* bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229345 . # Security update for the Linux Kernel Announcement ID: SUSE-SU-2024:4345-1 Release Date: 2024-12-17T08:31:01Z Rating: important References: * bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229345 * bsc#1229808 * bsc#1230220 * bsc#1231646 * bsc#1232165 * bsc#1232187 * bsc#1232224 * bsc#1232312 * bsc#1232436 * bsc#1232860 * bsc#1232907 * bsc#1232919 * bsc#1232928 * bsc#1233070 * bsc#1233117 * bsc#1233214 * bsc#1233293 * bsc#1233453 * bsc#1233456 * bsc#1233463 * bsc#1233468 * bsc#1233479 * bsc#1233490 * bsc#1233491 * bsc#1233555 * bsc#1233557 * bsc#1233561 * bsc#1233977 Cross-References: * CVE-2023-52922 * CVE-2024-26782 * CVE-2024-43854 * CVE-2024-44932 * CVE-2024-44964 * CVE-2024-47757 * CVE-2024-49925 * CVE-2024-49945 * CVE-2024-50017 * CVE-2024-50089 * CVE-2024-50115 * CVE-2024-50125 * CVE-2024-50127 * CVE-2024-50154 * CVE-2024-50205 * CVE-2024-50208 * CVE-2024-50259 * CVE-2024-50264 * CVE-2024-50267 * CVE-2024-50274 * CVE-2024-50279 * CVE-2024-50290 * CVE-2024-50301 * CVE-2024-50302 * CVE-2024-53061 * CVE-2024-53063 * CVE-2024-53068 CVSS scores: * CVE-2023-52922 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2023-52922 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2023-52922 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26782 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-43854 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-43854 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-44932 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-44932 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-44964 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:H/SI:H/SA:H * CVE-2024-44964 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-44964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47757 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-47757 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-47757 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-49925 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-49925 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-49925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-49945 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-49945 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50017 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50017 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50089 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50089 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-50089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50115 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:H * CVE-2024-50115 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H * CVE-2024-50115 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-50125 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50125 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50125 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50125 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50127 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50127 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50127 ( NVD): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50127 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50154 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50154 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50154 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50154 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50205 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50205 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-50205 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50208 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50208 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-50208 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50259 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-50259 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50259 