The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2024-26782: mptcp: fix double-free on socket dismantle (bsc#1222590).
* CVE-2024-44932: idpf: fix UAFs when destroying the queues (bsc#1229808).
* CVE-2024-44964: idpf: fix memory leaks and crashes while performing a soft
reset (bsc#1230220).
* CVE-2024-47757: nilfs2: fix potential oob read in nilfs_btree_check_delete()
(bsc#1232187).
* CVE-2024-50089: unicode: Do not special case ignorable code points
(bsc#1232860).
* CVE-2024-50115: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
(bsc#1232919).
* CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout (bsc#1232928).
* CVE-2024-50127: net: sched: fix use-after-free in taprio_change()
(bsc#1232907).
* CVE-2024-50154: tcp: Fix use-after-free of nreq in reqsk_timer_handler()
(bsc#1233070).
* CVE-2024-50205: ALSA: firewire-lib: Avoid division...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Manager Proxy 4.3
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-4346=1
* SUSE Manager Retail Branch Server 4.3
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-
Server-4.3-2024-4346=1
* SUSE Manager Server 4.3
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-4346=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2024-4346=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2024-4346=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2024-4346=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2024-4346=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2024-4346=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch...
Read the Full Advisory* SUSE Manager Proxy 4.3 (nosrc x86_64)
* kernel-default-5.14.21-150400.24.144.1
* SUSE Manager Proxy 4.3 (x86_64)
* kernel-default-base-5.14.21-150400.24.144.1.150400.24.70.1
* kernel-default-debugsource-5.14.21-150400.24.144.1
* kernel-default-debuginfo-5.14.21-150400.24.144.1
* kernel-default-devel-5.14.21-150400.24.144.1
* kernel-default-devel-debuginfo-5.14.21-150400.24.144.1
* kernel-syms-5.14.21-150400.24.144.1
* SUSE Manager Proxy 4.3 (noarch)
* kernel-devel-5.14.21-150400.24.144.1
* kernel-macros-5.14.21-150400.24.144.1
* kernel-source-5.14.21-150400.24.144.1
* SUSE Manager Retail Branch Server 4.3 (nosrc x86_64)
* kernel-default-5.14.21-150400.24.144.1
* SUSE Manager Retail Branch Server 4.3 (x86_64)
* kernel-default-base-5.14.21-150400.24.144.1.150400.24.70.1
* kernel-default-debugsource-5.14.21-150400.24.144.1
* kernel-default-debuginfo-5.14.21-150400.24.144.1
* kernel-default-devel-5.14.21-150400.24.144.1
* kernel-default-devel-debuginfo-5.14.21-150400.24.144.1
* SUSE Manager Retail Branch...
Read the Full Advisory* bsc#1218644
* bsc#1220382
* bsc#1221309
* bsc#1222590
* bsc#1229808
* bsc#1230220
* bsc#1231646
* bsc#1232187
* bsc#1232312
* bsc#1232860
* bsc#1232907
* bsc#1232919
* bsc#1232928
* bsc#1233070
* bsc#1233214
* bsc#1233293
* bsc#1233453
* bsc#1233456
* bsc#1233463
* bsc#1233468
* bsc#1233479
* bsc#1233490
* bsc#1233491
* bsc#1233555
* bsc#1233557
* bsc#1233561
* bsc#1233977
## References:
* https://www.suse.com/security/cve/CVE-2023-52922.html
* https://www.suse.com/security/cve/CVE-2024-26782.html
* https://www.suse.com/security/cve/CVE-2024-44932.html
* https://www.suse.com/security/cve/CVE-2024-44964.html
* https://www.suse.com/security/cve/CVE-2024-47757.html
* https://www.suse.com/security/cve/CVE-2024-50017.html
* https://www.suse.com/security/cve/CVE-2024-50089.html
* https://www.suse.com/security/cve/CVE-2024-50115.html
* https://www.suse.com/security/cve/CVE-2024-50125.html
* https://www.suse.com/security/cve/CVE-2024-50127.html
* https://www.suse.com/security/cve/CVE-2024-50154.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.