Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1235008 * bsc#1235431 Cross-References: * CVE-2024-53237 . # Security update for kernel-livepatch-MICRO-6-0_Update_4 Announcement ID: SUSE-SU-2025:20315-1 Release Date: 2025-04-29T11:22:27Z Rating: moderate References: * bsc#1235008 * bsc#1235431 Cross-References: * CVE-2024-53237 * CVE-2024-56650 CVSS scores: * CVE-2024-53237 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53237 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53237 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53237 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56650 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56650 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56650 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_4 fixes the following issues: * CVE-2024-53237: Fixed bluetooth: fix use-after-free in device_for_each_child() (bsc#1235008) * CVE-2024-56650: Fixed netfilter: x_tables: fix LED ID check in led_tg_check() (bsc#1235431) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-20=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-24-default-3-1.2 * kernel-livepatch-MICRO-6-0_Update_4-debugsource-3-1.2 * kernel-livepatch-6_4_0-24-default-debuginfo-3-1.2 ## References: * https://www.suse.com/security/cve/CVE-2024-53237.html * https://www.suse.com/security/cve/CVE-2024-56650.html *https://bugzilla.suse.com/show_bug.cgi?id=1235008 * https://bugzilla.suse.com/show_bug.cgi?id=1235431 . Enhance security by updating SUSE Linux Micro 6.1 to address critical vulnerabilities in Bluetooth and netfilter components, ensuring system integrity. SUSE Linux, kernel patch, bluetooth security, netfilter security. . LinuxSecurity.com Team
The 6.8.5 stable kernel update contains a number of important fixes across the tree. . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-6d35739db7 2024-04-13 03:40:51.150308 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 40 Version : 6.8.5 Release : 301.fc40 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.8.5 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 11 2024 Justin M. Forbes [6.8.5-301] - nouveau: fix devinit paths to only handle display on GSP. (Dave Airlie) - Add bluetooth bug to Bugsfixed for 6.8.6 (Justin M. Forbes) - Bluetooth: l2cap: Don't double set the HCI_CONN_MGMT_CONNECTED bit (Archie Pusaka) * Wed Apr 10 2024 Justin M. Forbes [6.8.5-0] - Set configs for SPECTRE_BHI (Justin M. Forbes) - Add AMD PMF bug (Justin M. Forbes) - redhat/configs: Enable CONFIG_AMDTEE for x86 (David Arcari) - Add CVE fix for 6.8.5 (Justin M. Forbes) - Linux v6.8.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2273968 - CVE-2024-26811 kernel: ksmbd: validate payload size in ipc response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2273968 [ 2 ] Bug #2274047 - Bluetooth headset partially connects under some circumstances with blues 5.73-3.fc40.x86_64 https://bugzilla.redhat.com/show_bug.cgi?id=2274047 [ 3 ] Bug #2274069 - AMD-PMF driver fails to load on kernel- 6.8.4-300.fc40.x86_64. Resulting in GPU failing to use full gpu available watts. https://bugzilla.redhat.com/show_bug.cgi?id=2274069 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-6d35739db7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 6.7.9 stable kernel update contains a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5db5954a5e 2024-03-13 01:47:46.880728 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 38 Version : 6.7.9 Release : 100.fc38 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.7.9 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 6 2024 Augusto Caringi [6.7.9-0] - Add some CVE fixes for 6.7.9 (Justin M. Forbes) - Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security (Yuxuan Hu) - Linux v6.7.9 * Sun Mar 3 2024 Justin M. Forbes [6.7.8-0] - Linux v6.7.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2267701 - CVE-2024-22099 kernel: NULL Pointer dereference bluetooth allows Overflow Buffers https://bugzilla.redhat.com/show_bug.cgi?id=2267701 [ 2 ] Bug #2267721 - CVE-2024-26622 kernel: tomoyo: fix UAF write bug in tomoyo_write_control() https://bugzilla.redhat.com/show_bug.cgi?id=2267721 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5db5954a5e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 6.7.9 stable kernel update contains a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-f797f1540e 2024-03-13 01:22:43.441080 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 39 Version : 6.7.9 Release : 200.fc39 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.7.9 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 6 2024 Augusto Caringi [6.7.9-0] - Add some CVE fixes for 6.7.9 (Justin M. Forbes) - Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security (Yuxuan Hu) - Linux v6.7.9 * Sun Mar 3 2024 Justin M. Forbes [6.7.8-0] - Linux v6.7.