Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1230697 * bsc#1231847 * bsc#1233112 * bsc#1233642 * bsc#1234025 . # Security update for the Linux Kernel Announcement ID: SUSE-SU-2025:0555-1 Release Date: 2025-02-14T15:25:28Z Rating: important References: * bsc#1230697 * bsc#1231847 * bsc#1233112 * bsc#1233642 * bsc#1234025 * bsc#1234690 * bsc#1234884 * bsc#1234896 * bsc#1234931 * bsc#1235134 * bsc#1235217 * bsc#1235230 * bsc#1235249 * bsc#1235430 * bsc#1235433 * bsc#1235441 * bsc#1235451 * bsc#1235466 * bsc#1235480 * bsc#1235521 * bsc#1235584 * bsc#1235645 * bsc#1235723 * bsc#1235759 * bsc#1235764 * bsc#1235814 * bsc#1235818 * bsc#1235920 * bsc#1235969 * bsc#1236628 Cross-References: * CVE-2024-50199 * CVE-2024-53095 * CVE-2024-53104 * CVE-2024-53144 * CVE-2024-53166 * CVE-2024-53177 * CVE-2024-54680 * CVE-2024-56600 * CVE-2024-56601 * CVE-2024-56602 * CVE-2024-56623 * CVE-2024-56631 * CVE-2024-56642 * CVE-2024-56645 * CVE-2024-56648 * CVE-2024-56650 * CVE-2024-56658 * CVE-2024-56661 * CVE-2024-56664 * CVE-2024-56704 * CVE-2024-56759 * CVE-2024-57791 * CVE-2024-57792 * CVE-2024-57798 * CVE-2024-57849 * CVE-2024-57893 * CVE-2024-57897 * CVE-2024-8805 CVSS scores: * CVE-2024-50199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53095 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53095 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53166 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53166 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53166 ( NVD ): 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53166 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53177 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53177 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53177 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-54680 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-54680 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-54680 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-54680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56600 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56601 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56601 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56601 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56601 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56602 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56602 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56602 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56602 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56623 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56623 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56631 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56631 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56631 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56631 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56642 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56642 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56642 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56642 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56645 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56645 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56648 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56648 ( SUSE ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56648 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56650 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56650 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56650 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-56658 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56658 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56658 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56661 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-56661 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56661 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56664 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56664 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H *CVE-2024-56664 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56704 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-56704 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56704 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56759 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56759 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-57791 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-57791 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57792 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-57792 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-57798 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-57798 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-57798 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-57849 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-57849 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-57893 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-57893 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-57897 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-57897 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8805 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-8805 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-8805 ( NVD ): 8.8CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves 28 vulnerabilities and has two security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2024-50199: mm/swapfile: skip HugeTLB pages for unuse_vma (bsc#1233112). * CVE-2024-53104: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (bsc#1234025). * CVE-2024-53166: block, bfq: fix bfqq uaf in bfq_limit_depth() (bsc#1234884). * CVE-2024-53177: smb: prevent use-after-free due to open_cached_dir error paths (bsc#1234896). * CVE-2024-56600: net: inet6: do not leave a dangling sk pointer in inet6_create() (bsc#1235217). * CVE-2024-56601: net: inet: do not leave a dangling sk pointer in inet_create() (bsc#1235230). * CVE-2024-56602: net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() (bsc#1235521). * CVE-2024-56623: scsi: qla2xxx: Fix use after free on unload (bsc#1235466). * CVE-2024-56631: scsi: sg: Fix slab-use-after-free read in sg_release() (bsc#1235480). * CVE-2024-56642: tipc: Fix use-after-free of kernel socket in cleanup_bearer() (bsc#1235433). * CVE-2024-56645: can: j1939: j1939_session_new(): fix skb reference counting (bsc#1235134). * CVE-2024-56648: net: hsr: avoid potential out-of-bound access in fill_frame_info() (bsc#1235451). * CVE-2024-56650: netfilter: x_tables: fix LED ID check in led_tg_check() (bsc#1235430). * CVE-2024-56658: net: defer final 'struct net' free in netns dismantle (bsc#1235441). * CVE-2024-56664: bpf, sockmap: Fix race between element replace and close() (bsc#1235249). * CVE-2024-56704: 9p/xen: fix release of IRQ (bsc#1235584). * CVE-2024-56759: btrfs:fix use-after-free when COWing tree bock and tracing is enabled (bsc#1235645). * CVE-2024-57791: net/smc: check return value of sock_recvmsg when draining clc data (bsc#1235759). * CVE-2024-57792: power: supply: gpio-charger: Fix set charge current limits (bsc#1235764). * CVE-2024-57798: drm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req() (bsc#1235818). * CVE-2024-57849: s390/cpum_sf: Handle CPU hotplug remove during sampling (bsc#1235814). * CVE-2024-57893: ALSA: seq: oss: Fix races at processing SysEx messages (bsc#1235920). * CVE-2024-57897: drm/amdkfd: Correct the migration DMA map direction (bsc#1235969). The following non-security bugs were fixed: * NFS: Adjust the amount of readahead performed by NFS readdir (bsc#1231847). * NFS: Do not flush the readdir cache in nfs_dentry_iput() (bsc#1231847). * NFS: Improve heuristic for readdirplus (bsc#1231847). * NFS: Trigger the "ls -l" readdir heuristic sooner (bsc#1231847). * tipc: fix NULL deref in cleanup_bearer() (bsc#1235433). * x86/static-call: Remove early_boot_irqs_disabled check to fix Xen PVH dom0 (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-555=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-555=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-555=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-555=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.109.1 * kernel-rt-debugsource-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.109.1 * kernel-rt-debugsource-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.109.1 * kernel-rt-debugsource-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.109.1 * kernel-rt-debugsource-5.14.21-150400.15.109.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.109.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50199.html * https://www.suse.com/security/cve/CVE-2024-53095.html * https://www.suse.com/security/cve/CVE-2024-53104.html * https://www.suse.com/security/cve/CVE-2024-53144.html * https://www.suse.com/security/cve/CVE-2024-53166.html * https://www.suse.com/security/cve/CVE-2024-53177.html * https://www.suse.com/security/cve/CVE-2024-54680.html * https://www.suse.com/security/cve/CVE-2024-56600.html * https://www.suse.com/security/cve/CVE-2024-56601.html * https://www.suse.com/security/cve/CVE-2024-56602.html * https://www.suse.com/security/cve/CVE-2024-56623.html * https://www.suse.com/security/cve/CVE-2024-56631.html * https://www.suse.com/security/cve/CVE-2024-56642.html *https://www.suse.com/security/cve/CVE-2024-56645.html * https://www.suse.com/security/cve/CVE-2024-56648.html * https://www.suse.com/security/cve/CVE-2024-56650.html * https://www.suse.com/security/cve/CVE-2024-56658.html * https://www.suse.com/security/cve/CVE-2024-56661.html * https://www.suse.com/security/cve/CVE-2024-56664.html * https://www.suse.com/security/cve/CVE-2024-56704.html * https://www.suse.com/security/cve/CVE-2024-56759.html * https://www.suse.com/security/cve/CVE-2024-57791.html * https://www.suse.com/security/cve/CVE-2024-57792.html * https://www.suse.com/security/cve/CVE-2024-57798.html * https://www.suse.com/security/cve/CVE-2024-57849.html * https://www.suse.com/security/cve/CVE-2024-57893.html * https://www.suse.com/security/cve/CVE-2024-57897.html * https://www.suse.com/security/cve/CVE-2024-8805.html * https://bugzilla.suse.com/show_bug.cgi?id=1230697 * https://bugzilla.suse.com/show_bug.cgi?id=1231847 * https://bugzilla.suse.com/show_bug.cgi?id=1233112 * https://bugzilla.suse.com/show_bug.cgi?id=1233642 * https://bugzilla.suse.com/show_bug.cgi?id=1234025 * https://bugzilla.suse.com/show_bug.cgi?id=1234690 * https://bugzilla.suse.com/show_bug.cgi?id=1234884 * https://bugzilla.suse.com/show_bug.cgi?id=1234896 * https://bugzilla.suse.com/show_bug.cgi?id=1234931 * https://bugzilla.suse.com/show_bug.cgi?id=1235134 * https://bugzilla.suse.com/show_bug.cgi?id=1235217 * https://bugzilla.suse.com/show_bug.cgi?id=1235230 * https://bugzilla.suse.com/show_bug.cgi?id=1235249 * https://bugzilla.suse.com/show_bug.cgi?id=1235430 * https://bugzilla.suse.com/show_bug.cgi?id=1235433 * https://bugzilla.suse.com/show_bug.cgi?id=1235441 * https://bugzilla.suse.com/show_bug.cgi?id=1235451 * https://bugzilla.suse.com/show_bug.cgi?id=1235466 * https://bugzilla.suse.com/show_bug.cgi?id=1235480 * https://bugzilla.suse.com/show_bug.cgi?id=1235521 * https://bugzilla.suse.com/show_bug.cgi?id=1235584 *https://bugzilla.suse.com/show_bug.cgi?id=1235645 * https://bugzilla.suse.com/show_bug.cgi?id=1235723 * https://bugzilla.suse.com/show_bug.cgi?id=1235759 * https://bugzilla.suse.com/show_bug.cgi?id=1235764 * https://bugzilla.suse.com/show_bug.cgi?id=1235814 * https://bugzilla.suse.com/show_bug.cgi?id=1235818 * https://bugzilla.suse.com/show_bug.cgi?id=1235920 * https://bugzilla.suse.com/show_bug.cgi?id=1235969 * https://bugzilla.suse.com/show_bug.cgi?id=1236628 . Explore key security upgrades in the latest SUSE advisory for the Linux Kernel, detailing essential patches and affected versions to ensure user safety. Linux Kernel Update,SUSE Security Fixes,Kernal Fixes,Security Advisories,Threat Management. . Severity: Important. LinuxSecurity.com Team
* bsc#1050549 * bsc#1186484 * bsc#1200599 * bsc#1212514 * bsc#1213456 . # Security update for the Linux Kernel Announcement ID: SUSE-SU-2024:0925-1 Rating: important References: * bsc#1050549 * bsc#1186484 * bsc#1200599 * bsc#1212514 * bsc#1213456 * bsc#1218450 * bsc#1218527 * bsc#1218915 * bsc#1219127 * bsc#1219146 * bsc#1219295 * bsc#1219653 * bsc#1219827 * bsc#1219835 * bsc#1220187 * bsc#1220238 * bsc#1220240 * bsc#1220241 * bsc#1220250 * bsc#1220330 * bsc#1220340 * bsc#1220344 * bsc#1220409 * bsc#1220421 * bsc#1220436 * bsc#1220444 * bsc#1220459 * bsc#1220468 * bsc#1220482 * bsc#1220526 * bsc#1220570 * bsc#1220575 * bsc#1220599 * bsc#1220607 * bsc#1220613 * bsc#1220638 * bsc#1220641 * bsc#1220649 * bsc#1220700 * bsc#1220735 * bsc#1220767 * bsc#1220796 * bsc#1220825 * bsc#1220831 * bsc#1220845 * bsc#1220860 * bsc#1220861 * bsc#1220863 * bsc#1220870 * bsc#1220930 * bsc#1220931 * bsc#1220932 * bsc#1220957 * bsc#1221039 * bsc#1221040 * bsc#1221287 Cross-References: * CVE-2019-25162 * CVE-2020-36777 * CVE-2020-36784 * CVE-2021-33200 * CVE-2021-46906 * CVE-2021-46915 * CVE-2021-46921 * CVE-2021-46924 * CVE-2021-46929 * CVE-2021-46932 * CVE-2021-46953 * CVE-2021-46974 * CVE-2021-46991 * CVE-2021-46992 * CVE-2021-47013 * CVE-2021-47054 * CVE-2021-47076 * CVE-2021-47077 * CVE-2021-47078 * CVE-2022-20154 * CVE-2022-48627 * CVE-2023-28746 * CVE-2023-35827 * CVE-2023-46343 * CVE-2023-52340 * CVE-2023-52429 * CVE-2023-52443 * CVE-2023-52445 * CVE-2023-52449 * CVE-2023-52451 * CVE-2023-52464 * CVE-2023-52475 * CVE-2023-52478 * CVE-2023-52482 * CVE-2023-52502 * CVE-2023-52530 * CVE-2023-52531 * CVE-2023-52532 * CVE-2023-52574 * CVE-2023-52597 * CVE-2023-52605 * CVE-2024-0607 * CVE-2024-1151 * CVE-2024-23849 * CVE-2024-23851 * CVE-2024-26585 * CVE-2024-26595 * CVE-2024-26600: * CVE-2024-26622 CVSSscores: * CVE-2019-25162 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2020-36777 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2020-36784 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2021-33200 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2021-33200 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2021-46906 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2021-46915 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2021-46921 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2021-46924 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2021-46929 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2021-46932 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2021-46953 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2021-46974 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2021-46991 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2021-46992 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2021-47013 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2021-47054 