The SUSE Linux Enterprise 15 SP6 RT kernel was updated to receive various
security bugfixes.
The following security bugs were fixed:
* CVE-2024-28956: x86/ibt: Keep IBT disabled during alternative patching
(bsc#1242006).
* CVE-2024-35840: mptcp: use OPTION_MPTCP_MPJ_SYNACK in
subflow_finish_connect() (bsc#1224597).
* CVE-2024-46713: kabi fix for perf/aux: Fix AUX buffer serialization
(bsc#1230581).
* CVE-2024-50038: netfilter: xtables: fix typo causing some targets not to
load on IPv6 (bsc#1231910).
* CVE-2024-50162: bpf: selftests: send packet to devmap redirect XDP
(bsc#1233075).
* CVE-2024-50163: bpf: Make sure internal and UAPI bpf_redirect flags do not
overlap (bsc#1233098).
* CVE-2024-50223: sched/numa: Fix the potential null pointer dereference in
(bsc#1233192).
* CVE-2024-53124: net: fix data-races around sk->sk_forward_alloc
(bsc#1234074).
* CVE-2024-53135: KVM: VMX: Bury Intel PT virtualization (guest/host mode)
behind...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-1964=1
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-1964=1
* SUSE Real Time Module 15-SP6
zypper in -t patch SUSE-SLE-Module-RT-15-SP6-2025-1964=1
* openSUSE Leap 15.6 (x86_64)
* cluster-md-kmp-rt-debuginfo-6.4.0-150600.10.39.1
* gfs2-kmp-rt-debuginfo-6.4.0-150600.10.39.1
* ocfs2-kmp-rt-debuginfo-6.4.0-150600.10.39.1
* kselftests-kmp-rt-debuginfo-6.4.0-150600.10.39.1
* kernel-rt-livepatch-devel-6.4.0-150600.10.39.1
* kernel-rt_debug-vdso-debuginfo-6.4.0-150600.10.39.1
* gfs2-kmp-rt-6.4.0-150600.10.39.1
* reiserfs-kmp-rt-6.4.0-150600.10.39.1
* kernel-rt-devel-debuginfo-6.4.0-150600.10.39.1
* reiserfs-kmp-rt-debuginfo-6.4.0-150600.10.39.1
* kernel-rt-optional-debuginfo-6.4.0-150600.10.39.1
* kernel-rt-vdso-debuginfo-6.4.0-150600.10.39.1
* dlm-kmp-rt-debuginfo-6.4.0-150600.10.39.1
* cluster-md-kmp-rt-6.4.0-150600.10.39.1
* kernel-rt-debugsource-6.4.0-150600.10.39.1
* kernel-rt-extra-6.4.0-150600.10.39.1
* kernel-rt-vdso-6.4.0-150600.10.39.1
* kernel-rt_debug-devel-6.4.0-150600.10.39.1
* kselftests-kmp-rt-6.4.0-150600.10.39.1
* kernel-rt_debug-debugsource-6.4.0-150600.10.39.1
* dlm-kmp-rt-6.4.0-150600.10.39.1
* kernel-rt-optional-6.4.0-150600.10.39.1
*...
Read the Full Advisory* bsc#1215199
* bsc#1220112
* bsc#1223096
* bsc#1223809
* bsc#1224013
* bsc#1224597
* bsc#1224757
* bsc#1226498
* bsc#1228659
* bsc#1229491
* bsc#1230581
* bsc#1230764
* bsc#1231016
* bsc#1231103
* bsc#1231910
* bsc#1232493
* bsc#1232649
* bsc#1232882
* bsc#1233075
* bsc#1233098
* bsc#1233192
* bsc#1234074
* bsc#1234154
* bsc#1234157
* bsc#1234698
* bsc#1235149
* bsc#1235501
* bsc#1235526
* bsc#1235550
* bsc#1235870
* bsc#1235968
* bsc#1236086
* bsc#1236142
* bsc#1236208
* bsc#1236704
* bsc#1237111
* bsc#1237312
* bsc#1237874
* bsc#1237882
* bsc#1238052
* bsc#1238212
* bsc#1238471
* bsc#1238473
* bsc#1238527
* bsc#1238565
* bsc#1238714
* bsc#1238737
* bsc#1238742
* bsc#1238745
* bsc#1238746
* bsc#1238774
* bsc#1238862
* bsc#1238961
* bsc#1238970
* bsc#1238983
* bsc#1238990
* bsc#1238992
* bsc#1239066
* bsc#1239079
* bsc#1239108
* bsc#1239470
* bsc#1239475
* bsc#1239476
* bsc#1239487
* bsc#1239510
* bsc#1239684
* bsc#1239691
* bsc#1239906
* bsc#1239925
* bsc#1239997
* bsc#1240167
* bsc#1240168
* bsc#1240171
* bsc#1240176
* bsc#1240181
* bsc#1240184
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.