The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2022-49035: media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE
(bsc#1215304).
* CVE-2024-53146: NFSD: Prevent a potential integer overflow (bsc#1234853).
* CVE-2024-53156: wifi: ath9k: add range check for conn_rsp_epid in
htc_connect_service() (bsc#1234846).
* CVE-2024-53173: NFSv4.0: Fix a use-after-free problem in the asynchronous
open() (bsc#1234891).
* CVE-2024-53179: smb: client: fix use-after-free of signing key
(bsc#1234921).
* CVE-2024-53214: vfio/pci: Properly hide first-in-list PCIe extended
capability (bsc#1235004).
* CVE-2024-53239: ALSA: 6fire: Release resources at card release
(bsc#1235054).
* CVE-2024-53240: xen/netfront: fix crash when removing device (bsc#1234281).
* CVE-2024-56539: wifi: mwifiex: Fix memcpy() field-spanning write warning in
mwifiex_config_scan() (bsc#1234963).
*...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Enterprise Storage 7.1
zypper in -t patch SUSE-Storage-7.1-2025-202=1
* SUSE Linux Enterprise Micro 5.1
zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-202=1
* SUSE Linux Enterprise Micro 5.2
zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-202=1
* SUSE Linux Enterprise Micro for Rancher 5.2
zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-202=1
* openSUSE Leap 15.3
zypper in -t patch SUSE-2025-202=1
* SUSE Linux Enterprise Live Patching 15-SP3
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-202=1
* SUSE Linux Enterprise High Availability Extension 15 SP3
zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2025-202=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-202=1
* SUSE Linux Enterprise Server 15 SP3 LTSS
zypper in -t...
Read the Full Advisory* SUSE Enterprise Storage 7.1 (aarch64 nosrc)
* kernel-64kb-5.3.18-150300.59.188.1
* SUSE Enterprise Storage 7.1 (aarch64)
* kernel-64kb-debugsource-5.3.18-150300.59.188.1
* kernel-64kb-devel-debuginfo-5.3.18-150300.59.188.1
* kernel-64kb-debuginfo-5.3.18-150300.59.188.1
* kernel-64kb-devel-5.3.18-150300.59.188.1
* SUSE Enterprise Storage 7.1 (aarch64 nosrc x86_64)
* kernel-default-5.3.18-150300.59.188.1
* kernel-preempt-5.3.18-150300.59.188.1
* SUSE Enterprise Storage 7.1 (aarch64 x86_64)
* kernel-default-debuginfo-5.3.18-150300.59.188.1
* kernel-obs-build-5.3.18-150300.59.188.1
* kernel-obs-build-debugsource-5.3.18-150300.59.188.1
* kernel-syms-5.3.18-150300.59.188.1
* reiserfs-kmp-default-5.3.18-150300.59.188.1
* kernel-preempt-devel-debuginfo-5.3.18-150300.59.188.1
* kernel-default-devel-debuginfo-5.3.18-150300.59.188.1
* kernel-default-devel-5.3.18-150300.59.188.1
* kernel-default-debugsource-5.3.18-150300.59.188.1
* kernel-default-base-5.3.18-150300.59.188.1.150300.18.111.1
*...
Read the Full Advisory* bsc#1215304
* bsc#1220927
* bsc#1220937
* bsc#1230697
* bsc#1232436
* bsc#1234281
* bsc#1234690
* bsc#1234846
* bsc#1234853
* bsc#1234891
* bsc#1234921
* bsc#1234963
* bsc#1235004
* bsc#1235054
* bsc#1235056
* bsc#1235061
* bsc#1235073
* bsc#1235246
* bsc#1235480
* bsc#1235584
## References:
* https://www.suse.com/security/cve/CVE-2022-49035.html
* https://www.suse.com/security/cve/CVE-2023-52524.html
* https://www.suse.com/security/cve/CVE-2024-53142.html
* https://www.suse.com/security/cve/CVE-2024-53144.html
* https://www.suse.com/security/cve/CVE-2024-53146.html
* https://www.suse.com/security/cve/CVE-2024-53156.html
* https://www.suse.com/security/cve/CVE-2024-53173.html
* https://www.suse.com/security/cve/CVE-2024-53179.html
* https://www.suse.com/security/cve/CVE-2024-53214.html
* https://www.suse.com/security/cve/CVE-2024-53239.html
* https://www.suse.com/security/cve/CVE-2024-53240.html
* https://www.suse.com/security/cve/CVE-2024-56539.html
* https://www.suse.com/security/cve/CVE-2024-56548.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.