kernel-default-extra >= 6.4.0-150600.23.22.1
  • kernel-devel >= 6.4.0-150600.23.22.1
  • kernel-docs >= 6.4.0-150600.23.22.1
  • kernel-macros >= 6.4.0-150600.23.22.1
  • kernel-obs-build >= 6.4.0-150600.23.22.1
  • kernel-source >= 6.4.0-150600.23.22.1
  • kernel-syms >= 6.4.0-150600.23.22.1
  • kernel-zfcpdump >= 6.4.0-150600.23.22.1
Patchnames:
SUSE-SLE-Module-Basesystem-15-SP6-2024-3383
SUSE-SLE-Module-Development-Tools-15-SP6-2024-3383
SUSE-SLE-Product-WE-15-SP6-2024-3383
SUSE Linux Enterprise High Availability Extension 15 SP6
  • cluster-md-kmp-default >= 6.4.0-150600.23.22.1
  • dlm-kmp-default >= 6.4.0-150600.23.22.1
  • gfs2-kmp-default >= 6.4.0-150600.23.22.1
  • ocfs2-kmp-default >= 6.4.0-150600.23.22.1
Patchnames:
SUSE-SLE-Product-HA-15-SP6-2024-3383
SUSE Linux Enterprise High Performance Computing 15 SP6
  • kernel-64kb >= 6.4.0-150600.23.22.1
  • kernel-64kb-devel >= 6.4.0-150600.23.22.1
  • kernel-azure >= 6.4.0-150600.8.11.1
  • kernel-azure-devel >= 6.4.0-150600.8.11.1
  • kernel-default >= 6.4.0-150600.23.22.1
  • kernel-default-base >= 6.4.0-150600.23.22.1.150600.12.8.3
  • kernel-default-devel >= 6.4.0-150600.23.22.1
  • kernel-devel >= 6.4.0-150600.23.22.1
  • kernel-devel-azure >= 6.4.0-150600.8.11.1
  • kernel-docs >= 6.4.0-150600.23.22.1
  • kernel-macros >= 6.4.0-150600.23.22.1
  • kernel-obs-build >= 6.4.0-150600.23.22.1
  • kernel-source >= 6.4.0-150600.23.22.1
  • kernel-source-azure >= 6.4.0-150600.8.11.1
  • kernel-syms >= 6.4.0-150600.23.22.1
  • kernel-syms-azure >= 6.4.0-150600.8.11.1
  • kernel-zfcpdump >= 6.4.0-150600.23.22.1
  • reiserfs-kmp-default >= 6.4.0-150600.23.22.1
Patchnames:
SUSE-SLE-Module-Basesystem-15-SP6-2024-3383
SUSE-SLE-Module-Development-Tools-15-SP6-2024-3383
SUSE-SLE-Module-Legacy-15-SP6-2024-3383
SUSE-SLE-Module-Public-Cloud-15-SP6-2024-3194
SUSE Linux Enterprise Live Patching 15 SP6
    Patchnames:
    SUSE-SLE-Module-Live-Patching-15-SP6-2024-3195
    SUSE-SLE-Module-Live-Patching-15-SP6-2024-3383
    SUSE Linux Enterprise Micro 6.0
    • kernel-default >= 6.4.0-19.1
    • kernel-default-base >= 6.4.0-17.1.1.51
    • kernel-default-extra >= 6.4.0-19.1
    • kernel-default-livepatch >= 6.4.0-19.1
    • kernel-devel >= 6.4.0-19.1
    • kernel-devel-rt >= 6.4.0-10.1
    • kernel-kvmsmall >= 6.4.0-19.1
    • kernel-livepatch-6_4_0-10-rt >= 1-1.1
    • kernel-livepatch-6_4_0-19-default >= 1-1.1
    • kernel-macros >= 6.4.0-19.1
    • kernel-rt >= 6.4.0-10.1
    • kernel-source >= 6.4.0-19.1
    • kernel-source-rt >= 6.4.0-10.1
    Patchnames:
    SUSE-SLE-Micro-6.0-61
    SUSE-SLE-Micro-6.0-63
    SUSE Linux Enterprise Module for Basesystem 15 SP6
    • kernel-64kb >= 6.4.0-150600.23.22.1
    • kernel-64kb-devel >= 6.4.0-150600.23.22.1
    • kernel-default >= 6.4.0-150600.23.22.1
