Security update for the Linux Kernel
Announcement ID: | SUSE-SU-2024:4103-1 |
---|---|
Release Date: | 2024-11-28T14:16:29Z |
Rating: | important |
References: |
|
Cross-References: |
|
CVSS scores: |
|
Affected Products: |
|
An update that solves 46 vulnerabilities and has 10 security fixes can now be installed.
Description:
The SUSE Linux Enterprise 15 SP2 LTSS kernel was updated to receive various security bugfixes.
The following security bugs were fixed:
- CVE-2021-47589: igbvf: fix double free in
igbvf_probe
(bsc#1226557). - CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1231893).
- CVE-2022-48960: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() (bsc#1231979).
- CVE-2022-48962: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() (bsc#1232286).
- CVE-2022-48967: NFC: nci: Bounds check struct nfc_target arrays (bsc#1232304).
- CVE-2022-48988: memcg: Fix possible use-after-free in memcg_write_event_control() (bsc#1206344 bsc#1232069).
- CVE-2022-48991: khugepaged: retract_page_tables() remember to test exit (bsc#1232070).
- CVE-2022-49003: nvme: fix SRCU protection of nvme_ns_head list (bsc#1232136).
- CVE-2022-49014: net: tun: Fix use-after-free in tun_detach() (bsc#1231890).
- CVE-2022-49015: net: hsr: Fix potential use-after-free (bsc#1231938).
- CVE-2022-49023: wifi: cfg80211: fix buffer overflow in elem comparison (bsc#1231961).
- CVE-2022-49025: net/mlx5e: Fix use-after-free when reverting termination table (bsc#1231960).
- CVE-2024-45016: netem: fix return value if duplicate enqueue fails (bsc#1230429).
- CVE-2024-46813: drm/amd/display: Check link_index before accessing dc->links (bsc#1231191).
- CVE-2024-46816: drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links (bsc#1231197).
- CVE-2024-46817: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6 (bsc#1231200).
- CVE-2024-46818: drm/amd/display: Check gpio_id before used as array index (bsc#1231203).
- CVE-2024-46849: ASoC: meson: axg-card: fix 'use-after-free' (bsc#1231073).
- CVE-2024-47668: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() (bsc#1231502).
- CVE-2024-47674: mm: avoid leaving partial pfn mappings around in error case (bsc#1231673).
- CVE-2024-47684: tcp: check skb is non-NULL in tcp_rto_delta_us() (bsc#1231987).
- CVE-2024-47706: block, bfq: fix possible UAF for bfqq->bic with merge chain (bsc#1231942).
- CVE-2024-47747: net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition (bsc#1232145).
- CVE-2024-49860: ACPI: sysfs: validate return type of _STR method (bsc#1231861).
- CVE-2024-49936: net/xen-netback: prevent UAF in xenvif_flush_hash() (bsc#1232424).
- CVE-2024-49974: NFSD: Force all NFSv4.2 COPY requests to be synchronous (bsc#1232383).
- CVE-2024-49991: drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer (bsc#1232282).
- CVE-2024-49995: tipc: guard against string buffer overrun (bsc#1232432).
- CVE-2024-50047: smb: client: fix UAF in async decryption (bsc#1232418).
The following non-security bugs were fixed:
- initrd: Revert "build initrd without systemd" (bsc#1195775).
- bpf: Fix pointer-leak due to insufficient speculative store bypass mitigation (bsc#1231375).
- kernel-binary.spec.in: Enable klp_symbols on openSUSE Tumbleweed (boo#1229042).
- kernel-binary: generate and install compile_commands.json (bsc#1228971).
- net: mana: Fix the extra HZ in mana_hwc_send_request (bsc#1232033).
- rpm/check-for-config-changes: Exclude ARCH_USING_PATCHABLE_FUNCTION_ENTRY gcc version dependent, at least on ppc
- rpm/check-for-config-changes: add HAVE_RUST and RUSTC_SUPPORTS_ to IGNORED_CONFIGS_RE They depend on SHADOW_CALL_STACK.
- rpm/kernel-binary.spec.in: Fix build regression The previous fix forgot to take over grep -c option that broke the conditional expression.
- rpm/kernel-binary.spec.in: fix klp_symbols macro The commit below removed openSUSE filter from %ifs of the klp_symbols definition (boo#1229042).
- rpm/kernel-obs-build.spec.in: Some builds do not just create an iso9660 image, but also mount it during build (bsc#1226212).
- rpm/kernel-obs-build.spec.in: Add networking modules for docker (bsc#1226211).
