The SUSE Linux Enterprise 15 SP6 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2024-26708: mptcp: fix inconsistent state on fastopen race
(bsc#1222672).
* CVE-2024-40980: drop_monitor: replace spin_lock by raw_spin_lock
(bsc#1227937).
* CVE-2024-44974: mptcp: pm: avoid possible UaF when selecting endp
(bsc#1230235).
* CVE-2024-45009: mptcp: pm: only decrement add_addr_accepted for MPJ req
(bsc#1230438).
* CVE-2024-45010: mptcp: pm: only mark 'subflow' endp as available
(bsc#1230439).
* CVE-2024-50029: Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync
(bsc#1231949).
* CVE-2024-50036: net: do not delay dst_entries_add() in dst_release()
(bsc#1231912).
* CVE-2024-50085: mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow
(bsc#1232508).
* CVE-2024-50142: xfrm: validate new SA's prefixlen using SA family when
sel.family is unset (bsc#1233028).
* CVE-2024-50185:...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2025-856=1 openSUSE-SLE-15.6-2025-856=1
* Basesystem Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-856=1
* Development Tools Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-856=1
* Legacy Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-856=1
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-856=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High Availability Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2025-856=1
* SUSE Linux Enterprise Workstation Extension 15 SP6
zypper in -t...
Read the Full Advisory* openSUSE Leap 15.6 (noarch nosrc)
* kernel-docs-6.4.0-150600.23.42.1
* openSUSE Leap 15.6 (noarch)
* kernel-macros-6.4.0-150600.23.42.1
* kernel-docs-html-6.4.0-150600.23.42.1
* kernel-source-6.4.0-150600.23.42.1
* kernel-devel-6.4.0-150600.23.42.1
* kernel-source-vanilla-6.4.0-150600.23.42.1
* openSUSE Leap 15.6 (nosrc ppc64le x86_64)
* kernel-debug-6.4.0-150600.23.42.2
* openSUSE Leap 15.6 (ppc64le x86_64)
* kernel-debug-debuginfo-6.4.0-150600.23.42.2
* kernel-debug-devel-debuginfo-6.4.0-150600.23.42.2
* kernel-debug-debugsource-6.4.0-150600.23.42.2
* kernel-debug-devel-6.4.0-150600.23.42.2
* openSUSE Leap 15.6 (x86_64)
* kernel-kvmsmall-vdso-debuginfo-6.4.0-150600.23.42.2
* kernel-kvmsmall-vdso-6.4.0-150600.23.42.2
* kernel-debug-vdso-6.4.0-150600.23.42.2
* kernel-default-vdso-6.4.0-150600.23.42.2
* kernel-default-vdso-debuginfo-6.4.0-150600.23.42.2
* kernel-debug-vdso-debuginfo-6.4.0-150600.23.42.2
* openSUSE Leap 15.6 (aarch64 ppc64le x86_64)
*...
Read the Full Advisory* bsc#1012628
* bsc#1215199
* bsc#1219367
* bsc#1222672
* bsc#1222803
* bsc#1225606
* bsc#1225742
* bsc#1225981
* bsc#1227937
* bsc#1228521
* bsc#1230235
* bsc#1230438
* bsc#1230439
* bsc#1230497
* bsc#1231432
* bsc#1231912
* bsc#1231920
* bsc#1231949
* bsc#1232159
* bsc#1232198
* bsc#1232201
* bsc#1232299
* bsc#1232508
* bsc#1232520
* bsc#1232919
* bsc#1233028
* bsc#1233109
* bsc#1233483
* bsc#1233749
* bsc#1234070
* bsc#1234853
* bsc#1234857
* bsc#1234891
* bsc#1234894
* bsc#1234895
* bsc#1234896
* bsc#1234963
* bsc#1235032
* bsc#1235054
* bsc#1235061
* bsc#1235073
* bsc#1235435
* bsc#1235485
* bsc#1235592
* bsc#1235599
* bsc#1235609
* bsc#1235932
* bsc#1235933
* bsc#1236113
* bsc#1236114
* bsc#1236115
* bsc#1236122
* bsc#1236123
* bsc#1236133
* bsc#1236138
* bsc#1236199
* bsc#1236200
* bsc#1236203
* bsc#1236205
* bsc#1236573
* bsc#1236575
* bsc#1236576
* bsc#1236591
* bsc#1236661
* bsc#1236677
* bsc#1236681
* bsc#1236682
* bsc#1236684
* bsc#1236689
* bsc#1236700
* bsc#1236702
* bsc#1236752
* bsc#1236759
* bsc#1236821
* bsc#1236822
* bsc#1236896
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.