    • kernel-default-base >= 6.4.0-150600.23.22.1.150600.12.8.3
    • kernel-default-devel >= 6.4.0-150600.23.22.1
    • kernel-devel >= 6.4.0-150600.23.22.1
    • kernel-macros >= 6.4.0-150600.23.22.1
    • kernel-zfcpdump >= 6.4.0-150600.23.22.1
    Patchnames:
    SUSE-SLE-Module-Basesystem-15-SP6-2024-3383
    SUSE Linux Enterprise Module for Development Tools 15 SP6
    • kernel-docs >= 6.4.0-150600.23.22.1
    • kernel-obs-build >= 6.4.0-150600.23.22.1
    • kernel-source >= 6.4.0-150600.23.22.1
    • kernel-syms >= 6.4.0-150600.23.22.1
    Patchnames:
    SUSE-SLE-Module-Development-Tools-15-SP6-2024-3383
    SUSE Linux Enterprise Module for Legacy 15 SP6
    • reiserfs-kmp-default >= 6.4.0-150600.23.22.1
    Patchnames:
    SUSE-SLE-Module-Legacy-15-SP6-2024-3383
    SUSE Linux Enterprise Module for Public Cloud 15 SP6
    • kernel-azure >= 6.4.0-150600.8.11.1
    • kernel-azure-devel >= 6.4.0-150600.8.11.1
    • kernel-devel-azure >= 6.4.0-150600.8.11.1
    • kernel-source-azure >= 6.4.0-150600.8.11.1
    • kernel-syms-azure >= 6.4.0-150600.8.11.1
    Patchnames:
    SUSE-SLE-Module-Public-Cloud-15-SP6-2024-3194
    SUSE Linux Enterprise Real Time 15 SP6
    SUSE Real Time Module 15 SP6
    • cluster-md-kmp-rt >= 6.4.0-150600.10.8.3
    • dlm-kmp-rt >= 6.4.0-150600.10.8.3
    • gfs2-kmp-rt >= 6.4.0-150600.10.8.3
    • kernel-devel-rt >= 6.4.0-150600.10.8.3
    • kernel-rt >= 6.4.0-150600.10.8.3
    • kernel-rt-devel >= 6.4.0-150600.10.8.3
    • kernel-rt_debug >= 6.4.0-150600.10.8.3
    • kernel-rt_debug-devel >= 6.4.0-150600.10.8.3
    • kernel-source-rt >= 6.4.0-150600.10.8.3
    • kernel-syms-rt >= 6.4.0-150600.10.8.1
    • ocfs2-kmp-rt >= 6.4.0-150600.10.8.3
    Patchnames:
    SUSE-SLE-Module-RT-15-SP6-2024-3195
    SUSE Linux Enterprise Server 15 SP6
    SUSE Linux Enterprise Server for SAP Applications 15 SP6
    • kernel-64kb >= 6.4.0-150600.23.22.1
    • kernel-64kb-devel >= 6.4.0-150600.23.22.1
    • kernel-azure >= 6.4.0-150600.8.11.1
    • kernel-azure-devel >= 6.4.0-150600.8.11.1
    • kernel-default >= 6.4.0-150600.23.22.1
    • kernel-default-base >= 6.4.0-150600.23.22.1.150600.12.8.3
    • kernel-default-devel >= 6.4.0-150600.23.22.1
    • kernel-default-extra >= 6.4.0-150600.23.22.1
    • kernel-devel >= 6.4.0-150600.23.22.1
    • kernel-devel-azure >= 6.4.0-150600.8.11.1
    • kernel-docs >= 6.4.0-150600.23.22.1
    • kernel-macros >= 6.4.0-150600.23.22.1
    • kernel-obs-build >= 6.4.0-150600.23.22.1
    • kernel-source >= 6.4.0-150600.23.22.1
    • kernel-source-azure >= 6.4.0-150600.8.11.1
    • kernel-syms >= 6.4.0-150600.23.22.1
    • kernel-syms-azure >= 6.4.0-150600.8.11.1
    • kernel-zfcpdump >= 6.4.0-150600.23.22.1
    • reiserfs-kmp-default >= 6.4.0-150600.23.22.1
    Patchnames:
    SUSE-SLE-Module-Basesystem-15-SP6-2024-3383
