Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2024-43854: Initialize integrity buffer to zero before writing it to
media (bsc#1229345)
* CVE-2024-49925: fbdev: efifb: Register sysfs groups through driver core
(bsc#1232224)
* CVE-2024-49945: net/ncsi: Disable the ncsi work before freeing the
associated structure (bsc#1232165).
* CVE-2024-50208: RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages
(bsc#1233117).
* CVE-2022-48879: efi: fix NULL-deref in init error path (bsc#1229556).
* CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1231893).
* CVE-2022-48959: net: dsa: sja1105: fix memory leak in
sja1105_setup_devlink_regions() (bsc#1231976).
* CVE-2022-48960: net: hisilicon: Fix potential use-after-free in hix5hd2_rx()
(bsc#1231979).
* CVE-2022-48962: net: hisilicon: Fix potential use-after-free in
hisi_femac_rx()...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2024-4131=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2024-4131=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2024-4131=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2024-4131=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2024-4131=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2024-4131=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High Availability Extension 15 SP4
zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2024-4131=1
* SUSE Linux...
Read the Full Advisory* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150400_24_141-default-debuginfo-1-150400.9.5.1
* kernel-livepatch-5_14_21-150400_24_141-default-1-150400.9.5.1
* kernel-livepatch-SLE15-SP4_Update_33-debugsource-1-150400.9.5.1
* openSUSE Leap 15.4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.141.1
* openSUSE Leap 15.4 (noarch)
* kernel-docs-html-5.14.21-150400.24.141.1
* kernel-devel-5.14.21-150400.24.141.1
* kernel-source-vanilla-5.14.21-150400.24.141.1
* kernel-macros-5.14.21-150400.24.141.1
* kernel-source-5.14.21-150400.24.141.1
* openSUSE Leap 15.4 (nosrc ppc64le x86_64)
* kernel-debug-5.14.21-150400.24.141.1
* openSUSE Leap 15.4 (ppc64le x86_64)
* kernel-debug-devel-debuginfo-5.14.21-150400.24.141.1
* kernel-debug-livepatch-devel-5.14.21-150400.24.141.1
* kernel-debug-devel-5.14.21-150400.24.141.1
* kernel-debug-debuginfo-5.14.21-150400.24.141.1
* kernel-debug-debugsource-5.14.21-150400.24.141.1
* openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
*...
Read the Full Advisory* bsc#1204171
* bsc#1205796
* bsc#1206188
* bsc#1206344
* bsc#1209290
* bsc#1210449
* bsc#1210627
* bsc#1213034
* bsc#1216223
* bsc#1216813
* bsc#1218562
* bsc#1220382
* bsc#1223384
* bsc#1223524
* bsc#1223824
* bsc#1225189
* bsc#1225336
* bsc#1225611
* bsc#1226666
* bsc#1228743
* bsc#1229345
* bsc#1229452
* bsc#1229454
* bsc#1229456
* bsc#1229556
* bsc#1230429
* bsc#1230442
* bsc#1230454
* bsc#1230600
* bsc#1230620
* bsc#1230715
* bsc#1230903
* bsc#1231016
* bsc#1231073
* bsc#1231191
* bsc#1231193
* bsc#1231195
* bsc#1231197
* bsc#1231200
* bsc#1231203
* bsc#1231293
* bsc#1231375
* bsc#1231502
* bsc#1231673
* bsc#1231861
* bsc#1231883
* bsc#1231885
* bsc#1231887
* bsc#1231888
* bsc#1231890
* bsc#1231892
* bsc#1231893
* bsc#1231895
* bsc#1231896
* bsc#1231897
* bsc#1231929
* bsc#1231936
* bsc#1231937
* bsc#1231938
* bsc#1231939
* bsc#1231940
* bsc#1231941
* bsc#1231942
* bsc#1231958
* bsc#1231960
* bsc#1231961
* bsc#1231962
* bsc#1231972
* bsc#1231976
* bsc#1231979
* bsc#1231987
* bsc#1231988
* bsc#1231991
* bsc#1231992
* bsc#1231995
* bsc#1231996
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.