Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2024:2365-1 Important: Kernel Security Enhancements

suse
Calendar Grey July 9, 2024
Scroller Suse
Stay informed regarding vital enhancements for the Linux Kernel that tackle various security vulnerabilities in alignment with SUSE-SU-2024:2365-1.
* bsc#1171988 * bsc#1191958 * bsc#1195065 * bsc#1195254 * bsc#1202623

Summary

## The SUSE Linux Enterprise 15 SP2 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2021-47247: net/mlx5e: Fix use-after-free of encap entry in neigh update handler (bsc#1224865). * CVE-2021-47311: net: qcom/emac: fix UAF in emac_remove (bsc#1225010). * CVE-2021-47368: enetc: Fix illegal access when reading affinity_hint (bsc#1225161). * CVE-2021-47372: net: macb: fix use after free on rmmod (bsc#1225184). * CVE-2021-47379: blk-cgroup: fix UAF by grabbing blkcg lock before destroying blkg pd (bsc#1225203). * CVE-2021-47571: staging: rtl8192e: Fix use after free in _rtl92e_pci_disconnect() (bsc#1225518). * CVE-2022-2938: psi: Fix uaf issue when psi trigger is destroyed while being polled (bsc#1202623).

References

* bsc#1171988

* bsc#1191958

* bsc#1195065

* bsc#1195254

* bsc#1202623

* bsc#1218148

* bsc#1219224

* bsc#1222015

* bsc#1223138

* bsc#1223384

* bsc#1224671

* bsc#1224703

* bsc#1224749

* bsc#1224764

* bsc#1224765

* bsc#1224766

* bsc#1224865

* bsc#1225010

* bsc#1225047

* bsc#1225109

* bsc#1225161

* bsc#1225184

* bsc#1225203

* bsc#1225487

* bsc#1225518

* bsc#1225611

* bsc#1225732

* bsc#1225749

* bsc#1225840

* bsc#1225866

* bsc#1226563

* bsc#1226587

* bsc#1226595

* bsc#1226670

* bsc#1226672

* bsc#1226712

* bsc#1226732

* bsc#1226758

* bsc#1226786

* bsc#1226962

Cross-

* CVE-2020-10135

* CVE-2021-3896

* CVE-2021-43389

* CVE-2021-4439

* CVE-2021-47247

* CVE-2021-47311

* CVE-2021-47328

* CVE-2021-47368

* CVE-2021-47372

* CVE-2021-47379

* CVE-2021-47571

* CVE-2021-47583

* CVE-2022-0435

* CVE-2022-22942

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:2365-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.