    SUSE-SLE-Module-Development-Tools-15-SP6-2024-3383
    SUSE-SLE-Module-Legacy-15-SP6-2024-3383
    SUSE-SLE-Module-Public-Cloud-15-SP6-2024-3194
    SUSE-SLE-Product-WE-15-SP6-2024-3383
    SUSE Linux Enterprise Workstation Extension 15 SP6
    • kernel-default-extra >= 6.4.0-150600.23.22.1
    Patchnames:
    SUSE-SLE-Product-WE-15-SP6-2024-3383
    openSUSE Leap 15.6
    • cluster-md-kmp-64kb >= 6.4.0-150600.23.22.1
    • cluster-md-kmp-azure >= 6.4.0-150600.8.11.1
    • cluster-md-kmp-default >= 6.4.0-150600.23.22.1
    • cluster-md-kmp-rt >= 6.4.0-150600.10.8.3
    • dlm-kmp-64kb >= 6.4.0-150600.23.22.1
    • dlm-kmp-azure >= 6.4.0-150600.8.11.1
    • dlm-kmp-default >= 6.4.0-150600.23.22.1
    • dlm-kmp-rt >= 6.4.0-150600.10.8.3
    • dtb-allwinner >= 6.4.0-150600.23.22.1
    • dtb-altera >= 6.4.0-150600.23.22.1
    • dtb-amazon >= 6.4.0-150600.23.22.1
    • dtb-amd >= 6.4.0-150600.23.22.1
    • dtb-amlogic >= 6.4.0-150600.23.22.1
    • dtb-apm >= 6.4.0-150600.23.22.1
    • dtb-apple >= 6.4.0-150600.23.22.1
    • dtb-arm >= 6.4.0-150600.23.22.1
    • dtb-broadcom >= 6.4.0-150600.23.22.1
    • dtb-cavium >= 6.4.0-150600.23.22.1
    • dtb-exynos >= 6.4.0-150600.23.22.1
    • dtb-freescale >= 6.4.0-150600.23.22.1
    • dtb-hisilicon >= 6.4.0-150600.23.22.1
    • dtb-lg >= 6.4.0-150600.23.22.1
    • dtb-marvell >= 6.4.0-150600.23.22.1
    • dtb-mediatek >= 6.4.0-150600.23.22.1
    • dtb-nvidia >= 6.4.0-150600.23.22.1
    • dtb-qcom >= 6.4.0-150600.23.22.1
    • dtb-renesas >= 6.4.0-150600.23.22.1
    • dtb-rockchip >= 6.4.0-150600.23.22.1
    • dtb-socionext >= 6.4.0-150600.23.22.1
    • dtb-sprd >= 6.4.0-150600.23.22.1
    • dtb-xilinx >= 6.4.0-150600.23.22.1
    • gfs2-kmp-64kb >= 6.4.0-150600.23.22.1
    • gfs2-kmp-azure >= 6.4.0-150600.8.11.1
    • gfs2-kmp-default >= 6.4.0-150600.23.22.1
    • gfs2-kmp-rt >= 6.4.0-150600.10.8.3
    • kernel-64kb >= 6.4.0-150600.23.22.1
    • kernel-64kb-devel >= 6.4.0-150600.23.22.1
    • kernel-64kb-extra >= 6.4.0-150600.23.22.1
    • kernel-64kb-livepatch-devel >= 6.4.0-150600.23.22.1
    • kernel-64kb-optional >= 6.4.0-150600.23.22.1
    • kernel-azure >= 6.4.0-150600.8.11.1
    • kernel-azure-devel >= 6.4.0-150600.8.11.1
    • kernel-azure-extra >= 6.4.0-150600.8.11.1
    • kernel-azure-livepatch-devel >= 6.4.0-150600.8.11.1
    • kernel-azure-optional >= 6.4.0-150600.8.11.1
    • kernel-azure-vdso >= 6.4.0-150600.8.11.1
    • kernel-debug >= 6.4.0-150600.23.22.1
    • kernel-debug-devel >= 6.4.0-150600.23.22.1
    • kernel-debug-livepatch-devel >= 6.4.0-150600.23.22.1
    • kernel-debug-vdso >= 6.4.0-150600.23.22.1
    • kernel-default >= 6.4.0-150600.23.22.1
    • kernel-default-base >= 6.4.0-150600.23.22.1.150600.12.8.3
    • kernel-default-base-rebuild >= 6.4.0-150600.23.22.1.150600.12.8.3
    • kernel-default-devel >= 6.4.0-150600.23.22.1