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50267 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50267 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50267 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50274 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-50274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50279 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-50279 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-50290( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-50301 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-50301 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-50302 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-50302 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53061 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53061 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53063 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-53063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53068 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53068 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves 27 vulnerabilities and has five security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2024-26782: mptcp: fix double-free on socket dismantle (bsc#1222590). * CVE-2024-43854: Initialize integrity buffer to zero before writing it to media (bsc#1229345) * CVE-2024-44932: idpf: fix UAFs when destroying the queues (bsc#1229808). * CVE-2024-44964: idpf: fix memory leaks and crashes while performing a soft reset (bsc#1230220). * CVE-2024-47757: nilfs2: fix potential oob read in nilfs_btree_check_delete() (bsc#1232187). * CVE-2024-49925: fbdev: efifb: Register sysfs groups through driver core (bsc#1232224) * CVE-2024-49945: net/ncsi: Disable the ncsi work before freeing the associated structure (bsc#1232165). * CVE-2024-50089: unicode: Do not special case ignorable code points (bsc#1232860). *CVE-2024-50115: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory (bsc#1232919). * CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout (bsc#1232928). * CVE-2024-50127: net: sched: fix use-after-free in taprio_change() (bsc#1232907). * CVE-2024-50154: tcp/dccp: Do not use timer_pending() in reqsk_queue_unlink() (bsc#1233070). * CVE-2024-50205: ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size() (bsc#1233293). * CVE-2024-50208: RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages (bsc#1233117). * CVE-2024-50259: netdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write() (bsc#1233214). * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (bsc#1233453). * CVE-2024-50267: usb: serial: io_edgeport: fix use after free in debug printk (bsc#1233456). * CVE-2024-50274: idpf: avoid vport access in idpf_get_link_ksettings (bsc#1233463). * CVE-2024-50279: dm cache: fix out-of-bounds access to the dirty bitset when resizing (bsc#1233468). * CVE-2024-50290: media: cx24116: prevent overflows on SNR calculus (bsc#1233479). * CVE-2024-50301: security/keys: fix slab-out-of-bounds in key_task_permission (bsc#1233490). * CVE-2024-50302: HID: core: zero-initialize the report buffer (bsc#1233491). * CVE-2024-53061: media: s5p-jpeg: prevent buffer overflows (bsc#1233555). * CVE-2024-53063: media: dvbdev: prevent the risk of out of memory access (bsc#1233557). * CVE-2024-53068: firmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier() (bsc#1233561). The following non-security bugs were fixed: * Update config files (bsc#1218644). * Update config files. Enabled IDPF for ARM64 (bsc#1221309) * initramfs: avoid filename buffer overrun (bsc#1232436). * kernel-binary: Enable livepatch package only when livepatch is enabled Otherwise the filelist may be empty failing the build (bsc#1218644). * mm/memory: addnon-anonymous page check in the copy_present_page() (bsc#1231646). * rpm/scripts: Remove obsolete Symbols.list Symbols.list is not longer needed by the new klp-convert implementation. (bsc#1218644) * x86/kexec: Add EFI config table identity mapping for kexec kernel (bsc#1220382). * x86/mm/ident_map: Use gbpages only where full GB page should be mapped (bsc#1220382). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-4345=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-4345=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-4345=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-4345=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.103.1 * kernel-rt-debugsource-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.103.1 * kernel-rt-debugsource-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.103.1 *kernel-rt-debugsource-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.103.1 * kernel-rt-debugsource-5.14.21-150400.15.103.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.103.1 ## References: * https://www.suse.com/security/cve/CVE-2023-52922.html * https://www.suse.com/security/cve/CVE-2024-26782.html * https://www.suse.com/security/cve/CVE-2024-43854.html * https://www.suse.com/security/cve/CVE-2024-44932.html * https://www.suse.com/security/cve/CVE-2024-44964.html * https://www.suse.com/security/cve/CVE-2024-47757.html * https://www.suse.com/security/cve/CVE-2024-49925.html * https://www.suse.com/security/cve/CVE-2024-49945.html * https://www.suse.com/security/cve/CVE-2024-50017.html * https://www.suse.com/security/cve/CVE-2024-50089.html * https://www.suse.com/security/cve/CVE-2024-50115.html * https://www.suse.com/security/cve/CVE-2024-50125.html * https://www.suse.com/security/cve/CVE-2024-50127.html * https://www.suse.com/security/cve/CVE-2024-50154.html * https://www.suse.com/security/cve/CVE-2024-50205.html * https://www.suse.com/security/cve/CVE-2024-50208.html * https://www.suse.com/security/cve/CVE-2024-50259.html * https://www.suse.com/security/cve/CVE-2024-50264.html * https://www.suse.com/security/cve/CVE-2024-50267.html * https://www.suse.com/security/cve/CVE-2024-50274.html * https://www.suse.com/security/cve/CVE-2024-50279.html * https://www.suse.com/security/cve/CVE-2024-50290.html * https://www.suse.com/security/cve/CVE-2024-50301.html * https://www.suse.com/security/cve/CVE-2024-50302.html * https://www.suse.com/security/cve/CVE-2024-53061.html * https://www.suse.com/security/cve/CVE-2024-53063.html *https://www.suse.com/security/cve/CVE-2024-53068.html * https://bugzilla.suse.com/show_bug.cgi?id=1218644 * https://bugzilla.suse.com/show_bug.cgi?id=1220382 * https://bugzilla.suse.com/show_bug.cgi?id=1221309 * https://bugzilla.suse.com/show_bug.cgi?id=1222590 * https://bugzilla.suse.com/show_bug.cgi?id=1229345 * https://bugzilla.suse.com/show_bug.cgi?id=1229808 * https://bugzilla.suse.com/show_bug.cgi?id=1230220 * https://bugzilla.suse.com/show_bug.cgi?id=1231646 * https://bugzilla.suse.com/show_bug.cgi?id=1232165 * https://bugzilla.suse.com/show_bug.cgi?id=1232187 * https://bugzilla.suse.com/show_bug.cgi?id=1232224 * https://bugzilla.suse.com/show_bug.cgi?id=1232312 * https://bugzilla.suse.com/show_bug.cgi?id=1232436 * https://bugzilla.suse.com/show_bug.cgi?id=1232860 * https://bugzilla.suse.com/show_bug.cgi?id=1232907 * https://bugzilla.suse.com/show_bug.cgi?id=1232919 * https://bugzilla.suse.com/show_bug.cgi?id=1232928 * https://bugzilla.suse.com/show_bug.cgi?id=1233070 * https://bugzilla.suse.com/show_bug.cgi?id=1233117 * https://bugzilla.suse.com/show_bug.cgi?id=1233214 * https://bugzilla.suse.com/show_bug.cgi?id=1233293 * https://bugzilla.suse.com/show_bug.cgi?id=1233453 * https://bugzilla.suse.com/show_bug.cgi?id=1233456 * https://bugzilla.suse.com/show_bug.cgi?id=1233463 * https://bugzilla.suse.com/show_bug.cgi?id=1233468 * https://bugzilla.suse.com/show_bug.cgi?id=1233479 * https://bugzilla.suse.com/show_bug.cgi?id=1233490 * https://bugzilla.suse.com/show_bug.cgi?id=1233491 * https://bugzilla.suse.com/show_bug.cgi?id=1233555 * https://bugzilla.suse.com/show_bug.cgi?id=1233557 * https://bugzilla.suse.com/show_bug.cgi?id=1233561 * https://bugzilla.suse.com/show_bug.cgi?id=1233977 . Vital patch release for SUSE Linux Kernel rectifying numerous