Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE Linux 15 SP6: 2025:0265-1 important: kernel live patch security fixes

suse
Calendar Grey January 27, 2025
Dist Suse Esm H88
Important security patch released for SUSE Linux Kernel rectifying various vulnerabilities and enhancing overall system reliability.
* bsc#1225819 * bsc#1227369 * bsc#1227781 * bsc#1227784 * bsc#1228349

Summary

## This update for the Linux Kernel 6.4.0-150600_23_17 fixes several issues. The following security issues were fixed: * CVE-2024-40921: net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state (bsc#1227784). * CVE-2024-40920: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state (bsc#1227781). * CVE-2024-36979: net: bridge: mst: fix vlan use-after-free (bsc#1227369). * CVE-2024-41057: cachefiles: fix slab-use-after-free in cachefiles_withdraw_cookie() (bsc#1229275). * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans (bsc#1233712). * CVE-2024-43861: Fix memory leak for not ip packets (bsc#1229553). * CVE-2024-35949: btrfs: make sure that WRITTEN is set on all metadata blocks (bsc#1229273).

References

* bsc#1225819

* bsc#1227369

* bsc#1227781

* bsc#1227784

* bsc#1228349

* bsc#1228786

* bsc#1229273

* bsc#1229275

* bsc#1229553

* bsc#1233712

Cross-

* CVE-2023-52752

* CVE-2024-35949

* CVE-2024-36979

* CVE-2024-40909

* CVE-2024-40920

* CVE-2024-40921

* CVE-2024-40954

* CVE-2024-41057

* CVE-2024-43861

* CVE-2024-50264

CVSS scores:

* CVE-2023-52752 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

* CVE-2023-52752 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-35949 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-36979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-36979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-40909 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:0265-1
Release Date: 2025-01-27T16:33:31Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here