    • kernel-default-extra >= 6.4.0-150600.23.22.1
    • kernel-default-livepatch >= 6.4.0-150600.23.22.1
    • kernel-default-livepatch-devel >= 6.4.0-150600.23.22.1
    • kernel-default-optional >= 6.4.0-150600.23.22.1
    • kernel-default-vdso >= 6.4.0-150600.23.22.1
    • kernel-devel >= 6.4.0-150600.23.22.1
    • kernel-devel-azure >= 6.4.0-150600.8.11.1
    • kernel-devel-rt >= 6.4.0-150600.10.8.3
    • kernel-docs >= 6.4.0-150600.23.22.1
    • kernel-docs-html >= 6.4.0-150600.23.22.1
    • kernel-kvmsmall >= 6.4.0-150600.23.22.1
    • kernel-kvmsmall-devel >= 6.4.0-150600.23.22.1
    • kernel-kvmsmall-livepatch-devel >= 6.4.0-150600.23.22.1
    • kernel-kvmsmall-vdso >= 6.4.0-150600.23.22.1
    • kernel-macros >= 6.4.0-150600.23.22.1
    • kernel-obs-build >= 6.4.0-150600.23.22.1
    • kernel-obs-qa >= 6.4.0-150600.23.22.1
    • kernel-rt >= 6.4.0-150600.10.8.3
    • kernel-rt-devel >= 6.4.0-150600.10.8.3
    • kernel-rt-extra >= 6.4.0-150600.10.8.3
    • kernel-rt-livepatch-devel >= 6.4.0-150600.10.8.3
    • kernel-rt-optional >= 6.4.0-150600.10.8.3
    • kernel-rt-vdso >= 6.4.0-150600.10.8.3
    • kernel-rt_debug >= 6.4.0-150600.10.8.3
    • kernel-rt_debug-devel >= 6.4.0-150600.10.8.3
    • kernel-rt_debug-livepatch-devel >= 6.4.0-150600.10.8.3
    • kernel-rt_debug-vdso >= 6.4.0-150600.10.8.3
    • kernel-source >= 6.4.0-150600.23.22.1
    • kernel-source-azure >= 6.4.0-150600.8.11.1
    • kernel-source-rt >= 6.4.0-150600.10.8.3
    • kernel-source-vanilla >= 6.4.0-150600.23.22.1
    • kernel-syms >= 6.4.0-150600.23.22.1
    • kernel-syms-azure >= 6.4.0-150600.8.11.1
    • kernel-syms-rt >= 6.4.0-150600.10.8.1
    • kernel-zfcpdump >= 6.4.0-150600.23.22.1
    • kselftests-kmp-64kb >= 6.4.0-150600.23.22.1
    • kselftests-kmp-azure >= 6.4.0-150600.8.11.1
    • kselftests-kmp-default >= 6.4.0-150600.23.22.1
    • kselftests-kmp-rt >= 6.4.0-150600.10.8.3
    • ocfs2-kmp-64kb >= 6.4.0-150600.23.22.1
    • ocfs2-kmp-azure >= 6.4.0-150600.8.11.1
    • ocfs2-kmp-default >= 6.4.0-150600.23.22.1
    • ocfs2-kmp-rt >= 6.4.0-150600.10.8.3
    • reiserfs-kmp-64kb >= 6.4.0-150600.23.22.1
    • reiserfs-kmp-azure >= 6.4.0-150600.8.11.1
    • reiserfs-kmp-default >= 6.4.0-150600.23.22.1
    • reiserfs-kmp-rt >= 6.4.0-150600.10.8.3
    Patchnames:
    openSUSE-SLE-15.6-2024-3194
    openSUSE-SLE-15.6-2024-3195
    openSUSE-SLE-15.6-2024-3383


    First public cloud image revisions this CVE is fixed in:


    Status of this issue by product and package

    Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification. The updates are grouped by state of their lifecycle. SUSE product lifecycles are documented on the lifecycle page.

    Product(s) Source package State
    Products under general support and receiving all security fixes.