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2021-47076 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2021-47077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2021-47078 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2022-20154 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-20154 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48627 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2023-35827 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-46343 ( SUSE ): 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-46343 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52340 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52443 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52445 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52449 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52451 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2023-52451 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2023-52475 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52478 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2023-52482 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2023-52502 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52530 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52532 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52574 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52597 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2023-52605 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-0607 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2024-0607 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2024-1151 ( SUSE ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-23849 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-23849 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-23851 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-23851 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-26585 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26585 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-26595 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-26622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 12 SP5 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that solves 49 vulnerabilities and has seven security fixes can now be installed. ## Description: The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2021-47078: Fixed a bug by clearing all QP fields if creation failed (bsc#1220863) * CVE-2021-47076: Fixed a bug by returning CQE error if invalid lkey was supplied (bsc#1220860) * CVE-2023-52605: Fixed a NULL pointer dereference check (bsc#1221039) * CVE-2023-52597: Fixed a setting of fpc register in KVM (bsc#1221040). * CVE-2023-52574: Fixed a bug by hiding new member header_ops (bsc#1220870). * CVE-2023-52482: Fixed a bug by adding SRSO mitigation for Hygon processors (bsc#1220735). * CVE-2022-48627: Fixed a memory overlapping when deleting chars in the buffer (bsc#1220845). * CVE-2023-28746: Fixed Register File Data Sampling (bsc#1213456). * CVE-2021-47077: Fixeda NULL pointer dereference when in shost_data (bsc#1220861). * CVE-2023-35827: Fixed a use-after-free issue in ravb_tx_timeout_work (bsc#1212514). * CVE-2023-52532: Fixed a bug in TX CQE error handling (bsc#1220932). * CVE-2023-52530: Fixed a potential key use-after-free in wifi mac80211 (bsc#1220930). * CVE-2023-52531: Fixed a memory corruption issue in iwlwifi (bsc#1220931). * CVE-2023-52502: Fixed a race condition in nfc_llcp_sock_get and nfc_llcp_sock_get_sn (bsc#1220831). * CVE-2024-26585: Fixed race between tx work scheduling and socket close (bsc#1220187). * CVE-2023-52340: Fixed ICMPv6 âPacket Too Bigâ packets force a DoS of the Linux kernel by forcing 100% CPU (bsc#1219295). * CVE-2024-0607: Fixed 64-bit load issue in nft_byteorder_eval (bsc#1218915). * CVE-2024-26622: Fixed UAF write bug in tomoyo_write_control (bsc#1220825). * CVE-2021-46921: Fixed ordering in queued_write_lock_slowpath (bsc#1220468). * CVE-2021-46932: Fixed missing work initialization before device registration (bsc#1220444) * CVE-2023-52451: Fixed access beyond end of drmem array (bsc#1220250). * CVE-2021-46953: Fixed a corruption in interrupt mappings on watchdow probe failure (bsc#1220599). * CVE-2023-52449: Fixed gluebi NULL pointer dereference caused by ftl notifier (bsc#1220238). * CVE-2023-52475: Fixed use-after-free in powermate_config_complete (bsc#1220649) * CVE-2023-52478: Fixed kernel crash on receiver USB disconnect (bsc#1220796) * CVE-2019-25162: Fixed a potential use after free (bsc#1220409). * CVE-2020-36784: Fixed reference leak when pm_runtime_get_sync fails (bsc#1220570). * CVE-2021-47054: Fixed a bug to put child node before return (bsc#1220767). * CVE-2021-46924: Fixed fix memory leak in device probe and remove (bsc#1220459) * CVE-2021-46915: Fixed a bug to avoid possible divide error in nft_limit_init (bsc#1220436). * CVE-2021-46906: Fixed an info leak in hid_submit_ctrl (bsc#1220421). * CVE-2023-52445:Fixed use after free on context disconnection (bsc#1220241). * CVE-2020-36777: Fixed a memory leak in dvb_media_device_free (bsc#1220526). * CVE-2023-52443: Fixed crash when parsed profile name is empty (bsc#1220240). * CVE-2023-46343: Fixed a NULL pointer dereference in send_acknowledge (CVE-2023-46343). * CVE-2021-46992: Fixed a bug to avoid overflows in nft_hash_buckets (bsc#1220638). * CVE-2021-47013: Fixed a use after free in emac_mac_tx_buf_send (bsc#1220641). * CVE-2021-46991: Fixed a use-after-free in i40e_client_subtask (bsc#1220575). * CVE-2024-26595: Fixed NULL pointer dereference in error path (bsc#1220344). * CVE-2024-1151: Fixed unlimited number of recursions from action sets (bsc#1219835). * CVE-2023-52464: Fixed possible out-of-bounds string access (bsc#1220330) * CVE-2024-23849: Fixed array-index-out-of-bounds in rds_cmsg_recv (bsc#1219127). * CVE-2024-26600: Fixed NULL pointer dereference for SRP in phy-omap-usb2 (bsc#1220340). The following non-security bugs were fixed: * ASN.1: Fix check for strdup() success (git-fixes). * audit: fix possible soft lockup in __audit_inode_child() (git-fixes). * Bluetooth: hci_bcsp: do not call kfree_skb() under spin_lock_irqsave() (git- fixes). * Bluetooth: hci_h5: do not call kfree_skb() under spin_lock_irqsave() (git- fixes). * Bluetooth: hci_ll: do not call kfree_skb() under spin_lock_irqsave() (git- fixes). * Bluetooth: hci_qca: do not call kfree_skb() under spin_lock_irqsave() (git- fixes). * bnx2x: Fix PF-VF communication over multi-cos queues (git-fixes). * e1000: fix memory leaks (git-fixes). * gve: Fix skb truesize underestimation (git-fixes). * igb: clean up in all error paths when enabling SR-IOV (git-fixes). * igb: Fix constant media auto sense switching when no cable is connected (git-fixes). * ipv6: Fix handling of LLA with VRF and sockets bound to VRF (git-fixes). * ipv6: fix typos in __ip6_finish_output() (git-fixes). * ixgbe: protect TX timestampingfrom API misuse (git-fixes). * kcm: Call strp_stop before strp_done in kcm_attach (git-fixes). * kcm: fix strp_init() order and cleanup (git-fixes). * KVM: s390: vsie: fix race during shadow creation (git-fixes bsc#1220613). * KVM: VMX: Move VERW closer to VMentry for MDS mitigation (git-fixes). * KVM: VMX: Use BT+JNC, i.e. EFLAGS.CF to select VMRESUME vs. VMLAUNCH (git- fixes). * KVM: x86: add support for CPUID leaf 0x80000021 (git-fixes). * KVM: x86: Move open-coded CPUID leaf 0x80000021 EAX bit propagation code (git-fixes). * KVM: x86: synthesize CPUID leaf 0x80000021h if useful (git-fixes). * KVM: x86: work around QEMU issue with synthetic CPUID leaves (git-fixes). * locking/barriers: Introduce smp_cond_load_relaxed() and atomic_cond_read_relaxed() (bsc#1220468 bsc#1050549). * md: bypass block throttle for superblock update (git-fixes). * media: coda: constify platform_device_id (git-fixes). * media: coda: explicitly request exclusive reset control (git-fixes). * media: coda: reduce iram size to leave space for suspend to ram (git-fixes). * media: coda: reuse coda_s_fmt_vid_cap to propagate format in coda_s_fmt_vid_out (git-fixes). * media: coda: set min_buffers_needed (git-fixes). * media: coda: wake up capture queue on encoder stop after output streamoff (git-fixes). * media: dvb-usb: Add memory free on error path in dw2102_probe() (git-fixes). * media: dvb-usb: dw2102: fix uninit-value in su3000_read_mac_address (git- fixes). * media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() (git- fixes). * media: dw2102: Fix memleak on sequence of probes (git-fixes). * media: dw2102: Fix use after free (git-fixes). * media: dw2102: make dvb_usb_device_description structures const (git-fixes). * media: m920x: do not use stack on USB reads (git-fixes). * media: rc: do not remove first bit if leader pulse is present (git-fixes). * media: rc: ir-rc6-decoder: enable toggle bit for Kathrein RCU-676 remote (git-fixes). *media: usb: dvd-usb: fix uninit-value bug in dibusb_read_eeprom_byte() (git- fixes). * media: uvcvideo: Set capability in s_param (git-fixes). * net: bonding: debug: avoid printing debug logs when bond is not notifying peers (git-fixes). * net: fec: add missed clk_disable_unprepare in remove (git-fixes). * net: fec: Better handle pm_runtime_get() failing in .remove() (git-fixes). * net: fec: fix clock count mis-match (git-fixes). * net: fec: fix use-after-free in fec_drv_remove (git-fixes). * net: hisilicon: Fix dma_map_single failed on arm64 (git-fixes). * net: hisilicon: fix hip04-xmit never return TX_BUSY (git-fixes). * net: hisilicon: Fix usage of uninitialized variable in function mdio_sc_cfg_reg_write() (git-fixes). * net: hisilicon: make hip04_tx_reclaim non-reentrant (git-fixes). * net: hns3: add compatible handling for MAC VLAN switch parameter configuration (git-fixes). * net: hns3: not allow SSU loopback while execute ethtool -t dev (git-fixes). * net: lpc-enet: fix printk format strings (git-fixes). * net: nfc: llcp: Add lock when modifying device list (git-fixes). * net: phy: dp83867: enable robust auto-mdix (git-fixes). * net: phy: initialise phydev speed and duplex sanely (git-fixes). * net: sfp: add mutex to prevent concurrent state checks (git-fixes). * net: tundra: tsi108: use spin_lock_irqsave instead of spin_lock_irq in IRQ context (git-fixes). * net: usb: dm9601: fix wrong return value in dm9601_mdio_read (git-fixes). * net/mlx5e: ethtool, Avoid setting speed to 56GBASE when autoneg off (git- fixes). * net/sched: tcindex: search key must be 16 bits (git-fixes). * nfsd: Do not refuse to serve out of cache (bsc#1220957). * PCI: Prevent xHCI driver from claiming AMD VanGogh USB3 DRD device (git- fixes). * Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d" (git-fixes). * Revert "wcn36xx: Disable bmps when encryption is disabled" (git-fixes). * s390: use the correct count for __iowrite64_copy() (git-fixesbsc#1220607). * stmmac: fix potential division by 0 (git-fixes). * tcp: fix tcp_mtup_probe_success vs wrong snd_cwnd (bsc#1218450). * usb: host: fotg210: fix the actual_length of an iso packet (git-fixes). * usb: host: fotg210: fix the endpoint's transactional opportunities calculation (git-fixes). * usb: hub: check for alternate port before enabling A_ALT_HNP_SUPPORT (bsc#1218527). * usb: musb: dsps: Fix the probe error path (git-fixes). * usb: musb: musb_dsps: request_irq() after initializing musb (git-fixes). * usb: musb: tusb6010: check return value after calling platform_get_resource() (git-fixes). * usb: typec: tcpci: clear the fault status bit (git-fixes). * wcn36xx: Fix (QoS) null data frame bitrate/modulation (git-fixes). * wcn36xx: Fix discarded frames due to wrong sequence number (git-fixes). * wcn36xx: fix RX BD rate mapping for 5GHz legacy rates (git-fixes). * x86/asm: Add _ASM_RIP() macro for x86-64 (%rip) suffix (git-fixes). * x86/bugs: Add asm helpers for executing VERW (bsc#1213456). * x86/bugs: Use ALTERNATIVE() instead of mds_user_clear static key (git- fixes). Also add mds_user_clear to kABI severity as it's used purely for mitigation so it's low risk. * x86/cpu, kvm: Move X86_FEATURE_LFENCE_RDTSC to its native leaf (git-fixes). * x86/entry_32: Add VERW just before userspace transition (git-fixes). * x86/entry_64: Add VERW just before userspace transition (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2024-925=1 SUSE-SLE- SERVER-12-SP5-2024-925=1 * SUSE Linux Enterprise High Availability Extension 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2024-925=1 *SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2024-925=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-925=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-925=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-925=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2024-925=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * gfs2-kmp-default-4.12.14-122.201.1 * dlm-kmp-default-debuginfo-4.12.14-122.201.1 * kernel-default-base-4.12.14-122.201.1 * kernel-default-debuginfo-4.12.14-122.201.1 * gfs2-kmp-default-debuginfo-4.12.14-122.201.1 * dlm-kmp-default-4.12.14-122.201.1 * cluster-md-kmp-default-debuginfo-4.12.14-122.201.1 * kernel-default-devel-4.12.14-122.201.1 * kernel-default-base-debuginfo-4.12.14-122.201.1 * ocfs2-kmp-default-debuginfo-4.12.14-122.201.1 * kernel-default-debugsource-4.12.14-122.201.1 * kernel-syms-4.12.14-122.201.1 * cluster-md-kmp-default-4.12.14-122.201.1 * ocfs2-kmp-default-4.12.14-122.201.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (nosrc ppc64le x86_64) * kernel-default-4.12.14-122.201.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * kernel-macros-4.12.14-122.201.1 * kernel-devel-4.12.14-122.201.1 * kernel-source-4.12.14-122.201.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * kernel-default-devel-debuginfo-4.12.14-122.201.1 * SUSE Linux Enterprise High Availability Extension 12 SP5 (ppc64le s390x x86_64) * gfs2-kmp-default-4.12.14-122.201.1 * dlm-kmp-default-debuginfo-4.12.14-122.201.1 * kernel-default-debuginfo-4.12.14-122.201.1 * gfs2-kmp-default-debuginfo-4.12.14-122.201.1 *dlm-kmp-default-4.12.14-122.201.1 * cluster-md-kmp-default-debuginfo-4.12.14-122.201.1 * ocfs2-kmp-default-debuginfo-4.12.14-122.201.1 * kernel-default-debugsource-4.12.14-122.201.1 * cluster-md-kmp-default-4.12.14-122.201.1 * ocfs2-kmp-default-4.12.14-122.201.1 * SUSE Linux Enterprise High Availability Extension 12 SP5 (nosrc) * kernel-default-4.12.14-122.201.1 * SUSE Linux Enterprise Live Patching 12-SP5 (nosrc) * kernel-default-4.12.14-122.201.1 * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kernel-default-kgraft-devel-4.12.14-122.201.1 * kernel-default-kgraft-4.12.14-122.201.1 * kernel-default-debuginfo-4.12.14-122.201.1 * kernel-default-debugsource-4.12.14-122.201.1 * kgraft-patch-4_12_14-122_201-default-1-8.7.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (noarch nosrc) * kernel-docs-4.12.14-122.201.