The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2024-41087: Fix double free on error (bsc#1228466).
* CVE-2024-53095: smb: client: Fix use-after-free of network namespace
(bsc#1233642).
* CVE-2024-53146: NFSD: Prevent a potential integer overflow (bsc#1234853).
* CVE-2024-53156: wifi: ath9k: add range check for conn_rsp_epid in
htc_connect_service() (bsc#1234846).
* CVE-2024-53173: NFSv4.0: Fix a use-after-free problem in the asynchronous
open() (bsc#1234891).
* CVE-2024-53179: smb: client: fix use-after-free of signing key
(bsc#1234921).
* CVE-2024-53214: vfio/pci: Properly hide first-in-list PCIe extended
capability (bsc#1235004).
* CVE-2024-53239: ALSA: 6fire: Release resources at card release
(bsc#1235054).
* CVE-2024-53240: xen/netfront: fix crash when removing device (bsc#1234281).
* CVE-2024-53241: x86/xen: use new hypercall functions instead of...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-203=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-203=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-203=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-203=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-203=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2025-203=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High Availability Extension 15 SP4
zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2025-203=1
* SUSE Linux...
Read the Full Advisory* openSUSE Leap 15.4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.147.1
* openSUSE Leap 15.4 (noarch)
* kernel-source-5.14.21-150400.24.147.1
* kernel-macros-5.14.21-150400.24.147.1
* kernel-devel-5.14.21-150400.24.147.1
* kernel-source-vanilla-5.14.21-150400.24.147.1
* kernel-docs-html-5.14.21-150400.24.147.1
* openSUSE Leap 15.4 (nosrc ppc64le x86_64)
* kernel-debug-5.14.21-150400.24.147.1
* openSUSE Leap 15.4 (ppc64le x86_64)
* kernel-debug-devel-debuginfo-5.14.21-150400.24.147.1
* kernel-debug-debugsource-5.14.21-150400.24.147.1
* kernel-debug-debuginfo-5.14.21-150400.24.147.1
* kernel-debug-devel-5.14.21-150400.24.147.1
* openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
* kernel-kvmsmall-devel-5.14.21-150400.24.147.1
* kernel-kvmsmall-debuginfo-5.14.21-150400.24.147.1
* kernel-kvmsmall-debugsource-5.14.21-150400.24.147.1
* kernel-default-base-5.14.21-150400.24.147.1.150400.24.72.1
* kernel-default-base-rebuild-5.14.21-150400.24.147.1.150400.24.72.1
*...
Read the Full Advisory* bsc#1170891
* bsc#1173139
* bsc#1185010
* bsc#1190358
* bsc#1190428
* bsc#1209798
* bsc#1215304
* bsc#1222878
* bsc#1228466
* bsc#1230697
* bsc#1232436
* bsc#1233070
* bsc#1233642
* bsc#1234281
* bsc#1234282
* bsc#1234846
* bsc#1234853
* bsc#1234891
* bsc#1234921
* bsc#1234960
* bsc#1234963
* bsc#1235004
* bsc#1235035
* bsc#1235054
* bsc#1235056
* bsc#1235061
* bsc#1235073
* bsc#1235220
* bsc#1235224
* bsc#1235246
* bsc#1235507
## References:
* https://www.suse.com/security/cve/CVE-2021-47202.html
* https://www.suse.com/security/cve/CVE-2022-49035.html
* https://www.suse.com/security/cve/CVE-2024-41087.html
* https://www.suse.com/security/cve/CVE-2024-50154.html
* https://www.suse.com/security/cve/CVE-2024-53095.html
* https://www.suse.com/security/cve/CVE-2024-53142.html
* https://www.suse.com/security/cve/CVE-2024-53146.html
* https://www.suse.com/security/cve/CVE-2024-53156.html
* https://www.suse.com/security/cve/CVE-2024-53173.html
* https://www.suse.com/security/cve/CVE-2024-53179.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.