vulnerabilities. Imperative for maintaining system stability.. SUSE Linux Micro Kernel Update Security Patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1223858 * bsc#1224169 * bsc#1224340 Affected Products: . # Security update for the Linux Kernel Announcement ID: SUSE-SU-2024:1813-1 Rating: important References: * bsc#1223858 * bsc#1224169 * bsc#1224340 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Real Time Module 15-SP5 An update that has three security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP5 RT kernel was updated to receive various security bugfixes. This update fixes a regression with kerberized nfs4 shares in the previous update (bsc#1223858). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-1813=1 openSUSE-SLE-15.5-2024-1813=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1813=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2024-1813=1 * SUSE Real Time Module 15-SP5 zypper in -t patch SUSE-SLE-Module-RT-15-SP5-2024-1813=1 ## Package List: * openSUSE Leap 15.5 (noarch) * kernel-source-rt-5.14.21-150500.13.55.1 * kernel-devel-rt-5.14.21-150500.13.55.1 * openSUSE Leap 15.5 (x86_64) * kernel-rt-debuginfo-5.14.21-150500.13.55.1 * kernel-rt-livepatch-5.14.21-150500.13.55.1 * dlm-kmp-rt-5.14.21-150500.13.55.1 * kernel-rt-vdso-debuginfo-5.14.21-150500.13.55.1 * kernel-rt_debug-debugsource-5.14.21-150500.13.55.1 *kernel-syms-rt-5.14.21-150500.13.55.1 * kselftests-kmp-rt-5.14.21-150500.13.55.1 * kernel-rt-extra-5.14.21-150500.13.55.1 * kernel-rt-optional-debuginfo-5.14.21-150500.13.55.1 * kernel-rt-vdso-5.14.21-150500.13.55.1 * kernel-livepatch-5_14_21-150500_13_55-rt-1-150500.11.3.1 * kernel-livepatch-SLE15-SP5-RT_Update_15-debugsource-1-150500.11.3.1 * cluster-md-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * kernel-rt-extra-debuginfo-5.14.21-150500.13.55.1 * kernel-rt-devel-debuginfo-5.14.21-150500.13.55.1 * ocfs2-kmp-rt-5.14.21-150500.13.55.1 * reiserfs-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * kernel-rt-devel-5.14.21-150500.13.55.1 * kernel-rt-livepatch-devel-5.14.21-150500.13.55.1 * kernel-rt_debug-devel-debuginfo-5.14.21-150500.13.55.1 * dlm-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * kernel-livepatch-5_14_21-150500_13_55-rt-debuginfo-1-150500.11.3.1 * kernel-rt-debugsource-5.14.21-150500.13.55.1 * kernel-rt_debug-debuginfo-5.14.21-150500.13.55.1 * gfs2-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * kselftests-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * kernel-rt-optional-5.14.21-150500.13.55.1 * reiserfs-kmp-rt-5.14.21-150500.13.55.1 * cluster-md-kmp-rt-5.14.21-150500.13.55.1 * gfs2-kmp-rt-5.14.21-150500.13.55.1 * kernel-rt_debug-devel-5.14.21-150500.13.55.1 * kernel-rt_debug-vdso-5.14.21-150500.13.55.1 * kernel-rt_debug-livepatch-devel-5.14.21-150500.13.55.1 * kernel-rt_debug-vdso-debuginfo-5.14.21-150500.13.55.1 * ocfs2-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * openSUSE Leap 15.5 (nosrc x86_64) * kernel-rt_debug-5.14.21-150500.13.55.1 * kernel-rt-5.14.21-150500.13.55.1 * SUSE Linux Enterprise Micro 5.5 (nosrc x86_64) * kernel-rt-5.14.21-150500.13.55.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * kernel-rt-debuginfo-5.14.21-150500.13.55.1 * kernel-rt-debugsource-5.14.21-150500.13.55.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * kernel-source-rt-5.14.21-150500.13.55.1 * SUSELinux Enterprise Live Patching 15-SP5 (x86_64) * kernel-livepatch-5_14_21-150500_13_55-rt-1-150500.11.3.1 * kernel-livepatch-5_14_21-150500_13_55-rt-debuginfo-1-150500.11.3.1 * kernel-livepatch-SLE15-SP5-RT_Update_15-debugsource-1-150500.11.3.1 * SUSE Real Time Module 15-SP5 (x86_64) * kernel-rt-debuginfo-5.14.21-150500.13.55.1 * dlm-kmp-rt-5.14.21-150500.13.55.1 * kernel-rt-vdso-debuginfo-5.14.21-150500.13.55.1 * kernel-rt_debug-debugsource-5.14.21-150500.13.55.1 * kernel-syms-rt-5.14.21-150500.13.55.1 * kernel-rt-vdso-5.14.21-150500.13.55.1 * cluster-md-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * kernel-rt-devel-debuginfo-5.14.21-150500.13.55.1 * ocfs2-kmp-rt-5.14.21-150500.13.55.1 * kernel-rt-devel-5.14.21-150500.13.55.1 * kernel-rt_debug-devel-debuginfo-5.14.21-150500.13.55.1 * dlm-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * kernel-rt_debug-debuginfo-5.14.21-150500.13.55.1 * kernel-rt-debugsource-5.14.21-150500.13.55.1 * gfs2-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * cluster-md-kmp-rt-5.14.21-150500.13.55.1 * gfs2-kmp-rt-5.14.21-150500.13.55.1 * kernel-rt_debug-devel-5.14.21-150500.13.55.1 * kernel-rt_debug-vdso-5.14.21-150500.13.55.1 * kernel-rt_debug-vdso-debuginfo-5.14.21-150500.13.55.1 * ocfs2-kmp-rt-debuginfo-5.14.21-150500.13.55.1 * SUSE Real Time Module 15-SP5 (noarch) * kernel-source-rt-5.14.21-150500.13.55.1 * kernel-devel-rt-5.14.21-150500.13.55.1 * SUSE Real Time Module 15-SP5 (nosrc x86_64) * kernel-rt_debug-5.14.21-150500.13.55.1 * kernel-rt-5.14.21-150500.13.55.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1223858 * https://bugzilla.suse.com/show_bug.cgi?id=1224169 * https://bugzilla.suse.com/show_bug.cgi?id=1224340 . SUSE reveals significant security enhancements for the Linux Kernel, featuring patches and guidance for installation.. SUSE Linux Enterprise, Linux Kernel, Security Updates, Bugfix Instructions. . Severity: Important. LinuxSecurity.com Team
Updated kernel packages that fix several security issues and bugs in the Red Hat Enterprise Linux 4 kernel are now available. This security advisory has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: kernel security and bugfix update Advisory ID: RHSA-2007:0774-01 Advisory URL: https://access.redhat.com/errata/RHSA-2007:0774.html Issue date: 2007-09-04 Updated on: 2007-09-04 Product: Red Hat Enterprise Linux CVE Names: CVE-2006-0558 CVE-2007-1217 - ---------------------------------------------------------------------1. Summary: Updated kernel packages that fix several security issues and bugs in the Red Hat Enterprise Linux 4 kernel are now available. This security advisory has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, noarch, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, noarch, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, noarch, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, noarch, x86_64 3. Problem description: The Linux kernel handles the basic functions of the operating system. These new kernel packages contain fixes for the security issues described below: * a flaw in the ISDN CAPI subsystem that allowed a remote user to cause a denial of service or potential remote access. Exploitation would require the attacker to be able to send arbitrary frames over the ISDN network to the victim's machine. (CVE-2007-1217, Moderate) * a flaw in the perfmon subsystem on ia64 platforms that allowed a local user to cause a denial of service. (CVE-2006-0558, Moderate) In addition, the following bugs were addressed: * a panic after reloading of the LSIFusion driver. * a vm performance problem was corrected by balancing inactive page lists. * added a nodirplus option to address NFSv3 performance issues with large directories. * changed the personality handling to disallow personality changes of setuid and setgid binaries. This ensures they keep any randomization and Exec-shield protection. All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels to the packages associated with their machine architectures and configurations as listed in this erratum. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bug IDs fixed (http://bugzilla.redhat.com/): 243257 - CVE-2007-1217 Overflow in CAPI subsystem 248141 - lockup in shrink_zone when node out of memory 250199 - CVE-2006-0558 ia64 crash 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: 765a9f014a98b52c6a71b163744eb723 kernel-2.6.9-55.0.6.EL.src.rpm i386: 5ca649f693fa4dadf3a17cd1c87d3778 kernel-2.6.9-55.0.6.EL.i686.rpm effa7d30c0e6bed0cba0d0802c7984f4 kernel-debuginfo-2.6.9-55.0.6.EL.i686.rpm 70bc806db1f470c0275761d77b4b2e31 kernel-devel-2.6.9-55.0.6.EL.i686.rpm 461a3363011947ed95a34272427ecc05 