    SUSE Linux Enterprise Desktop 15 SP5 kernel-default Not affected
    SUSE Linux Enterprise Desktop 15 SP5 kernel-source Not affected
    SUSE Linux Enterprise Desktop 15 SP6 kernel-64kb Released
    SUSE Linux Enterprise Desktop 15 SP6 kernel-default Released
    SUSE Linux Enterprise Desktop 15 SP6 kernel-default-base Released
    SUSE Linux Enterprise Desktop 15 SP6 kernel-docs Released
    SUSE Linux Enterprise Desktop 15 SP6 kernel-obs-build Released
    SUSE Linux Enterprise Desktop 15 SP6 kernel-source Released
    SUSE Linux Enterprise Desktop 15 SP6 kernel-syms Released
    SUSE Linux Enterprise Desktop 15 SP6 kernel-zfcpdump Released
    SUSE Linux Enterprise High Availability Extension 15 SP6 kernel-default Released
    SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-default Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP5 kernel-source-azure Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-64kb Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-azure Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-default Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-default-base Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-docs Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-obs-build Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-source Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-source-azure Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-syms Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-syms-azure Released
    SUSE Linux Enterprise High Performance Computing 15 SP6 kernel-zfcpdump Released
    SUSE Linux Enterprise Live Patching 15 SP5 kernel-default Not affected
    SUSE Linux Enterprise Live Patching 15 SP5 kernel-source Not affected
    SUSE Linux Enterprise Live Patching 15 SP6 kernel-default Released
    SUSE Linux Enterprise Live Patching 15 SP6 kernel-livepatch-SLE15-SP6-RT_Update_2 Released
    SUSE Linux Enterprise Live Patching 15 SP6 kernel-livepatch-SLE15-SP6_Update_4 Released
    SUSE Linux Enterprise Live Patching 15 SP6 kernel-source Released
    SUSE Linux Enterprise Micro 5.1 kernel-default Not affected
    SUSE Linux Enterprise Micro 5.1 kernel-rt Not affected
    SUSE Linux Enterprise Micro 5.1 kernel-source Not affected
    SUSE Linux Enterprise Micro 5.1 kernel-source-rt Not affected
    SUSE Linux Enterprise Micro 5.2 kernel-default Not affected
    SUSE Linux Enterprise Micro 5.2 kernel-rt Not affected
    SUSE Linux Enterprise Micro 5.2 kernel-source Not affected
    SUSE Linux Enterprise Micro 5.2 kernel-source-rt Not affected
    SUSE Linux Enterprise Micro 5.3 kernel-default Not affected
    SUSE Linux Enterprise Micro 5.3 kernel-rt Not affected
    SUSE Linux Enterprise Micro 5.3 kernel-source Not affected
    SUSE Linux Enterprise Micro 5.3 kernel-source-rt Not affected
    SUSE Linux Enterprise Micro 5.4 kernel-default Not affected
    SUSE Linux Enterprise Micro 5.4 kernel-rt Not affected
    SUSE Linux Enterprise Micro 5.4 kernel-source Not affected
    SUSE Linux Enterprise Micro 5.4 kernel-source-rt Not affected
    SUSE Linux Enterprise Micro 5.5 kernel-default Not affected
    SUSE Linux Enterprise Micro 5.5 kernel-source Not affected
    SUSE Linux Enterprise Micro 5.5 kernel-source-rt Not affected
    SUSE Linux Enterprise Micro 6.0 kernel-default Released
    SUSE Linux Enterprise Micro 6.0 kernel-default-base Released
    SUSE Linux Enterprise Micro 6.0 kernel-kvmsmall Released
    SUSE Linux Enterprise Micro 6.0 kernel-livepatch-MICRO-6-0-RT_Update_2 Released
    SUSE Linux Enterprise Micro 6.0 kernel-livepatch-MICRO-6-0_Update_2 Released
    SUSE Linux Enterprise Micro 6.0 kernel-rt Released
    SUSE Linux Enterprise Micro 6.0 kernel-source Released
    SUSE Linux Enterprise Micro 6.0 kernel-source-rt Released
    SUSE Linux Enterprise Module for Basesystem 15 SP5 kernel-default Not affected
    SUSE Linux Enterprise Module for Basesystem 15 SP5 kernel-source Not affected
    SUSE Linux Enterprise Module for Basesystem 15 SP6 kernel-64kb Released
    SUSE Linux Enterprise Module for Basesystem 15 SP6 kernel-default Released
    SUSE Linux Enterprise Module for Basesystem 15 SP6 kernel-default-base Released
    SUSE Linux Enterprise Module for Basesystem 15 SP6 kernel-source Released
    SUSE Linux Enterprise Module for Basesystem 15 SP6 kernel-zfcpdump Released
