The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2024-2201: Fixed information leak in x86/BHI (bsc#1217339).
* CVE-2024-41092: drm/i915/gt: Fix potential UAF by revoke of fence registers
(bsc#1228483).
* CVE-2024-42098: crypto: ecdh - explicitly zeroize private_key (bsc#1228779).
* CVE-2024-42229: crypto: aead,cipher - zeroize key buffer after use
(bsc#1228708).
* CVE-2024-57996: net_sched: sch_sfq: do not allow 1 packet limit
(bsc#1239076).
* CVE-2024-58014: wifi: brcmsmac: add gain range check to
wlc_phy_iqcal_gainparams_nphy() (bsc#1239109).
* CVE-2025-21718: net: rose: fix timer races against user threads
(bsc#1239073).
* CVE-2025-21780: drm/amdgpu: avoid buffer overflow attach in
smu_sys_set_pp_table() (bsc#1239115).
The following non-security bugs were fixed:
* initcall_blacklist: Does not allow kernel_lockdown be blacklisted
(bsc#1237521).
...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Manager Server 4.3
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-1027=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-1027=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-1027=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-1027=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-1027=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-1027=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2025-1027=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High...
Read the Full Advisory* SUSE Manager Server 4.3 (nosrc ppc64le s390x x86_64)
* kernel-default-5.14.21-150400.24.158.1
* SUSE Manager Server 4.3 (ppc64le x86_64)
* kernel-default-base-5.14.21-150400.24.158.1.150400.24.78.1
* SUSE Manager Server 4.3 (ppc64le s390x x86_64)
* kernel-default-devel-debuginfo-5.14.21-150400.24.158.1
* kernel-default-debuginfo-5.14.21-150400.24.158.1
* kernel-default-devel-5.14.21-150400.24.158.1
* kernel-default-debugsource-5.14.21-150400.24.158.1
* kernel-syms-5.14.21-150400.24.158.1
* SUSE Manager Server 4.3 (noarch)
* kernel-devel-5.14.21-150400.24.158.1
* kernel-macros-5.14.21-150400.24.158.1
* kernel-source-5.14.21-150400.24.158.1
* SUSE Manager Server 4.3 (nosrc s390x)
* kernel-zfcpdump-5.14.21-150400.24.158.1
* SUSE Manager Server 4.3 (s390x)
* kernel-zfcpdump-debugsource-5.14.21-150400.24.158.1
* kernel-zfcpdump-debuginfo-5.14.21-150400.24.158.1
* openSUSE Leap 15.4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.158.1
* openSUSE Leap 15.4 (noarch)
* kernel-devel-5.14.21-150400.24.158.1
*...
Read the Full Advisory* bsc#1065729
* bsc#1180814
* bsc#1183682
* bsc#1190336
* bsc#1190768
* bsc#1190786
* bsc#1193629
* bsc#1194869
* bsc#1194904
* bsc#1195823
* bsc#1196444
* bsc#1197158
* bsc#1197174
* bsc#1197246
* bsc#1197302
* bsc#1197331
* bsc#1197472
* bsc#1197661
* bsc#1197926
* bsc#1198019
* bsc#1198021
* bsc#1198240
* bsc#1198577
* bsc#1198660
* bsc#1199657
* bsc#1200045
* bsc#1200571
* bsc#1200807
* bsc#1200809
* bsc#1200810
* bsc#1200824
* bsc#1200825
* bsc#1200871
* bsc#1200872
* bsc#1201193
* bsc#1201218
* bsc#1201323
* bsc#1201381
* bsc#1201610
* bsc#1202672
* bsc#1202711
* bsc#1202712
* bsc#1202771
* bsc#1202774
* bsc#1202778
* bsc#1202781
* bsc#1203699
* bsc#1203769
* bsc#1204171
* bsc#1206048
* bsc#1206049
* bsc#1207593
* bsc#1207640
* bsc#1210050
* bsc#1211263
* bsc#1217339
* bsc#1228483
* bsc#1228708
* bsc#1228779
* bsc#1228966
* bsc#1237521
* bsc#1237718
* bsc#1237721
* bsc#1237722
* bsc#1237723
* bsc#1237724
* bsc#1237725
* bsc#1237726
* bsc#1237727
* bsc#1237728
* bsc#1237729
* bsc#1237734
* bsc#1237735
* bsc#1237736
* bsc#1237737
* bsc#1237738
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.