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-debugsource-4.12.14-122.201.2 * kernel-obs-build-4.12.14-122.201.2 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 nosrc x86_64) * kernel-default-4.12.14-122.201.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * kernel-default-base-4.12.14-122.201.1 * kernel-default-debuginfo-4.12.14-122.201.1 * kernel-default-devel-4.12.14-122.201.1 * kernel-default-base-debuginfo-4.12.14-122.201.1 * kernel-default-debugsource-4.12.14-122.201.1 * kernel-syms-4.12.14-122.201.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * kernel-macros-4.12.14-122.201.1 * kernel-devel-4.12.14-122.201.1 * kernel-source-4.12.14-122.201.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * kernel-default-devel-debuginfo-4.12.14-122.201.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64 nosrc) * kernel-default-4.12.14-122.201.1 * SUSE Linux Enterprise Server 12 SP5(aarch64 ppc64le s390x x86_64) * kernel-default-base-4.12.14-122.201.1 * kernel-default-debuginfo-4.12.14-122.201.1 * kernel-default-devel-4.12.14-122.201.1 * kernel-default-base-debuginfo-4.12.14-122.201.1 * kernel-default-debugsource-4.12.14-122.201.1 * kernel-syms-4.12.14-122.201.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * kernel-macros-4.12.14-122.201.1 * kernel-devel-4.12.14-122.201.1 * kernel-source-4.12.14-122.201.1 * SUSE Linux Enterprise Server 12 SP5 (s390x) * kernel-default-man-4.12.14-122.201.1 * SUSE Linux Enterprise Server 12 SP5 (x86_64) * kernel-default-devel-debuginfo-4.12.14-122.201.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (nosrc) * kernel-default-4.12.14-122.201.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * kernel-default-debugsource-4.12.14-122.201.1 * kernel-default-extra-4.12.14-122.201.1 * kernel-default-extra-debuginfo-4.12.14-122.201.1 * kernel-default-debuginfo-4.12.14-122.201.1 ## References: * https://www.suse.com/security/cve/CVE-2019-25162.html * https://www.suse.com/security/cve/CVE-2020-36777.html * https://www.suse.com/security/cve/CVE-2020-36784.html * https://www.suse.com/security/cve/CVE-2021-33200.html * https://www.suse.com/security/cve/CVE-2021-46906.html * https://www.suse.com/security/cve/CVE-2021-46915.html * https://www.suse.com/security/cve/CVE-2021-46921.html * https://www.suse.com/security/cve/CVE-2021-46924.html * https://www.suse.com/security/cve/CVE-2021-46929.html * https://www.suse.com/security/cve/CVE-2021-46932.html * https://www.suse.com/security/cve/CVE-2021-46953.html * https://www.suse.com/security/cve/CVE-2021-46974.html * https://www.suse.com/security/cve/CVE-2021-46991.html * https://www.suse.com/security/cve/CVE-2021-46992.html * https://www.suse.com/security/cve/CVE-2021-47013.html * https://www.suse.com/security/cve/CVE-2021-47054.html * https://www.suse.com/security/cve/CVE-2021-47076.html *https://www.suse.com/security/cve/CVE-2021-47077.html * https://www.suse.com/security/cve/CVE-2021-47078.html * https://www.suse.com/security/cve/CVE-2022-20154.html * https://www.suse.com/security/cve/CVE-2022-48627.html * https://www.suse.com/security/cve/CVE-2023-28746.html * https://www.suse.com/security/cve/CVE-2023-35827.html * https://www.suse.com/security/cve/CVE-2023-46343.html * https://www.suse.com/security/cve/CVE-2023-52340.html * https://www.suse.com/security/cve/CVE-2023-52429.html * https://www.suse.com/security/cve/CVE-2023-52443.html * https://www.suse.com/security/cve/CVE-2023-52445.html * https://www.suse.com/security/cve/CVE-2023-52449.html * https://www.suse.com/security/cve/CVE-2023-52451.html * https://www.suse.com/security/cve/CVE-2023-52464.html * https://www.suse.com/security/cve/CVE-2023-52475.html * https://www.suse.com/security/cve/CVE-2023-52478.html * https://www.suse.com/security/cve/CVE-2023-52482.html * https://www.suse.com/security/cve/CVE-2023-52502.html * https://www.suse.com/security/cve/CVE-2023-52530.html * https://www.suse.com/security/cve/CVE-2023-52531.html * https://www.suse.com/security/cve/CVE-2023-52532.html * https://www.suse.com/security/cve/CVE-2023-52574.html * https://www.suse.com/security/cve/CVE-2023-52597.html * https://www.suse.com/security/cve/CVE-2023-52605.html * https://www.suse.com/security/cve/CVE-2024-0607.html * https://www.suse.com/security/cve/CVE-2024-1151.html * https://www.suse.com/security/cve/CVE-2024-23849.html * https://www.suse.com/security/cve/CVE-2024-23851.html * https://www.suse.com/security/cve/CVE-2024-26585.html * https://www.suse.com/security/cve/CVE-2024-26595.html * * https://www.suse.com/security/cve/CVE-2024-26622.html * https://bugzilla.suse.com/show_bug.cgi?id=1050549 * https://bugzilla.suse.com/show_bug.cgi?id=1186484 * https://bugzilla.suse.com/show_bug.cgi?id=1200599 * https://bugzilla.suse.com/show_bug.cgi?id=1212514 *https://bugzilla.suse.com/show_bug.cgi?id=1213456 * https://bugzilla.suse.com/show_bug.cgi?id=1218450 * https://bugzilla.suse.com/show_bug.cgi?id=1218527 * https://bugzilla.suse.com/show_bug.cgi?id=1218915 * https://bugzilla.suse.com/show_bug.cgi?id=1219127 * https://bugzilla.suse.com/show_bug.cgi?id=1219146 * https://bugzilla.suse.com/show_bug.cgi?id=1219295 * https://bugzilla.suse.com/show_bug.cgi?id=1219653 * https://bugzilla.suse.com/show_bug.cgi?id=1219827 * https://bugzilla.suse.com/show_bug.cgi?id=1219835 * https://bugzilla.suse.com/show_bug.cgi?id=1220187 * https://bugzilla.suse.com/show_bug.cgi?id=1220238 * https://bugzilla.suse.com/show_bug.cgi?id=1220240 * https://bugzilla.suse.com/show_bug.cgi?id=1220241 * https://bugzilla.suse.com/show_bug.cgi?id=1220250 * https://bugzilla.suse.com/show_bug.cgi?id=1220330 * https://bugzilla.suse.com/show_bug.cgi?id=1220340 * https://bugzilla.suse.com/show_bug.cgi?id=1220344 * https://bugzilla.suse.com/show_bug.cgi?id=1220409 * https://bugzilla.suse.com/show_bug.cgi?id=1220421 * https://bugzilla.suse.com/show_bug.cgi?id=1220436 * https://bugzilla.suse.com/show_bug.cgi?id=1220444 * https://bugzilla.suse.com/show_bug.cgi?id=1220459 * https://bugzilla.suse.com/show_bug.cgi?id=1220468 * https://bugzilla.suse.com/show_bug.cgi?id=1220482 * https://bugzilla.suse.com/show_bug.cgi?id=1220526 * https://bugzilla.suse.com/show_bug.cgi?id=1220570 * https://bugzilla.suse.com/show_bug.cgi?id=1220575 * https://bugzilla.suse.com/show_bug.cgi?id=1220599 * https://bugzilla.suse.com/show_bug.cgi?id=1220607 * https://bugzilla.suse.com/show_bug.cgi?id=1220613 * https://bugzilla.suse.com/show_bug.cgi?id=1220638 * https://bugzilla.suse.com/show_bug.cgi?id=1220641 * https://bugzilla.suse.com/show_bug.cgi?id=1220649 * https://bugzilla.suse.com/show_bug.cgi?id=1220700 * https://bugzilla.suse.com/show_bug.cgi?id=1220735 * https://bugzilla.suse.com/show_bug.cgi?id=1220767 *https://bugzilla.suse.com/show_bug.cgi?id=1220796 * https://bugzilla.suse.com/show_bug.cgi?id=1220825 * https://bugzilla.suse.com/show_bug.cgi?id=1220831 * https://bugzilla.suse.com/show_bug.cgi?id=1220845 * https://bugzilla.suse.com/show_bug.cgi?id=1220860 * https://bugzilla.suse.com/show_bug.cgi?id=1220861 * https://bugzilla.suse.com/show_bug.cgi?id=1220863 * https://bugzilla.suse.com/show_bug.cgi?id=1220870 * https://bugzilla.suse.com/show_bug.cgi?id=1220930 * https://bugzilla.suse.com/show_bug.cgi?id=1220931 * https://bugzilla.suse.com/show_bug.cgi?id=1220932 * https://bugzilla.suse.com/show_bug.cgi?id=1220957 * https://bugzilla.suse.com/show_bug.cgi?id=1221039 * https://bugzilla.suse.com/show_bug.cgi?id=1221040 * https://bugzilla.suse.com/show_bug.cgi?id=1221287 . A significant security notice for SUSE Linux detailing kernel enhancements, featuring essential patch resolutions.. SUSE Kernel Security Update, Linux Kernel Bug Fixes, SUSE Patch Management. . Severity: Important. LinuxSecurity.com Team