- rpm/release-projects: Add SLFO projects (bsc#1231293).
Special Instructions and Notes:
- Please reboot the system after installing this update.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Live Patching 15-SP2
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP2-2024-4103=1
-
SUSE Linux Enterprise High Availability Extension 15 SP2
zypper in -t patch SUSE-SLE-Product-HA-15-SP2-2024-4103=1
-
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-4103=1
-
SUSE Linux Enterprise Server 15 SP2 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-4103=1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP2
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-4103=1
Package List:
-
SUSE Linux Enterprise Live Patching 15-SP2 (nosrc)
- kernel-default-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Live Patching 15-SP2 (ppc64le s390x x86_64)
- kernel-default-livepatch-devel-5.3.18-150200.24.209.1
- kernel-livepatch-5_3_18-150200_24_209-default-1-150200.5.3.1
- kernel-default-livepatch-5.3.18-150200.24.209.1
- kernel-livepatch-5_3_18-150200_24_209-default-debuginfo-1-150200.5.3.1
- kernel-livepatch-SLE15-SP2_Update_54-debugsource-1-150200.5.3.1
- kernel-default-debuginfo-5.3.18-150200.24.209.1
- kernel-default-debugsource-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise High Availability Extension 15 SP2 (aarch64 ppc64le s390x x86_64)
- cluster-md-kmp-default-5.3.18-150200.24.209.1
- cluster-md-kmp-default-debuginfo-5.3.18-150200.24.209.1
- ocfs2-kmp-default-5.3.18-150200.24.209.1
- ocfs2-kmp-default-debuginfo-5.3.18-150200.24.209.1
- gfs2-kmp-default-5.3.18-150200.24.209.1
- kernel-default-debugsource-5.3.18-150200.24.209.1
- dlm-kmp-default-debuginfo-5.3.18-150200.24.209.1
- gfs2-kmp-default-debuginfo-5.3.18-150200.24.209.1
- kernel-default-debuginfo-5.3.18-150200.24.209.1
- dlm-kmp-default-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise High Availability Extension 15 SP2 (nosrc)
- kernel-default-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS (aarch64 nosrc x86_64)
- kernel-default-5.3.18-150200.24.209.1
- kernel-preempt-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS (aarch64 x86_64)
- kernel-default-base-5.3.18-150200.24.209.1.150200.9.109.1
- kernel-obs-build-debugsource-5.3.18-150200.24.209.1
- kernel-preempt-debugsource-5.3.18-150200.24.209.1
- kernel-preempt-devel-5.3.18-150200.24.209.1
- kernel-preempt-debuginfo-5.3.18-150200.24.209.1
- kernel-syms-5.3.18-150200.24.209.1
- kernel-preempt-devel-debuginfo-5.3.18-150200.24.209.1
- kernel-default-devel-debuginfo-5.3.18-150200.24.209.1
- kernel-default-devel-5.3.18-150200.24.209.1
- kernel-default-debuginfo-5.3.18-150200.24.209.1
- kernel-obs-build-5.3.18-150200.24.209.1
- kernel-default-debugsource-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS (noarch)
- kernel-source-5.3.18-150200.24.209.1
- kernel-devel-5.3.18-150200.24.209.1
- kernel-macros-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS (noarch nosrc)
- kernel-docs-5.3.18-150200.24.209.2
-
SUSE Linux Enterprise Server 15 SP2 LTSS (aarch64 ppc64le s390x x86_64 nosrc)
- kernel-default-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Server 15 SP2 LTSS (aarch64 ppc64le s390x x86_64)
- kernel-default-base-5.3.18-150200.24.209.1.150200.9.109.1
- kernel-obs-build-debugsource-5.3.18-150200.24.209.1
- reiserfs-kmp-default-debuginfo-5.3.18-150200.24.209.1
- kernel-syms-5.3.18-150200.24.209.1
- kernel-default-devel-debuginfo-5.3.18-150200.24.209.1
- reiserfs-kmp-default-5.3.18-150200.24.209.1
- kernel-default-devel-5.3.18-150200.24.209.1
- kernel-default-debuginfo-5.3.18-150200.24.209.1
- kernel-obs-build-5.3.18-150200.24.209.1