    SUSE Linux Enterprise Module for Development Tools 15 SP5 kernel-default Not affected
    SUSE Linux Enterprise Module for Development Tools 15 SP5 kernel-source Not affected
    SUSE Linux Enterprise Module for Development Tools 15 SP6 kernel-default Released
    SUSE Linux Enterprise Module for Development Tools 15 SP6 kernel-docs Released
    SUSE Linux Enterprise Module for Development Tools 15 SP6 kernel-obs-build Released
    SUSE Linux Enterprise Module for Development Tools 15 SP6 kernel-source Released
    SUSE Linux Enterprise Module for Development Tools 15 SP6 kernel-syms Released
    SUSE Linux Enterprise Module for Legacy 15 SP6 kernel-default Released
    SUSE Linux Enterprise Module for Public Cloud 15 SP5 kernel-source-azure Not affected
    SUSE Linux Enterprise Module for Public Cloud 15 SP6 kernel-azure Released
    SUSE Linux Enterprise Module for Public Cloud 15 SP6 kernel-source-azure Released
    SUSE Linux Enterprise Module for Public Cloud 15 SP6 kernel-syms-azure Released
    SUSE Linux Enterprise Real Time 15 SP5 kernel-source-rt Not affected
    SUSE Linux Enterprise Real Time 15 SP6 kernel-rt Released
    SUSE Linux Enterprise Real Time 15 SP6 kernel-rt_debug Released
    SUSE Linux Enterprise Real Time 15 SP6 kernel-source-rt Released
    SUSE Linux Enterprise Real Time 15 SP6 kernel-syms-rt Released
    SUSE Linux Enterprise Server 15 SP5 kernel-default Not affected
    SUSE Linux Enterprise Server 15 SP5 kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP5 kernel-source-azure Not affected
    SUSE Linux Enterprise Server 15 SP6 kernel-64kb Released
    SUSE Linux Enterprise Server 15 SP6 kernel-azure Released
    SUSE Linux Enterprise Server 15 SP6 kernel-default Released
    SUSE Linux Enterprise Server 15 SP6 kernel-default-base Released
    SUSE Linux Enterprise Server 15 SP6 kernel-docs Released
    SUSE Linux Enterprise Server 15 SP6 kernel-obs-build Released
    SUSE Linux Enterprise Server 15 SP6 kernel-source Released
    SUSE Linux Enterprise Server 15 SP6 kernel-source-azure Released
    SUSE Linux Enterprise Server 15 SP6 kernel-syms Released
    SUSE Linux Enterprise Server 15 SP6 kernel-syms-azure Released
    SUSE Linux Enterprise Server 15 SP6 kernel-zfcpdump Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-default Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-source Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP5 kernel-source-azure Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-64kb Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-azure Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-default Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-default-base Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-docs Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-obs-build Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-source Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-source-azure Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-syms Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-syms-azure Released
    SUSE Linux Enterprise Server for SAP Applications 15 SP6 kernel-zfcpdump Released
    SUSE Linux Enterprise Workstation Extension 15 SP6 kernel-default Released
    SUSE Manager Proxy 4.3 kernel-default Not affected
    SUSE Manager Proxy 4.3 kernel-source Not affected
    SUSE Manager Retail Branch Server 4.3 kernel-default Not affected
    SUSE Manager Retail Branch Server 4.3 kernel-source Not affected
    SUSE Manager Server 4.3 kernel-default Not affected
    SUSE Manager Server 4.3 kernel-source Not affected
    SUSE Real Time Module 15 SP5 kernel-source-rt Not affected
    SUSE Real Time Module 15 SP6 kernel-rt Released
    SUSE Real Time Module 15 SP6 kernel-rt_debug Released
    SUSE Real Time Module 15 SP6 kernel-source-rt Released
    SUSE Real Time Module 15 SP6 kernel-syms-rt Released
    openSUSE Leap 15.5 kernel-default Not affected
    openSUSE Leap 15.5 kernel-source Not affected
    openSUSE Leap 15.5 kernel-source-azure Not affected
    openSUSE Leap 15.5 kernel-source-rt Not affected
    openSUSE Leap 15.6 kernel-default Released
    openSUSE Leap 15.6 kernel-source Released
    openSUSE Leap 15.6 kernel-source-azure Released
    openSUSE Leap 15.6 kernel-source-rt Released
    Products under Long Term Service Pack support and receiving important and critical security fixes.