* bsc#1179610 * bsc#1211226 * bsc#1215237 * bsc#1215375 * bsc#1217250 . # Security update for the Linux Kernel Announcement ID: SUSE-SU-2024:0110-1 Rating: important References: * bsc#1179610 * bsc#1211226 * bsc#1215237 * bsc#1215375 * bsc#1217250 * bsc#1217709 * bsc#1217946 * bsc#1217947 * bsc#1218105 * bsc#1218184 * bsc#1218253 * bsc#1218258 * bsc#1218559 * jsc#PED-5021 Cross-References: * CVE-2020-26555 * CVE-2023-51779 * CVE-2023-6121 * CVE-2023-6606 * CVE-2023-6610 * CVE-2023-6931 * CVE-2023-6932 CVSS scores: * CVE-2020-26555 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2020-26555 ( NVD ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2023-51779 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6121 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2023-6121 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2023-6606 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2023-6606 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2023-6610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2023-6610 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2023-6931 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6931 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6932 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6932 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves seven vulnerabilities, contains one feature and has six security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP3 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2020-26555: Fixed an issue during BR/EDR PIN code pairing in the Bluetooth subsystem that wouldallow replay attacks (bsc#1179610 bsc#1215237). * CVE-2023-6121: Fixed an information leak via dmesg when receiving a crafted packet in the NVMe-oF/TCP subsystem (bsc#1217250). * CVE-2023-6606: Fixed an out of bounds read in the SMB client when receiving a malformed length from a server (bsc#1217947). * CVE-2023-6610: Fixed an out of bounds read in the SMB client when printing debug information (bsc#1217946). * CVE-2023-6931: Fixed an out of bounds write in the Performance Events subsystem when adding a new event (bsc#1218258). * CVE-2023-6932: Fixed a use-after-free issue when receiving an IGMP query packet due to reference count mismanagement (bsc#1218253). * CVE-2023-51779: Fixed a use-after-free because of a bt_sock_ioctl race condition in bt_sock_recvmsg (bsc#1218559). The following non-security bugs were fixed: * Reviewed and added more information to README.SUSE (jsc#PED-5021). * Enabled multibuild for kernel packages (JSC-SLE#5501, boo#1211226, bsc#1218184). * clocksource: Avoid accidental unstable marking of clocksources (bsc#1218105). * clocksource: Suspend the watchdog temporarily when high read latency detected (bsc#1218105). * efi/mokvar: Reserve the table only if it is in boot services data (bsc#1215375). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-110=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-110=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-110=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (nosrc x86_64) * kernel-rt-5.3.18-150300.155.1 * SUSE Linux Enterprise Micro 5.1 (x86_64) * kernel-rt-debugsource-5.3.18-150300.155.1 *kernel-rt-debuginfo-5.3.18-150300.155.1 * SUSE Linux Enterprise Micro 5.2 (nosrc x86_64) * kernel-rt-5.3.18-150300.155.1 * SUSE Linux Enterprise Micro 5.2 (x86_64) * kernel-rt-debugsource-5.3.18-150300.155.1 * kernel-rt-debuginfo-5.3.18-150300.155.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (nosrc x86_64) * kernel-rt-5.3.18-150300.155.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * kernel-rt-debugsource-5.3.18-150300.155.1 * kernel-rt-debuginfo-5.3.18-150300.155.1 ## References: * https://www.suse.com/security/cve/CVE-2020-26555.html * https://www.suse.com/security/cve/CVE-2023-51779.html * https://www.suse.com/security/cve/CVE-2023-6121.html * https://www.suse.com/security/cve/CVE-2023-6606.html * https://www.suse.com/security/cve/CVE-2023-6610.html * https://www.suse.com/security/cve/CVE-2023-6931.html * https://www.suse.com/security/cve/CVE-2023-6932.html * https://bugzilla.suse.com/show_bug.cgi?id=1179610 * https://bugzilla.suse.com/show_bug.cgi?id=1211226 * https://bugzilla.suse.com/show_bug.cgi?id=1215237 * https://bugzilla.suse.com/show_bug.cgi?id=1215375 * https://bugzilla.suse.com/show_bug.cgi?id=1217250 * https://bugzilla.suse.com/show_bug.cgi?id=1217709 * https://bugzilla.suse.com/show_bug.cgi?id=1217946 * https://bugzilla.suse.com/show_bug.cgi?id=1217947 * https://bugzilla.suse.com/show_bug.cgi?id=1218105 * https://bugzilla.suse.com/show_bug.cgi?id=1218184 * https://bugzilla.suse.com/show_bug.cgi?id=1218253 * https://bugzilla.suse.com/show_bug.cgi?id=1218258 * https://bugzilla.suse.com/show_bug.cgi?id=1218559 * . Critical update released for SUSE Linux Kernel tackling various security flaws alongside enhancements. System reboot required after installation.. SUSE Linux Kernel Update, Security Fixes, Bug Resolution, Kernel Security. . Severity: Important. LinuxSecurity.com Team
New version 4.0.5. Fixes Bug #2159392, CVE-2023-1992, CVE-2023-1993 and CVE-2023-1994.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-f70fbf64cb 2023-04-22 00:46:16.249480 --------------------------------------------------------------------------------Name : wireshark Product : Fedora 38 Version : 4.0.5 Release : 1.fc38 URL : https://www.wireshark.org/ Summary : Network traffic analyzer Description : Wireshark allows you to examine protocol data stored in files or as it is captured from wired or wireless (WiFi or Bluetooth) networks, USB devices, and many other sources. It supports dozens of protocol capture file formats and understands more than a thousand protocols. It has many powerful features including a rich display filter language and the ability to reassemble multiple protocol packets in order to, for example, view a complete TCP stream, save the contents of a file which was transferred over HTTP or CIFS, or play back an RTP audio stream. --------------------------------------------------------------------------------Update Information: New version 4.0.5. Fixes Bug #2159392, CVE-2023-1992, CVE-2023-1993 and CVE-2023-1994. --------------------------------------------------------------------------------ChangeLog: * Thu Apr 13 2023 Michal Ruprich - 1:4.0.5-1 - New version 4.0.5 - Fix for bug #2159392 --------------------------------------------------------------------------------References: [ 1 ] Bug #2186303 - wireshark-4.0.