The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2023-52524: Fixed possible corruption in nfc/llcp (bsc#1220927).
* CVE-2024-49925: fbdev: efifb: Register sysfs groups through driver core
(bsc#1232224)
* CVE-2024-50089: unicode: Do not special case ignorable code points
(bsc#1232860).
* CVE-2024-50115: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
(bsc#1232919).
* CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout (bsc#1232928).
* CVE-2024-50127: net: sched: fix use-after-free in taprio_change()
(bsc#1232907).
* CVE-2024-50154: tcp/dccp: Do not use timer_pending() in reqsk_queue_unlink()
(bsc#1233070)
* CVE-2024-50205: ALSA: firewire-lib: Avoid division by zero in
apply_constraint_to_size() (bsc#1233293).
* CVE-2024-50208: RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages
(bsc#1233117).
* CVE-2024-50264: vsock/virtio:...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.3
zypper in -t patch SUSE-2024-4313=1
* SUSE Linux Enterprise Live Patching 15-SP3
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2024-4313=1
* SUSE Linux Enterprise High Availability Extension 15 SP3
zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2024-4313=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-4313=1
* SUSE Linux Enterprise Server 15 SP3 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-4313=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP3
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-4313=1
* SUSE Enterprise Storage 7.1
zypper in -t patch SUSE-Storage-7.1-2024-4313=1
* SUSE Linux Enterprise Micro 5.1
zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-4313=1
* SUSE...
Read the Full Advisory* openSUSE Leap 15.3 (noarch nosrc)
* kernel-docs-5.3.18-150300.59.185.1
* openSUSE Leap 15.3 (noarch)
* kernel-docs-html-5.3.18-150300.59.185.1
* kernel-source-vanilla-5.3.18-150300.59.185.1
* kernel-source-5.3.18-150300.59.185.1
* kernel-devel-5.3.18-150300.59.185.1
* kernel-macros-5.3.18-150300.59.185.1
* openSUSE Leap 15.3 (nosrc ppc64le x86_64)
* kernel-kvmsmall-5.3.18-150300.59.185.1
* kernel-debug-5.3.18-150300.59.185.1
* openSUSE Leap 15.3 (ppc64le x86_64)
* kernel-kvmsmall-devel-debuginfo-5.3.18-150300.59.185.1
* kernel-debug-debuginfo-5.3.18-150300.59.185.1
* kernel-debug-debugsource-5.3.18-150300.59.185.1
* kernel-kvmsmall-debuginfo-5.3.18-150300.59.185.1
* kernel-debug-devel-5.3.18-150300.59.185.1
* kernel-kvmsmall-debugsource-5.3.18-150300.59.185.1
* kernel-debug-devel-debuginfo-5.3.18-150300.59.185.1
* kernel-kvmsmall-devel-5.3.18-150300.59.185.1
* openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64)
* ocfs2-kmp-default-debuginfo-5.3.18-150300.59.185.1
*...
Read the Full Advisory* bsc#1154353
* bsc#1198778
* bsc#1218644
* bsc#1220927
* bsc#1231939
* bsc#1231940
* bsc#1231958
* bsc#1231962
* bsc#1231991
* bsc#1231992
* bsc#1231995
* bsc#1232006
* bsc#1232163
* bsc#1232172
* bsc#1232224
* bsc#1232436
* bsc#1232860
* bsc#1232907
* bsc#1232919
* bsc#1232928
* bsc#1233070
* bsc#1233117
* bsc#1233293
* bsc#1233453
* bsc#1233456
* bsc#1233468
* bsc#1233479
* bsc#1233490
* bsc#1233491
* bsc#1233555
* bsc#1233557
* jsc#SLE-8100
## References:
* https://www.suse.com/security/cve/CVE-2022-48985.html
* https://www.suse.com/security/cve/CVE-2022-49006.html
* https://www.suse.com/security/cve/CVE-2022-49010.html
* https://www.suse.com/security/cve/CVE-2022-49011.html
* https://www.suse.com/security/cve/CVE-2022-49019.html
* https://www.suse.com/security/cve/CVE-2022-49021.html
* https://www.suse.com/security/cve/CVE-2022-49022.html
* https://www.suse.com/security/cve/CVE-2022-49029.html
* https://www.suse.com/security/cve/CVE-2022-49031.html
* https://www.suse.com/security/cve/CVE-2022-49032.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.