The SUSE Linux Enterprise 15 SP6 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2024-28956: x86/ibt: Keep IBT disabled during alternative patching
(bsc#1242006).
* CVE-2024-35840: mptcp: use OPTION_MPTCP_MPJ_SYNACK in
subflow_finish_connect() (bsc#1224597).
* CVE-2024-50038: netfilter: xtables: fix typo causing some targets not to
load on IPv6 (bsc#1231910).
* CVE-2024-50162: bpf: selftests: send packet to devmap redirect XDP
(bsc#1233075).
* CVE-2024-50163: bpf: Make sure internal and UAPI bpf_redirect flags do not
overlap (bsc#1233098).
* CVE-2024-53124: net: fix data-races around sk->sk_forward_alloc
(bsc#1234074).
* CVE-2024-53139: sctp: fix possible UAF in sctp_v6_available() (bsc#1234157).
* CVE-2024-57924: fs: relax assertions on failure to encode file handles
(bsc#1236086).
* CVE-2024-58018: nvkm: correctly calculate the available space of the GSP
cmdq buffer...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2025-1614=1 openSUSE-SLE-15.6-2025-1614=1
* Basesystem Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1614=1
* Development Tools Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-1614=1
* Legacy Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-1614=1
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-1614=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High Availability Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2025-1614=1
* SUSE Linux Enterprise Workstation Extension 15 SP6
zypper...
Read the Full Advisory* openSUSE Leap 15.6 (noarch nosrc)
* kernel-docs-6.4.0-150600.23.50.1
* openSUSE Leap 15.6 (noarch)
* kernel-source-6.4.0-150600.23.50.1
* kernel-source-vanilla-6.4.0-150600.23.50.1
* kernel-macros-6.4.0-150600.23.50.1
* kernel-devel-6.4.0-150600.23.50.1
* kernel-docs-html-6.4.0-150600.23.50.1
* openSUSE Leap 15.6 (nosrc ppc64le x86_64)
* kernel-debug-6.4.0-150600.23.50.1
* openSUSE Leap 15.6 (ppc64le x86_64)
* kernel-debug-devel-debuginfo-6.4.0-150600.23.50.1
* kernel-debug-debugsource-6.4.0-150600.23.50.1
* kernel-debug-devel-6.4.0-150600.23.50.1
* kernel-debug-debuginfo-6.4.0-150600.23.50.1
* openSUSE Leap 15.6 (x86_64)
* kernel-debug-vdso-6.4.0-150600.23.50.1
* kernel-kvmsmall-vdso-debuginfo-6.4.0-150600.23.50.1
* kernel-default-vdso-6.4.0-150600.23.50.1
* kernel-default-vdso-debuginfo-6.4.0-150600.23.50.1
* kernel-debug-vdso-debuginfo-6.4.0-150600.23.50.1
* kernel-kvmsmall-vdso-6.4.0-150600.23.50.1
* openSUSE Leap 15.6 (aarch64 ppc64le x86_64)
* kernel-kvmsmall-devel-debuginfo-6.4.0-150600.23.50.1
*...
Read the Full Advisory* bsc#1215199
* bsc#1223809
* bsc#1224013
* bsc#1224597
* bsc#1224757
* bsc#1228659
* bsc#1230764
* bsc#1231103
* bsc#1231910
* bsc#1232493
* bsc#1233075
* bsc#1233098
* bsc#1234074
* bsc#1234157
* bsc#1234698
* bsc#1235501
* bsc#1235526
* bsc#1235550
* bsc#1235870
* bsc#1236086
* bsc#1236704
* bsc#1237111
* bsc#1237874
* bsc#1237882
* bsc#1238052
* bsc#1238212
* bsc#1238471
* bsc#1238527
* bsc#1238565
* bsc#1238714
* bsc#1238737
* bsc#1238742
* bsc#1238745
* bsc#1238746
* bsc#1238862
* bsc#1238961
* bsc#1238970
* bsc#1238983
* bsc#1238990
* bsc#1239066
* bsc#1239079
* bsc#1239108
* bsc#1239470
* bsc#1239475
* bsc#1239476
* bsc#1239487
* bsc#1239510
* bsc#1239684
* bsc#1239906
* bsc#1239925
* bsc#1239997
* bsc#1240167
* bsc#1240168
* bsc#1240171
* bsc#1240176
* bsc#1240181
* bsc#1240184
* bsc#1240185
* bsc#1240375
* bsc#1240557
* bsc#1240575
* bsc#1240576
* bsc#1240581
* bsc#1240582
* bsc#1240583
* bsc#1240584
* bsc#1240585
* bsc#1240587
* bsc#1240590
* bsc#1240591
* bsc#1240592
* bsc#1240594
* bsc#1240595
* bsc#1240596
* bsc#1240600
* bsc#1240612
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.