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2186303 [ 2 ] Bug #2186326 - CVE-2023-1994 wireshark: GQUIC dissector crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2186326 [ 3 ] Bug #2186328 - CVE-2023-1993 wireshark: LISP dissector large loop [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2186328 [ 4 ] Bug #2186330 - CVE-2023-1992 wireshark: RPCoRDMA dissector crash[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2186330 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f70fbf64cb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This update upgrades Firefox to version 102.10.0 ESR. * MFSA-TMP-2023-0001 Mozilla: Double-free in libwebp * Mozilla: Fullscreen notification obscured (CVE-2023-29533) * Mozilla: Potential Memory Corruption following Garbage Collector compaction (CVE-2023-29535) * Mozilla: Invalid free from JavaScript code (CVE-2023-29536) * Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 1 [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2023:1791-1 Issue Date: 2023-04-14 CVE Numbers: CVE-2023-29533 CVE-2023-29535 CVE-2023-29536 CVE-2023-29539 CVE-2023-29541 CVE-2023-1945 CVE-2023-29548 CVE-2023-29550 -- This update upgrades Firefox to version 102.10.0 ESR. Security Fix(es): * MFSA-TMP-2023-0001 Mozilla: Double-free in libwebp * Mozilla: Fullscreen notification obscured (CVE-2023-29533) * Mozilla: Potential Memory Corruption following Garbage Collector compaction (CVE-2023-29535) * Mozilla: Invalid free from JavaScript code (CVE-2023-29536) * Mozilla: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10 (CVE-2023-29550) * Mozilla: Memory Corruption in Safe Browsing Code (CVE-2023-1945) * Mozilla: Content-Disposition filename truncation leads to Reflected File Download (CVE-2023-29539) * Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux (CVE-2023-29541) * Mozilla: Incorrect optimization result on ARM64 (CVE-2023-29548) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 firefox-102.10.0-1.el7_9.x86_64.rpm firefox-debuginfo-102.10.0-1.el7_9.x86_64.rpm firefox-102.10.0-1.el7_9.i686.rpm firefox-debuginfo-102.10.0-1.el7_9.i686.rpm - Scientific Linux Development Team . Boost the safety of Firefox by implementing vital enhancements that resolveseveral memory vulnerabilities and glitches for Scientific Linux 7.x.. Firefox Security Update, Mozilla Memory Issues, Scientific Linux Update. . Severity: Critical. LinuxSecurity.com Team
An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2023:1091-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1091 Issue date: 2023-03-07 CVE Names: CVE-2022-4378 CVE-2022-42703 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: stack overflow in do_proc_dointvec and proc_skip_spaces (CVE-2022-4378) * kernel: use-after-free related to leaf anon_vma double reuse (CVE-2022-42703) For more details about the securityissue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Regression - SAS3416 card works on RHEL 7.7 and below, does not work on RHEL 7.8 or 7.9 (BZ#1974485) * use-after-free in sctp_do_8_2_transport_strike (BZ#2054037) * RHEL7.9 - [Regression] Kernel test failed during CPU polarization test - lscpu, chcpu - LPAR (BZ#2071980) * RHEL 7, block: Crash in blk_mq_rq_timed_out() when dereferencing NULL request-> q pointer (BZ#2088029) * qla2xxx: Qlogic double completion races during error handling are still not fixed and this will also be a RHEL8+ exposure (BZ#2092105) * kernel 3.10.0-1160.80.1.el7.x86_64 on Xeon E55xx crashes upon KVM startup (BZ#2143438) * Guest's time jumped forward by 12 minutes _after_ live-migration completes (in 30 seconds) (BZ#2152838) * RHEL7: target crashes if a malicious initiator sends a logout immediately after a login command (BZ#2154243) * RHEL7.9 - LTP testcase creat09 fails related to 'CVE-2018-13405' and 'CVE-2021-4037` (BZ#2159946) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2054037 - use-after-free in sctp_do_8_2_transport_strike [rhel-7.9.z] 2133483 - CVE-2022-42703 kernel: use-after-free related to leaf anon_vma double reuse 2143438 - kernel 3.10.0-1160.80.1.el7.x86_64 on Xeon E55xx crashes upon KVM startup [rhel-7.9.z] 2152548 - CVE-2022-4378 kernel: stack overflow in do_proc_dointvec and proc_skip_spaces 6. Package List: Red Hat Enterprise Linux Client (v.7): Source: kernel-3.10.0-1160.88.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1160.88.1.el7.noarch.rpm kernel-doc-3.10.0-1160.88.1.el7.noarch.rpm x86_64: bpftool-3.10.0-1160.88.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1160.88.1.el7.x86_64.rpm kernel-devel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-headers-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1160.88.1.el7.x86_64.rpm perf-3.10.0-1160.88.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: bpftool-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1160.88.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v.7): Source: kernel-3.10.0-1160.88.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1160.88.1.el7.noarch.rpm kernel-doc-3.10.0-1160.88.1.el7.noarch.rpm x86_64: bpftool-3.10.0-1160.88.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1160.88.1.el7.x86_64.rpm kernel-devel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-headers-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1160.88.1.el7.x86_64.rpm perf-3.10.0-1160.88.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: bpftool-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1160.88.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: kernel-3.10.0-1160.88.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1160.88.1.el7.noarch.rpm kernel-doc-3.10.0-1160.88.1.el7.noarch.rpm ppc64: bpftool-3.10.0-1160.88.1.el7.ppc64.rpm bpftool-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm kernel-3.10.0-1160.88.1.el7.ppc64.rpm kernel-bootwrapper-3.10.0-1160.88.1.el7.ppc64.rpm kernel-debug-3.10.0-1160.88.1.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm kernel-debug-devel-3.10.0-1160.88.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-1160.88.1.el7.ppc64.rpm kernel-devel-3.10.0-1160.88.1.el7.ppc64.rpm kernel-headers-3.10.0-1160.88.1.el7.ppc64.rpm kernel-tools-3.10.0-1160.88.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm kernel-tools-libs-3.10.0-1160.88.1.el7.ppc64.rpm perf-3.10.0-1160.88.1.el7.ppc64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm python-perf-3.10.0-1160.88.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm ppc64le: bpftool-3.10.0-1160.88.1.el7.ppc64le.rpm bpftool-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-debug-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-devel-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-headers-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-tools-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-tools-libs-3.10.0-1160.88.1.el7.ppc64le.rpm perf-3.10.0-1160.88.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm python-perf-3.10.0-1160.88.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm s390x: bpftool-3.10.0-1160.88.1.el7.s390x.rpm bpftool-debuginfo-3.10.0-1160.88.1.el7.s390x.rpm kernel-3.10.0-1160.88.1.el7.s390x.rpm kernel-debug-3.10.0-1160.88.1.el7.s390x.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.s390x.rpm kernel-debug-devel-3.10.0-1160.88.1.el7.s390x.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-1160.88.1.el7.s390x.rpm kernel-devel-3.10.0-1160.88.1.el7.s390x.rpm kernel-headers-3.10.0-1160.88.1.el7.s390x.rpm kernel-kdump-3.10.0-1160.88.1.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-1160.88.1.el7.s390x.rpm kernel-kdump-devel-3.10.0-1160.88.1.el7.s390x.rpm perf-3.10.0-1160.88.1.el7.s390x.rpm perf-debuginfo-3.10.0-1160.88.1.el7.s390x.rpm python-perf-3.10.0-1160.88.1.el7.s390x.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.s390x.rpm x86_64: bpftool-3.10.0-1160.88.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1160.88.1.el7.x86_64.rpm kernel-devel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-headers-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1160.88.1.el7.x86_64.rpm perf-3.10.0-1160.88.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: bpftool-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-1160.88.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm kernel-tools-libs-devel-3.10.0-1160.88.1.el7.ppc64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.ppc64.rpm ppc64le: bpftool-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-debug-devel-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-1160.88.