This update for the Linux Kernel 5.14.21-150500_55_65 fixes several issues.
The following security issues were fixed:
* CVE-2024-53156: wifi: ath9k: add range check for conn_rsp_epid in
htc_connect_service() (bsc#1234847).
* CVE-2024-43882: Fixed ToCToU between perm check and set-uid/gid usage
(bsc#1229504).
* CVE-2024-50115: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
(bsc#1233019).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.3
zypper in -t patch SUSE-2025-1668=1 SUSE-2025-1664=1
* SUSE Linux Enterprise Live Patching 15-SP3
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-1668=1 SUSE-SLE-
Module-Live-Patching-15-SP3-2025-1664=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-1666=1 SUSE-2025-1667=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2025-1666=1 SUSE-SLE-
Module-Live-Patching-15-SP4-2025-1667=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2025-1673=1 SUSE-2025-1674=1
* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2025-1673=1 SUSE-SLE-
Module-Live-Patching-15-SP5-2025-1674=1
* openSUSE Leap 15.3 (ppc64le s390x x86_64)
* kernel-livepatch-5_3_18-150300_59_158-default-18-150300.2.2
* kernel-livepatch-SLE15-SP3_Update_43-debugsource-18-150300.2.2
* kernel-livepatch-5_3_18-150300_59_170-default-11-150300.2.2
* kernel-livepatch-SLE15-SP3_Update_47-debugsource-11-150300.2.2
* kernel-livepatch-5_3_18-150300_59_158-default-debuginfo-18-150300.2.2
* kernel-livepatch-5_3_18-150300_59_170-default-debuginfo-11-150300.2.2
* openSUSE Leap 15.3 (x86_64)
* kernel-livepatch-5_3_18-150300_59_170-preempt-debuginfo-11-150300.2.2
* kernel-livepatch-5_3_18-150300_59_170-preempt-11-150300.2.2
* kernel-livepatch-5_3_18-150300_59_158-preempt-debuginfo-18-150300.2.2
* kernel-livepatch-5_3_18-150300_59_158-preempt-18-150300.2.2
* SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64)
* kernel-livepatch-5_3_18-150300_59_158-default-18-150300.2.2
* kernel-livepatch-5_3_18-150300_59_170-default-debuginfo-11-150300.2.2
* kernel-livepatch-SLE15-SP3_Update_47-debugsource-11-150300.2.2
*...
Read the Full Advisory* bsc#1229504
* bsc#1233019
* bsc#1234847
## References:
* https://www.suse.com/security/cve/CVE-2024-43882.html
* https://www.suse.com/security/cve/CVE-2024-50115.html
* https://www.suse.com/security/cve/CVE-2024-53156.html
* https://bugzilla.suse.com/show_bug.cgi?id=1229504
* https://bugzilla.suse.com/show_bug.cgi?id=1233019
* https://bugzilla.suse.com/show_bug.cgi?id=1234847
Get the latest Linux and open source security news straight to your inbox.