The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2024-50199: mm/swapfile: skip HugeTLB pages for unuse_vma (bsc#1233112).
* CVE-2024-53104: media: uvcvideo: Skip parsing frames of type
UVC_VS_UNDEFINED in uvc_parse_format (bsc#1234025).
* CVE-2024-53166: block, bfq: fix bfqq uaf in bfq_limit_depth() (bsc#1234884).
* CVE-2024-53177: smb: prevent use-after-free due to open_cached_dir error
paths (bsc#1234896).
* CVE-2024-56600: net: inet6: do not leave a dangling sk pointer in
inet6_create() (bsc#1235217).
* CVE-2024-56601: net: inet: do not leave a dangling sk pointer in
inet_create() (bsc#1235230).
* CVE-2024-56602: net: ieee802154: do not leave a dangling sk pointer in
ieee802154_create() (bsc#1235521).
* CVE-2024-56623: scsi: qla2xxx: Fix use after free on unload (bsc#1235466).
* CVE-2024-56631: scsi: sg: Fix slab-use-after-free read in sg_release()
...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-576=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-576=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-576=1
* SUSE Manager Proxy 4.3
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-576=1
* SUSE Manager Retail Branch Server 4.3
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-
Server-4.3-2025-576=1
* SUSE Manager Server 4.3
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-576=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-576=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch...
Read the Full Advisory* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc)
* kernel-64kb-5.14.21-150400.24.150.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64)
* kernel-64kb-devel-5.14.21-150400.24.150.1
* kernel-64kb-debuginfo-5.14.21-150400.24.150.1
* kernel-64kb-debugsource-5.14.21-150400.24.150.1
* kernel-64kb-devel-debuginfo-5.14.21-150400.24.150.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc
x86_64)
* kernel-default-5.14.21-150400.24.150.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* reiserfs-kmp-default-debuginfo-5.14.21-150400.24.150.1
* kernel-default-debugsource-5.14.21-150400.24.150.1
* reiserfs-kmp-default-5.14.21-150400.24.150.1
* kernel-obs-build-5.14.21-150400.24.150.1
* kernel-obs-build-debugsource-5.14.21-150400.24.150.1
* kernel-default-devel-debuginfo-5.14.21-150400.24.150.1
* kernel-default-debuginfo-5.14.21-150400.24.150.1
* kernel-default-base-5.14.21-150400.24.150.1.150400.24.74.1
*...
Read the Full Advisory* bsc#1230697
* bsc#1231847
* bsc#1233112
* bsc#1233642
* bsc#1234025
* bsc#1234690
* bsc#1234884
* bsc#1234896
* bsc#1234931
* bsc#1235134
* bsc#1235217
* bsc#1235230
* bsc#1235249
* bsc#1235430
* bsc#1235433
* bsc#1235441
* bsc#1235451
* bsc#1235466
* bsc#1235480
* bsc#1235521
* bsc#1235584
* bsc#1235645
* bsc#1235723
* bsc#1235759
* bsc#1235764
* bsc#1235814
* bsc#1235818
* bsc#1235920
* bsc#1235969
* bsc#1236628
## References:
* https://www.suse.com/security/cve/CVE-2024-50199.html
* https://www.suse.com/security/cve/CVE-2024-53095.html
* https://www.suse.com/security/cve/CVE-2024-53104.html
* https://www.suse.com/security/cve/CVE-2024-53144.html
* https://www.suse.com/security/cve/CVE-2024-53166.html
* https://www.suse.com/security/cve/CVE-2024-53177.html
* https://www.suse.com/security/cve/CVE-2024-54680.html
* https://www.suse.com/security/cve/CVE-2024-56600.html
* https://www.suse.com/security/cve/CVE-2024-56601.html
* https://www.suse.com/security/cve/CVE-2024-56602.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.