    SUSE Linux Enterprise Desktop 15 SP4 kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 12 SP5 kernel-default Not affected
    SUSE Linux Enterprise High Performance Computing 12 SP5 kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 12 SP5 kernel-source-azure Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP2 kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS kernel-default Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP3 kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-default Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP4 kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS kernel-default Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS kernel-default Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS kernel-source Not affected
    SUSE Linux Enterprise Live Patching 12 SP5 kernel-default Not affected
    SUSE Linux Enterprise Live Patching 12 SP5 kernel-source Not affected
    SUSE Linux Enterprise Live Patching 15 SP2 kernel-default Not affected
    SUSE Linux Enterprise Live Patching 15 SP2 kernel-source Not affected
    SUSE Linux Enterprise Live Patching 15 SP3 kernel-default Not affected
    SUSE Linux Enterprise Live Patching 15 SP3 kernel-source Not affected
    SUSE Linux Enterprise Live Patching 15 SP4 kernel-default Not affected
    SUSE Linux Enterprise Live Patching 15 SP4 kernel-source Not affected
    SUSE Linux Enterprise Module for Basesystem 15 SP2 kernel-source Not affected
    SUSE Linux Enterprise Module for Basesystem 15 SP3 kernel-source Not affected
    SUSE Linux Enterprise Module for Basesystem 15 SP4 kernel-source Not affected
    SUSE Linux Enterprise Module for Development Tools 15 SP2 kernel-source Not affected
    SUSE Linux Enterprise Module for Development Tools 15 SP3 kernel-source Not affected
    SUSE Linux Enterprise Module for Development Tools 15 SP4 kernel-source Not affected
    SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-default Not affected
    SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP5 kernel-default Not affected
    SUSE Linux Enterprise Server 12 SP5 kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP5 kernel-source-azure Not affected
    SUSE Linux Enterprise Server 12 SP5-LTSS kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP5-LTSS kernel-source-azure Not affected
    SUSE Linux Enterprise Server 15 SP2 kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP2-LTSS kernel-default Not affected
    SUSE Linux Enterprise Server 15 SP2-LTSS kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP3 kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP3-LTSS kernel-default Not affected
    SUSE Linux Enterprise Server 15 SP3-LTSS kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP4 kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP4-LTSS kernel-default Not affected
    SUSE Linux Enterprise Server 15 SP4-LTSS kernel-source Not affected
    SUSE Linux Enterprise Server for SAP Applications 12 SP5 kernel-default Not affected
    SUSE Linux Enterprise Server for SAP Applications 12 SP5 kernel-source Not affected
    SUSE Linux Enterprise Server for SAP Applications 12 SP5 kernel-source-azure Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP2 kernel-default Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP2 kernel-source Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP3 kernel-default Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP3 kernel-source Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP4 kernel-default Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP4 kernel-source Not affected
    Products past their end of life and not receiving proactive updates anymore.