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2267701 - CVE-2024-22099 kernel: NULL Pointer dereference bluetooth allows Overflow Buffers https://bugzilla.redhat.com/show_bug.cgi?id=2267701 [ 2 ] Bug #2267721 - CVE-2024-26622 kernel: tomoyo: fix UAF write bug in tomoyo_write_control() https://bugzilla.redhat.com/show_bug.cgi?id=2267721 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f797f1540e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5809-1 January 17, 2023 linux-oem-5.14 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-oem-5.14: Linux kernel for OEM systems Details: Kyle Zeng discovered that the sysctl implementation in the Linux kernel contained a stack-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-4378) Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation in the Linux kernel contained multiple use-after-free vulnerabilities. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-42896) It was discovered that an integer overflow vulnerability existed in the Bluetooth subsystem in the Linux kernel. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2022-45934) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.14.0-1056-oem 5.14.0-1056.63 linux-image-oem-20.04 5.14.0.1056.54 linux-image-oem-20.04b 5.14.0.1056.54 linux-image-oem-20.04c 5.14.0.1056.54 linux-image-oem-20.04d 5.14.0.1056.54 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled thestandard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5809-1 CVE-2022-42896, CVE-2022-4378, CVE-2022-45934 Package Information: https://launchpad.net/ubuntu/+source/linux-oem-5.14/5.14.0-1056.63 . Ubuntu 20.04 LTS receives critical patches addressing OEM kernel vulnerabilities, such as potential denial of service and risks of arbitrary code execution.. Ubuntu Security Updates, Linux Kernel Threats, OEM Kernel Issues. . Severity: Critical. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3751-1 Rating: important References: #1190432 #1192042 Cross-References: CVE-2021-0935 CVE-2021-3752 CVSS scores: CVE-2021-0935 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-3752 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server 12-SP3-LTSS ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 4.4.180-94_141 fixes several issues. The following security issues were fixed: - CVE-2021-0935: Fixed use after free that could lead to local escalation of privilege in ip6_xmit of ip6_output.c (bsc#1192042). - CVE-2021-3752: Fixed vulnerability in the linux kernel Bluetooth uaf module (bsc#1190432). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-3749=1 SUSE-SLE-SAP-12-SP3-2021-3750=1 SUSE-SLE-SAP-12-SP3-2021-3751=1 SUSE-SLE-SAP-12-SP3-2021-3752=1 SUSE-SLE-SAP-12-SP3-2021-3753=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-3749=1 SUSE-SLE-SERVER-12-SP3-2021-3750=1 SUSE-SLE-SERVER-12-SP3-2021-3751=1 SUSE-SLE-SERVER-12-SP3-2021-3752=1 SUSE-SLE-SERVER-12-SP3-2021-3753=1 Package List: - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): kgraft-patch-4_4_180-94_135-default-14-2.2 kgraft-patch-4_4_180-94_135-default-debuginfo-14-2.2 kgraft-patch-4_4_180-94_138-default-12-2.2 kgraft-patch-4_4_180-94_138-default-debuginfo-12-2.2 kgraft-patch-4_4_180-94_141-default-11-2.2 kgraft-patch-4_4_180-94_141-default-debuginfo-11-2.2 kgraft-patch-4_4_180-94_144-default-8-2.2 kgraft-patch-4_4_180-94_144-default-debuginfo-8-2.2 kgraft-patch-4_4_180-94_147-default-5-2.2 kgraft-patch-4_4_180-94_147-default-debuginfo-5-2.2 - SUSE Linux Enterprise Server 12-SP3-LTSS (ppc64le x86_64): kgraft-patch-4_4_180-94_135-default-14-2.2 kgraft-patch-4_4_180-94_135-default-debuginfo-14-2.2 kgraft-patch-4_4_180-94_138-default-12-2.2 kgraft-patch-4_4_180-94_138-default-debuginfo-12-2.2 kgraft-patch-4_4_180-94_141-default-11-2.2 kgraft-patch-4_4_180-94_141-default-debuginfo-11-2.2 kgraft-patch-4_4_180-94_144-default-8-2.2 kgraft-patch-4_4_180-94_144-default-debuginfo-8-2.2 kgraft-patch-4_4_180-94_147-default-5-2.2 kgraft-patch-4_4_180-94_147-default-debuginfo-5-2.2 References: https://www.suse.com/security/cve/CVE-2021-0935.html https://www.suse.com/security/cve/CVE-2021-3752.html https://bugzilla.suse.com/1190432 https://bugzilla.suse.com/1192042 . This enhancement targets critical vulnerabilities within the Linux Kernel for Ubuntu, guaranteeing operational reliability and safeguarding data.. Linux Kernel Security,SUSE Live Patch,Important Update,Bluetooth Fix,Escalation Resolution. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5044-1 August 18, 2021 linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems - linux-gcp-4.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi2: Linux kernel for Raspberry Pi (V8) systems - linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors- linux-aws-hwe: Linux kernel for Amazon Web Services (AWS-HWE) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe: Linux hardware enablement (HWE) kernel - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: It was discovered that the bluetooth subsystem in the Linux kernel did not properly handle HCI device initialization failure, leading to a double-free vulnerability. An attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2021-3564) It was discovered that the bluetooth subsystem in the Linux kernel did not properly handle HCI device detach events, leading to a use-after-free vulnerability. An attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2021-3573) It was discovered that the NFC implementation in the Linux kernel did not properly handle failed connect events leading to a NULLpointer dereference. A local attacker could use this to cause a denial of service. (CVE-2021-3587) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-4.15.0-1079-oracle 4.15.0-1079.87 linux-image-4.15.0-1094-raspi2 4.15.0-1094.100 linux-image-4.15.0-1098-kvm 4.15.0-1098.100 linux-image-4.15.0-1107-gcp 4.15.0-1107.121 linux-image-4.15.0-1110-aws 4.15.0-1110.117 linux-image-4.15.0-1111-snapdragon 4.15.0-1111.120 linux-image-4.15.0-1122-azure 4.15.0-1122.135 linux-image-4.15.0-154-generic 4.15.0-154.161 linux-image-4.15.0-154-generic-lpae 4.15.0-154.161 linux-image-4.15.0-154-lowlatency 4.15.0-154.161 linux-image-aws-lts-18.04 4.15.0.1110.113 linux-image-azure-lts-18.04 4.15.0.1122.95 linux-image-gcp-lts-18.04 4.15.0.1107.126 linux-image-generic 4.15.0.154.143 linux-image-generic-lpae 4.15.0.154.143 linux-image-kvm 4.15.0.1098.94 linux-image-lowlatency 4.15.0.154.143 linux-image-oracle-lts-18.04 4.15.0.1079.89 linux-image-raspi2 4.15.0.1094.92 linux-image-snapdragon 4.15.0.1111.114 linux-image-virtual 4.15.0.154.143 Ubuntu 16.04 ESM: linux-image-4.15.0-1107-gcp 4.15.0-1107.121~16.04.1 linux-image-4.15.0-1110-aws 4.15.0-1110.117~16.04.1 linux-image-4.15.0-154-generic 4.15.0-154.161~16.04.1 linux-image-4.15.0-154-lowlatency 4.15.0-154.161~16.04.1 linux-image-aws-hwe 4.15.0.1110.101 linux-image-gcp 4.15.0.1107.108 linux-image-generic-hwe-16.04 4.15.0.154.148 linux-image-gke 4.15.0.1107.108 linux-image-lowlatency-hwe-16.04 4.15.0.154.148 linux-image-oem 4.15.0.154.148 linux-image-virtual-hwe-16.04 4.15.0.154.148 Ubuntu 14.04 ESM: linux-image-4.15.0-1122-azure 4.15.0-1122.135~14.04.1 linux-image-azure 4.15.0.1122.95 After a standard system update you needto reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5044-1 CVE-2021-3564, CVE-2021-3573, CVE-2021-3587 Package Information: https://launchpad.net/ubuntu/+source/linux/4.15.0-154.161 https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1110.117 https://launchpad.net/ubuntu/+source/linux-azure-4.15/4.15.0-1122.135 https://launchpad.net/ubuntu/+source/linux-gcp-4.15/4.15.0-1107.121 https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1098.100 https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1079.87 https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1094.100 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1111.120 . Crucial Linux kernel patch for Ubuntu resolves vulnerabilities linked to denial of service via Bluetooth and NFC connections. Essential update.. Linux Kernel Update, Ubuntu Security Notice, Bluetooth Vulnerability, NFC Issues. . Severity: Critical. LinuxSecurity.com Team
KDE Plasma 5.21.3 release. ---- Fix for CVE-2021-28117. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-85c9774673 2021-03-20 00:16:30.596946 --------------------------------------------------------------------------------Name : bluedevil Product : Fedora 34 Version : 5.21.3 Release : 1.fc34 URL : Summary : Bluetooth stack for KDE Description : BlueDevil is the bluetooth stack for KDE. --------------------------------------------------------------------------------Update Information: KDE Plasma 5.21.3 release. ---- Fix for CVE-2021-28117 --------------------------------------------------------------------------------ChangeLog: * Tue Mar 16 2021 Jan Grulich - 5.21.3-1 - 5.21.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1937887 - CVE-2021-28117 plasma-discover: missing URI scheme validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1937887 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-85c9774673' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.