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.ppc64le.rpm x86_64: bpftool-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1160.88.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v.7): Source: kernel-3.10.0-1160.88.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1160.88.1.el7.noarch.rpm kernel-doc-3.10.0-1160.88.1.el7.noarch.rpm x86_64: bpftool-3.10.0-1160.88.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1160.88.1.el7.x86_64.rpm kernel-devel-3.10.0-1160.88.1.el7.x86_64.rpm kernel-headers-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1160.88.1.el7.x86_64.rpm perf-3.10.0-1160.88.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: bpftool-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1160.88.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1160.88.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-4378 https://access.redhat.com/security/cve/CVE-2022-42703 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZAcuD9zjgjWX9erEAQjyZBAAkwsEIIDKLQkrNBmDpWdm38h5MGj42bke EvbbjabjOpQYA4r+7pahOwp+xVSPIVEsDcY9ita0pBf9F7mR7RioqqiKtKLcCak/ T+Qk2vgfAmGuj3QAAxcMRp88xiFBx7EwwXtcU5ulciEsjDLMMx/DiAZPkkPgo5M9 p1SrjC/qORcPKsGnG27iT/npSiaOTG6orNDzmi1a/WIVjhzLYOoMXIX3NjUpG+Gd 4iRoEtJXCaVS5g3UtIj9NznFEon1k8HuclmAmDLjlVLhgzEmDcKr3pOBLAUyDXlv C6tWkzQjbRXI3USrBYCH69QGD4MsnONW1Odji+ZnQNaiLz9QxkFvZq4XdZ4AeLgT 9Bli4GHvAkFoJnLCa17sc8R7y0pO6UOYuYiQhglunM09K71INTO7xHBEh23+nNeW zx3cG2kKZMehyJTEvc4CuNW4JKyTc3h4qEbq8K5we7JU43TLfxcGdfm1Csi5ydMZ X7bJPM8NfC15M+1EIj8TC8pgDEPC9tz1Y7VyeeISV0TH/yU52qRuMoOR741kwybQ 03EiviBvEEy3g2UqV/050wawqSQuodIGtdngrcelp4km1inyv4vAr8KdL57qNeIM L732JrUbAflLZQZalYPVjO/9CqFESwUQ0Wd8oTbO9/CBiT0cS168WRLYOwF2RtHp fc2jpAMX+JQ=uGpq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-7087 https://linux.oracle.com/errata/ELSA-2022-7087.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: 389-ds-base-1.3.10.2-17.el7_9.x86_64.rpm 389-ds-base-devel-1.3.10.2-17.el7_9.x86_64.rpm 389-ds-base-libs-1.3.10.2-17.el7_9.x86_64.rpm 389-ds-base-snmp-1.3.10.2-17.el7_9.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/389-ds-base-1.3.10.2-17.el7_9.src.rpm Related CVEs: CVE-2022-2850 Description of changes: [1.3.10-2-17] - Bump version to 1.3.10.2-17 - Resolves: Bug 2113056 - Import may break replication because changelog starting csn may not be created - Resolves: Bug 2131083 - SIGSEGV in sync_repl _______________________________________________ El-errata mailing list
An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2022:6741-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:6741 Issue date: 2022-09-28 CVE Names: CVE-2022-1729 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.7) - noarch, x86_64 Red Hat Enterprise Linux Server E4S (v. 7.7) - noarch, ppc64le, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server Optional E4S (v. 7.7) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional TUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server TUS (v. 7.7) - noarch, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: race condition in perf_event_open leads to privilege escalation (CVE-2022-1729) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section. Bug Fix(es): * Posix ACL object is leaked in several places upon setattr and fsetxattr syscalls (BZ#2106586) * netfilter: backports from upstream (BZ#2120634) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2086753 - CVE-2022-1729 kernel: race condition in perf_event_open leads to privilege escalation 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.7): Source: kernel-3.10.0-1062.70.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1062.70.1.el7.noarch.rpm kernel-doc-3.10.0-1062.70.1.el7.noarch.rpm x86_64: bpftool-3.10.0-1062.70.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.70.1.el7.x86_64.rpm kernel-devel-3.10.0-1062.70.1.el7.x86_64.rpm kernel-headers-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1062.70.1.el7.x86_64.rpm perf-3.10.0-1062.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm python-perf-3.10.0-1062.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm Red Hat Enterprise Linux Server E4S (v.7.7): Source: kernel-3.10.0-1062.70.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1062.70.1.el7.noarch.rpm kernel-doc-3.10.0-1062.70.1.el7.noarch.rpm ppc64le: bpftool-3.10.0-1062.70.1.el7.ppc64le.rpm bpftool-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-debug-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-devel-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-headers-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-tools-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-tools-libs-3.10.0-1062.70.1.el7.ppc64le.rpm perf-3.10.0-1062.70.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm python-perf-3.10.0-1062.70.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm x86_64: bpftool-3.10.0-1062.70.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.70.1.el7.x86_64.rpm kernel-devel-3.10.0-1062.70.1.el7.x86_64.rpm kernel-headers-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1062.70.1.el7.x86_64.rpm perf-3.10.0-1062.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm python-perf-3.10.0-1062.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm Red Hat Enterprise Linux Server TUS (v.7.7): Source: kernel-3.10.0-1062.70.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1062.70.1.el7.noarch.rpm kernel-doc-3.10.0-1062.70.1.el7.noarch.rpm x86_64: bpftool-3.10.0-1062.70.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.70.1.el7.x86_64.rpm kernel-devel-3.10.0-1062.70.1.el7.x86_64.rpm kernel-headers-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1062.70.1.el7.x86_64.rpm perf-3.10.0-1062.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm python-perf-3.10.0-1062.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.7): x86_64: bpftool-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1062.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional E4S (v.7.7): ppc64le: bpftool-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-debug-devel-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-1062.70.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-1062.70.1.el7.ppc64le.rpm x86_64: bpftool-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1062.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional TUS (v. 7.7): x86_64: bpftool-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1062.70.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.70.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-1729 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYzSXBtzjgjWX9erEAQjKrQ//UMJzCqtbTKo49Rw2Q5bNpiBbMYIczHLu uVWQDb82h2K2Ky3qpGHMIQuhMb/pr0k+9Q+MzjEzkIEnDW4iwXvApz2snWy+jXD9 nqnsBPuQqU/4bCGIJYRw+b6/onxXUzFU58opqkoOcOR1bEpc+7VTCwGwH6KExb3s X6BQTyLmIHkcdMl6qzDtw4JqU591mDgujbxAXo/FTh2C2gIaFV1/TWHNNRe6OoDJ 1HQqthx4aWoY4rK2cHLdwuG0gdGK6QTy/lEAu0+79YiVYrBgWK5yTuyyyLGD8SXQ Fn+c4KMjIO3I1FbQwzGmYuRjrQjatJZJczRt+MLo5DxoSbraf7Y7zn3lI6VtKPX9 snqgjZ6vZ0AUkN2bMRRtiA0QRTkqy/FAr+OlSdJaLCLGXRKZfk8vh7Es4bYpO8Mx 2GzpwthdFyyWcgyoEDI6WCp4t4oaAkKZu5rLoa8563icrcTLRMAdUM4IMNuUOI1q S4ovejF2K4G7gaUS2V/i5N298+B8vr10yEtNPHiQ7SZKdjQ+SXD+fkr2Joz/GsSo ozjIYjBsi/Oglk3G7CVJPWUVWf+CsLZHg3ucSsCT2FMFkACtZLbht1wEHzg5kvWc Qj6KpVi4RJ+ZrYrMCi0EB0ejYbQrkLQpCBIRmN7zLrEyPB+qTq2yquYHffmSpdmW jfydo6q/6as=rbbu -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.