## The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2017-14051: scsi/qla2xxx: Fix an integer overflow in sysfs code. (bsc#1056588) * CVE-2024-53146: NFSD: Prevent a potential integer overflow (bsc#1234853). * CVE-2024-53156: wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() (bsc#1234846). * CVE-2024-53173: NFSv4.0: Fix a use-after-free problem in the asynchronous open() (bsc#1234891). * CVE-2024-53239: ALSA: 6fire: Release resources at card release (bsc#1235054). * CVE-2024-56539: wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan() (bsc#1234963). * CVE-2024-56548: hfsplus: do not query the device logical block size multiple times (bsc#1235073).
* bsc#1027565
* bsc#1056588
* bsc#1059525
* bsc#1202346
* bsc#1227985
* bsc#1234846
* bsc#1234853
* bsc#1234891
* bsc#1234963
* bsc#1235054
* bsc#1235056
* bsc#1235061
* bsc#1235073
* bsc#1235220
* bsc#1235224
Cross-
* CVE-2017-1000253
* CVE-2017-14051
* CVE-2017-2636
* CVE-2022-20368
* CVE-2022-48839
* CVE-2024-53146
* CVE-2024-53156
* CVE-2024-53173
* CVE-2024-53239
* CVE-2024-56539
* CVE-2024-56548
* CVE-2024-56598
* CVE-2024-56604
* CVE-2024-56605
* CVE-2024-56619
CVSS scores:
* CVE-2017-1000253 ( SUSE ): 8.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2017-1000253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2017-1000253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Get the latest Linux and open source security news straight to your inbox.