* bsc#1226324 * bsc#1229553 * bsc#1232637 * bsc#1233712 . # Security update for the Linux Kernel (Live Patch 47 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:0245-1 Release Date: 2025-01-27T12:03:58Z Rating: important References: * bsc#1226324 * bsc#1229553 * bsc#1232637 * bsc#1233712 Cross-References: * CVE-2022-48956 * CVE-2024-36971 * CVE-2024-43861 * CVE-2024-50264 CVSS scores: * CVE-2022-48956 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48956 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36971 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36971 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-43861 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-43861 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves four vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_170 fixes several issues. The following security issues were fixed: * CVE-2024-36971: Fixed __dst_negative_advice() race (bsc#1226324). * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (bsc#1233712). * CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1232637). * CVE-2024-43861: Fix memory leak for not ip packets (bsc#1229553). ## Patch Instructions: To install thisSUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-245=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-245=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_170-default-4-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_170-default-debuginfo-4-150300.7.6.1 * kernel-livepatch-SLE15-SP3_Update_47-debugsource-4-150300.7.6.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_170-preempt-4-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_170-preempt-debuginfo-4-150300.7.6.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_170-default-4-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_170-default-debuginfo-4-150300.7.6.1 * kernel-livepatch-SLE15-SP3_Update_47-debugsource-4-150300.7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48956.html * https://www.suse.com/security/cve/CVE-2024-36971.html * https://www.suse.com/security/cve/CVE-2024-43861.html * https://www.suse.com/security/cve/CVE-2024-50264.html * https://bugzilla.suse.com/show_bug.cgi?id=1226324 * https://bugzilla.suse.com/show_bug.cgi?id=1229553 * https://bugzilla.suse.com/show_bug.cgi?id=1232637 * https://bugzilla.suse.com/show_bug.cgi?id=1233712 . SUSE Linux Kernel security patch released, tackling severe vulnerabilities with Live Patch 47 providing essential fixes.. SUSE Linux Kernel, live patch updates, security patching. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for bluez ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2291-1 Rating: moderate References: #1186463 Cross-References: CVE-2020-26558 CVE-2021-0129 CVSS scores: CVE-2020-26558 (NVD) : 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVE-2020-26558 (SUSE): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVE-2021-0129 (NVD) : 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-0129 (SUSE): 6.4 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP3 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for bluez fixes the following issues: - CVE-2021-0129,CVE-2020-26558: Check bluetooth security flags (bsc#1186463). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-WE-15-SP3-2021-2291=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP3-2021-2291=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-2291=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP3 (x86_64): bluez-cups-5.55-3.3.1 bluez-cups-debuginfo-5.55-3.3.1 bluez-debuginfo-5.55-3.3.1 bluez-debugsource-5.55-3.3.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (aarch64 ppc64le s390x x86_64): bluez-debuginfo-5.55-3.3.1 bluez-debugsource-5.55-3.3.1 bluez-devel-5.55-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): bluez-5.55-3.3.1 bluez-debuginfo-5.55-3.3.1 bluez-debugsource-5.55-3.3.1 libbluetooth3-5.55-3.3.1 libbluetooth3-debuginfo-5.55-3.3.1 References: https://www.suse.com/security/cve/CVE-2020-26558.html https://www.suse.com/security/cve/CVE-2021-0129.html https://bugzilla.suse.com/1186463 . Ubuntu Security Patch resolves several moderate flaws in OpenSSH, boosting system safety for its users.. SUSE Security Update, Bluez Vulnerabilities, Linux Enterprise Patch. . LinuxSecurity.com Team
An update that solves one vulnerability and has two fixes is now available. . SUSE Security Update: Security update for qemu ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1502-1 Rating: moderate References: #1158880 #1167816 #1170940 Cross-References: CVE-2020-1983 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for qemu fixes the following issues: Security issue fixed: - CVE-2020-1983: Fixed a use-after-free in the ip_reass function of slirp (bsc#1170940). Non-security issues fixed: - Fixed an issue where limiting the memory bandwidth was not possible (bsc#1167816). - Fixed the issue that s390x could not read IPL channel program when using dasd as boot device (bsc#1158880). - Miscellaneous fixes to the in-package support documentation. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2020-1502=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-1502=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP1 (aarch64 ppc64le s390x x86_64): qemu-3.1.1.1-9.21.4 qemu-block-curl-3.1.1.1-9.21.4 qemu-block-curl-debuginfo-3.1.1.1-9.21.4 qemu-block-iscsi-3.1.1.1-9.21.4 qemu-block-iscsi-debuginfo-3.1.1.1-9.21.4 qemu-block-rbd-3.1.1.1-9.21.4 qemu-block-rbd-debuginfo-3.1.1.1-9.21.4 qemu-block-ssh-3.1.1.1-9.21.4 qemu-block-ssh-debuginfo-3.1.1.1-9.21.4 qemu-debuginfo-3.1.1.1-9.21.4 qemu-debugsource-3.1.1.1-9.21.4 qemu-guest-agent-3.1.1.1-9.21.4 qemu-guest-agent-debuginfo-3.1.1.1-9.21.4 qemu-lang-3.1.1.1-9.21.4 - SUSE Linux Enterprise Module for Server Applications 15-SP1 (s390x x86_64): qemu-kvm-3.1.1.1-9.21.4 - SUSE Linux Enterprise Module for Server Applications 15-SP1 (aarch64): qemu-arm-3.1.1.1-9.21.4 qemu-arm-debuginfo-3.1.1.1-9.21.4 - SUSE Linux Enterprise Module for Server Applications 15-SP1 (ppc64le): qemu-ppc-3.1.1.1-9.21.4 qemu-ppc-debuginfo-3.1.1.1-9.21.4 - SUSE Linux Enterprise Module for Server Applications 15-SP1 (noarch): qemu-ipxe-1.0.0+-9.21.4 qemu-seabios-1.12.0-9.21.4 qemu-sgabios-8-9.21.4 qemu-vgabios-1.12.0-9.21.4 - SUSE Linux Enterprise Module for Server Applications 15-SP1 (x86_64): qemu-audio-alsa-3.1.1.1-9.21.4 qemu-audio-alsa-debuginfo-3.1.1.1-9.21.4 qemu-audio-oss-3.1.1.1-9.21.4 qemu-audio-oss-debuginfo-3.1.1.1-9.21.4 qemu-audio-pa-3.1.1.1-9.21.4 qemu-audio-pa-debuginfo-3.1.1.1-9.21.4 qemu-ui-curses-3.1.1.1-9.21.4 qemu-ui-curses-debuginfo-3.1.1.1-9.21.4 qemu-ui-gtk-3.1.1.1-9.21.4 qemu-ui-gtk-debuginfo-3.1.1.1-9.21.4 qemu-x86-3.1.1.1-9.21.4 qemu-x86-debuginfo-3.1.1.1-9.21.4 - SUSE Linux Enterprise Module for Server Applications 15-SP1 (s390x): qemu-s390-3.1.1.1-9.21.4 qemu-s390-debuginfo-3.1.1.1-9.21.4 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): qemu-debuginfo-3.1.1.1-9.21.4 qemu-debugsource-3.1.1.1-9.21.4 qemu-tools-3.1.1.1-9.21.4 qemu-tools-debuginfo-3.1.1.1-9.21.4 References: https://www.suse.com/security/cve/CVE-2020-1983.html https://bugzilla.suse.com/1158880 https://bugzilla.suse.com/1167816 https://bugzilla.suse.com/1170940 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.