- kernel-default-debugsource-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Server 15 SP2 LTSS (noarch)
- kernel-source-5.3.18-150200.24.209.1
- kernel-devel-5.3.18-150200.24.209.1
- kernel-macros-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Server 15 SP2 LTSS (noarch nosrc)
- kernel-docs-5.3.18-150200.24.209.2
-
SUSE Linux Enterprise Server 15 SP2 LTSS (aarch64 nosrc x86_64)
- kernel-preempt-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Server 15 SP2 LTSS (aarch64 x86_64)
- kernel-preempt-devel-5.3.18-150200.24.209.1
- kernel-preempt-debugsource-5.3.18-150200.24.209.1
- kernel-preempt-debuginfo-5.3.18-150200.24.209.1
- kernel-preempt-devel-debuginfo-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (nosrc ppc64le x86_64)
- kernel-default-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64)
- kernel-default-base-5.3.18-150200.24.209.1.150200.9.109.1
- kernel-obs-build-debugsource-5.3.18-150200.24.209.1
- reiserfs-kmp-default-debuginfo-5.3.18-150200.24.209.1
- kernel-syms-5.3.18-150200.24.209.1
- kernel-default-devel-debuginfo-5.3.18-150200.24.209.1
- reiserfs-kmp-default-5.3.18-150200.24.209.1
- kernel-default-devel-5.3.18-150200.24.209.1
- kernel-default-debuginfo-5.3.18-150200.24.209.1
- kernel-obs-build-5.3.18-150200.24.209.1
- kernel-default-debugsource-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch)
- kernel-source-5.3.18-150200.24.209.1
- kernel-devel-5.3.18-150200.24.209.1
- kernel-macros-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch nosrc)
- kernel-docs-5.3.18-150200.24.209.2
-
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (nosrc x86_64)
- kernel-preempt-5.3.18-150200.24.209.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (x86_64)
- kernel-preempt-devel-5.3.18-150200.24.209.1
- kernel-preempt-debugsource-5.3.18-150200.24.209.1
- kernel-preempt-debuginfo-5.3.18-150200.24.209.1
- kernel-preempt-devel-debuginfo-5.3.18-150200.24.209.1
References:
- https://www.suse.com/security/cve/CVE-2021-47416.html
- https://www.suse.com/security/cve/CVE-2021-47589.html
- https://www.suse.com/security/cve/CVE-2022-3435.html
- https://www.suse.com/security/cve/CVE-2022-45934.html
- https://www.suse.com/security/cve/CVE-2022-48664.html
- https://www.suse.com/security/cve/CVE-2022-48947.html
- https://www.suse.com/security/cve/CVE-2022-48956.html
- https://www.suse.com/security/cve/CVE-2022-48960.html
- https://www.suse.com/security/cve/CVE-2022-48962.html
- https://www.suse.com/security/cve/CVE-2022-48967.html
- https://www.suse.com/security/cve/CVE-2022-48970.html
- https://www.suse.com/security/cve/CVE-2022-48988.html
- https://www.suse.com/security/cve/CVE-2022-48991.html
- https://www.suse.com/security/cve/CVE-2022-48999.html
- https://www.suse.com/security/cve/CVE-2022-49003.html
- https://www.suse.com/security/cve/CVE-2022-49014.html
- https://www.suse.com/security/cve/CVE-2022-49015.html
- https://www.suse.com/security/cve/CVE-2022-49023.html
- https://www.suse.com/security/cve/CVE-2022-49025.html
- https://www.suse.com/security/cve/CVE-2023-28327.html
- https://www.suse.com/security/cve/CVE-2023-46343.html
- https://www.suse.com/security/cve/CVE-2023-52881.html
- https://www.suse.com/security/cve/CVE-2023-52919.html
- https://www.suse.com/security/cve/CVE-2023-6270.html
- https://www.suse.com/security/cve/CVE-2024-27043.html
- https://www.suse.com/security/cve/CVE-2024-42145.html
- https://www.suse.com/security/cve/CVE-2024-44947.html
- https://www.suse.com/security/cve/CVE-2024-45016.html
- https://www.suse.com/security/cve/CVE-2024-46813.html
- https://www.suse.com/security/cve/CVE-2024-46816.html
- https://www.suse.com/security/cve/CVE-2024-46817.html
- https://www.suse.com/security/cve/CVE-2024-46818.html