    HPE Helion OpenStack 8 kernel-source Not affected
    SUSE CaaS Platform 4.0 kernel-source Not affected
    SUSE CaaS Platform Toolchain 3 kernel-source Not affected
    SUSE Enterprise Storage 6 kernel-source Not affected
    SUSE Enterprise Storage 7 kernel-source Not affected
    SUSE Enterprise Storage 7.1 kernel-source Not affected
    SUSE Linux Enterprise Desktop 11 SP4 kernel-source Not affected
    SUSE Linux Enterprise Desktop 12 SP3 kernel-source Not affected
    SUSE Linux Enterprise Desktop 12 SP4 kernel-source Not affected
    SUSE Linux Enterprise Desktop 15 kernel-source Not affected
    SUSE Linux Enterprise Desktop 15 SP1 kernel-source Not affected
    SUSE Linux Enterprise Desktop 15 SP2 kernel-source Not affected
    SUSE Linux Enterprise Desktop 15 SP3 kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP1 kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15-ESPOS kernel-source Not affected
    SUSE Linux Enterprise High Performance Computing 15-LTSS kernel-source Not affected
    SUSE Linux Enterprise Micro 5.0 kernel-default Not affected
    SUSE Linux Enterprise Micro 5.0 kernel-rt Unsupported
    SUSE Linux Enterprise Module for Basesystem 15 kernel-source Not affected
    SUSE Linux Enterprise Module for Basesystem 15 SP1 kernel-source Not affected
    SUSE Linux Enterprise Module for Development Tools 15 kernel-source Not affected
    SUSE Linux Enterprise Module for Development Tools 15 SP1 kernel-source Not affected
    SUSE Linux Enterprise Real Time 12 SP5 kernel-source-rt Not affected
    SUSE Linux Enterprise Real Time 15 SP1 kernel-source-rt Unsupported
    SUSE Linux Enterprise Real Time 15 SP2 kernel-source Not affected
    SUSE Linux Enterprise Real Time 15 SP3 kernel-source Not affected
    SUSE Linux Enterprise Real Time 15 SP3 kernel-source-rt Not affected
    SUSE Linux Enterprise Real Time 15 SP4 kernel-source Not affected
    SUSE Linux Enterprise Real Time 15 SP4 kernel-source-rt Not affected
    SUSE Linux Enterprise Server 11 SP4 kernel-source Not affected
    SUSE Linux Enterprise Server 11 SP4 LTSS kernel-default Not affected
    SUSE Linux Enterprise Server 11 SP4 LTSS kernel-source Not affected
    SUSE Linux Enterprise Server 11 SP4-LTSS kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP3 kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP3-BCL kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP3-ESPOS kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP3-LTSS kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP4 kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP4-ESPOS kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP4-LTSS kernel-default Not affected
    SUSE Linux Enterprise Server 12 SP4-LTSS kernel-source Not affected
    SUSE Linux Enterprise Server 15 kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP1 kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP1-BCL kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP1-LTSS kernel-default Not affected
    SUSE Linux Enterprise Server 15 SP1-LTSS kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP2-BCL kernel-source Not affected
    SUSE Linux Enterprise Server 15 SP3-BCL kernel-source Not affected
    SUSE Linux Enterprise Server 15-LTSS kernel-default Not affected
    SUSE Linux Enterprise Server 15-LTSS kernel-source Not affected
    SUSE Linux Enterprise Server for SAP Applications 12 SP3 kernel-source Not affected
    SUSE Linux Enterprise Server for SAP Applications 12 SP4 kernel-source Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 kernel-source Not affected
    SUSE Linux Enterprise Server for SAP Applications 15 SP1 kernel-source Not affected
    SUSE Linux Enterprise Software Development Kit 12 SP5 kernel-default Not affected
    SUSE Linux Enterprise Software Development Kit 12 SP5 kernel-source Not affected
    SUSE Manager Proxy 4.0 kernel-source Not affected
    SUSE Manager Proxy 4.1 kernel-source Not affected
    SUSE Manager Proxy 4.2 kernel-source Not affected
    SUSE Manager Retail Branch Server 4.0 kernel-source Not affected
    SUSE Manager Retail Branch Server 4.1 kernel-source Not affected
    SUSE Manager Retail Branch Server 4.2 kernel-source Not affected
    SUSE Manager Server 4.0 kernel-source Not affected
    SUSE Manager Server 4.1 kernel-source Not affected
    SUSE Manager Server 4.2 kernel-source Not affected
    SUSE OpenStack Cloud 8 kernel-source Not affected
    SUSE OpenStack Cloud 9 kernel-source Not affected
    SUSE OpenStack Cloud Crowbar 8 kernel-source Not affected
    SUSE OpenStack Cloud Crowbar 9 kernel-source Not affected
    SUSE Real Time Module 15 SP1 kernel-source-rt Unsupported
    SUSE Real Time Module 15 SP3 kernel-source-rt Not affected
    SUSE Real Time Module 15 SP4 kernel-source-rt Not affected
    openSUSE Leap 15.3 kernel-source Not affected
    openSUSE Leap 15.3 kernel-source-rt Not affected
    openSUSE Leap 15.4 kernel-source Not affected
    openSUSE Leap 15.4 kernel-source-azure Unsupported
    openSUSE Leap 15.4 kernel-source-rt Not affected
    Products at an unknown state of their lifecycle.
    SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security kernel-source Not affected
    SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security kernel-source-azure Not affected


    SUSE Timeline for this CVE

    CVE page created: Sat Aug 17 12:00:19 2024
    CVE page last modified: Tue Nov 12 15:14:31 2024