- https://www.suse.com/security/cve/CVE-2024-46849.html
- https://www.suse.com/security/cve/CVE-2024-47668.html
- https://www.suse.com/security/cve/CVE-2024-47674.html
- https://www.suse.com/security/cve/CVE-2024-47684.html
- https://www.suse.com/security/cve/CVE-2024-47706.html
- https://www.suse.com/security/cve/CVE-2024-47747.html
- https://www.suse.com/security/cve/CVE-2024-49860.html
- https://www.suse.com/security/cve/CVE-2024-49867.html
- https://www.suse.com/security/cve/CVE-2024-49936.html
- https://www.suse.com/security/cve/CVE-2024-49974.html
- https://www.suse.com/security/cve/CVE-2024-49982.html
- https://www.suse.com/security/cve/CVE-2024-49991.html
- https://www.suse.com/security/cve/CVE-2024-49995.html
- https://www.suse.com/security/cve/CVE-2024-50047.html
- https://bugzilla.suse.com/show_bug.cgi?id=1195775
- https://bugzilla.suse.com/show_bug.cgi?id=1204171
- https://bugzilla.suse.com/show_bug.cgi?id=1205796
- https://bugzilla.suse.com/show_bug.cgi?id=1206344
- https://bugzilla.suse.com/show_bug.cgi?id=1209290
- https://bugzilla.suse.com/show_bug.cgi?id=1218562
- https://bugzilla.suse.com/show_bug.cgi?id=1219125
- https://bugzilla.suse.com/show_bug.cgi?id=1223384
- https://bugzilla.suse.com/show_bug.cgi?id=1223524
- https://bugzilla.suse.com/show_bug.cgi?id=1223824
- https://bugzilla.suse.com/show_bug.cgi?id=1225336
- https://bugzilla.suse.com/show_bug.cgi?id=1225611
- https://bugzilla.suse.com/show_bug.cgi?id=1226211
- https://bugzilla.suse.com/show_bug.cgi?id=1226212
- https://bugzilla.suse.com/show_bug.cgi?id=1226557
- https://bugzilla.suse.com/show_bug.cgi?id=1228743
- https://bugzilla.suse.com/show_bug.cgi?id=1229042
- https://bugzilla.suse.com/show_bug.cgi?id=1229454
- https://bugzilla.suse.com/show_bug.cgi?id=1229456
- https://bugzilla.suse.com/show_bug.cgi?id=1230429
- https://bugzilla.suse.com/show_bug.cgi?id=1231073
- https://bugzilla.suse.com/show_bug.cgi?id=1231191
- https://bugzilla.suse.com/show_bug.cgi?id=1231197
- https://bugzilla.suse.com/show_bug.cgi?id=1231200
- https://bugzilla.suse.com/show_bug.cgi?id=1231203
- https://bugzilla.suse.com/show_bug.cgi?id=1231293
- https://bugzilla.suse.com/show_bug.cgi?id=1231375
- https://bugzilla.suse.com/show_bug.cgi?id=1231502
- https://bugzilla.suse.com/show_bug.cgi?id=1231673
- https://bugzilla.suse.com/show_bug.cgi?id=1231861
- https://bugzilla.suse.com/show_bug.cgi?id=1231887
- https://bugzilla.suse.com/show_bug.cgi?id=1231890
- https://bugzilla.suse.com/show_bug.cgi?id=1231893
- https://bugzilla.suse.com/show_bug.cgi?id=1231895
- https://bugzilla.suse.com/show_bug.cgi?id=1231936
- https://bugzilla.suse.com/show_bug.cgi?id=1231938
- https://bugzilla.suse.com/show_bug.cgi?id=1231942
- https://bugzilla.suse.com/show_bug.cgi?id=1231960
- https://bugzilla.suse.com/show_bug.cgi?id=1231961
- https://bugzilla.suse.com/show_bug.cgi?id=1231979
- https://bugzilla.suse.com/show_bug.cgi?id=1231987
- https://bugzilla.suse.com/show_bug.cgi?id=1231988
- https://bugzilla.suse.com/show_bug.cgi?id=1232033
- https://bugzilla.suse.com/show_bug.cgi?id=1232069
- https://bugzilla.suse.com/show_bug.cgi?id=1232070
- https://bugzilla.suse.com/show_bug.cgi?id=1232097
- https://bugzilla.suse.com/show_bug.cgi?id=1232136
- https://bugzilla.suse.com/show_bug.cgi?id=1232145
- https://bugzilla.suse.com/show_bug.cgi?id=1232262
- https://bugzilla.suse.com/show_bug.cgi?id=1232282
- https://bugzilla.suse.com/show_bug.cgi?id=1232286
- https://bugzilla.suse.com/show_bug.cgi?id=1232304
- https://bugzilla.suse.com/show_bug.cgi?id=1232383
- https://bugzilla.suse.com/show_bug.cgi?id=1232418
- https://bugzilla.suse.com/show_bug.cgi?id=1232424
- https://bugzilla.suse.com/show_bug.cgi?id=1232432