kernel-hugemem-2.6.9-55.0.6.EL.i686.rpm 09eea38f8458e99035f01b75bc6c2591 kernel-hugemem-devel-2.6.9-55.0.6.EL.i686.rpm 82836f23fac455e0d8c91d65135406c3 kernel-smp-2.6.9-55.0.6.EL.i686.rpm 9de094acb60ee41456f7dc5d5d5ef425 kernel-smp-devel-2.6.9-55.0.6.EL.i686.rpm 457638d044d30bd6254c09481adfb0d6 kernel-xenU-2.6.9-55.0.6.EL.i686.rpm cb7178e80a0a1cc311a0e03202762af3 kernel-xenU-devel-2.6.9-55.0.6.EL.i686.rpm ia64: a34296fd8eb4b1ea772a97504863db3b kernel-2.6.9-55.0.6.EL.ia64.rpm 4180c95dd8656f17e23afbacedc536f8 kernel-debuginfo-2.6.9-55.0.6.EL.ia64.rpm 07d2d09a4551b905e6ea43130a918517 kernel-devel-2.6.9-55.0.6.EL.ia64.rpm 93755492c8cafa8b5eba00188ade56f8 kernel-largesmp-2.6.9-55.0.6.EL.ia64.rpm 24223db0f6610aea7f031b7e2b1731c0 kernel-largesmp-devel-2.6.9-55.0.6.EL.ia64.rpm noarch: 12721d7fbe9f676d333e6bd102450741 kernel-doc-2.6.9-55.0.6.EL.noarch.rpm ppc: a7f827d585e7b88e275c4415f921bd22 kernel-2.6.9-55.0.6.EL.ppc64.rpm 9960bec30ae32a6b0ef32291cb5c4c22 kernel-2.6.9-55.0.6.EL.ppc64iseries.rpm e9e3319cf9daa15c43c63251800f9aa0 kernel-debuginfo-2.6.9-55.0.6.EL.ppc64.rpm b14d8fb2e253356a66c8ad567c90c3de kernel-debuginfo-2.6.9-55.0.6.EL.ppc64iseries.rpm 747f20511e832ac72f768181c6323438 kernel-devel-2.6.9-55.0.6.EL.ppc64.rpm 4342ec81fae76e355da332539406f021 kernel-devel-2.6.9-55.0.6.EL.ppc64iseries.rpm ef695eb5436de012753ed28c479fbacb kernel-largesmp-2.6.9-55.0.6.EL.ppc64.rpm e29fc42bce0ce54fba3032cd1ce7a031 kernel-largesmp-devel-2.6.9-55.0.6.EL.ppc64.rpm s390: f8f49e1d1f3b2648dabfbe843b3b93b4 kernel-2.6.9-55.0.6.EL.s390.rpm b5dbbeb030cfdae3334e93cd6c0a84b9 kernel-debuginfo-2.6.9-55.0.6.EL.s390.rpm 62628af6da559c4f8e8f649ab06ecc07 kernel-devel-2.6.9-55.0.6.EL.s390.rpm s390x: 28c9fd7c0fa74382229e4c93b915f037 kernel-2.6.9-55.0.6.EL.s390x.rpm 15bebcc1182c9a579463b3462c6bd9e1 kernel-debuginfo-2.6.9-55.0.6.EL.s390x.rpm 5ff9158eea826817e39f5a3f4ae58d57 kernel-devel-2.6.9-55.0.6.EL.s390x.rpm x86_64: 45b6465b5990b7f15a1bdda3801776ba kernel-2.6.9-55.0.6.EL.x86_64.rpm 87f0be447ef0130568e819e5e0bd0c4b kernel-debuginfo-2.6.9-55.0.6.EL.x86_64.rpm 848643171741d18b3d6cac4cd29a3251 kernel-devel-2.6.9-55.0.6.EL.x86_64.rpm 082aee2e6be21e53e51ffcb18f21c5ea kernel-largesmp-2.6.9-55.0.6.EL.x86_64.rpm f840a93d76ee2911a0954e114b69843b kernel-largesmp-devel-2.6.9-55.0.6.EL.x86_64.rpm 8a05d9a9f805c2d72636d4d143e6954f kernel-smp-2.6.9-55.0.6.EL.x86_64.rpm 9cb515622e094f2aebccfa21844258a5 kernel-smp-devel-2.6.9-55.0.6.EL.x86_64.rpm 7015c4515b1bfdd8058b70a5f3354737 kernel-xenU-2.6.9-55.0.6.EL.x86_64.rpm a56936184935bc91369d4cb160b1ae72 kernel-xenU-devel-2.6.9-55.0.6.EL.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: 765a9f014a98b52c6a71b163744eb723 kernel-2.6.9-55.0.6.EL.src.rpm i386: 5ca649f693fa4dadf3a17cd1c87d3778 kernel-2.6.9-55.0.6.EL.i686.rpm effa7d30c0e6bed0cba0d0802c7984f4 kernel-debuginfo-2.6.9-55.0.6.EL.i686.rpm 70bc806db1f470c0275761d77b4b2e31 kernel-devel-2.6.9-55.0.6.EL.i686.rpm 461a3363011947ed95a34272427ecc05 kernel-hugemem-2.6.9-55.0.6.EL.i686.rpm 09eea38f8458e99035f01b75bc6c2591 kernel-hugemem-devel-2.6.9-55.0.6.EL.i686.rpm 82836f23fac455e0d8c91d65135406c3 kernel-smp-2.6.9-55.0.6.EL.i686.rpm 9de094acb60ee41456f7dc5d5d5ef425 kernel-smp-devel-2.6.9-55.0.6.EL.i686.rpm 457638d044d30bd6254c09481adfb0d6 kernel-xenU-2.6.9-55.0.6.EL.i686.rpm cb7178e80a0a1cc311a0e03202762af3 kernel-xenU-devel-2.6.9-55.0.6.EL.i686.rpm noarch: 12721d7fbe9f676d333e6bd102450741 kernel-doc-2.6.9-55.0.6.EL.noarch.rpm x86_64: 45b6465b5990b7f15a1bdda3801776ba kernel-2.6.9-55.0.6.EL.x86_64.rpm 87f0be447ef0130568e819e5e0bd0c4b kernel-debuginfo-2.6.9-55.0.6.EL.x86_64.rpm 848643171741d18b3d6cac4cd29a3251 kernel-devel-2.6.9-55.0.6.EL.x86_64.rpm 082aee2e6be21e53e51ffcb18f21c5ea kernel-largesmp-2.6.9-55.0.6.EL.x86_64.rpm f840a93d76ee2911a0954e114b69843b kernel-largesmp-devel-2.6.9-55.0.6.EL.x86_64.rpm 8a05d9a9f805c2d72636d4d143e6954f kernel-smp-2.6.9-55.0.6.EL.x86_64.rpm 9cb515622e094f2aebccfa21844258a5 kernel-smp-devel-2.6.9-55.0.6.EL.x86_64.rpm 7015c4515b1bfdd8058b70a5f3354737 kernel-xenU-2.6.9-55.0.6.EL.x86_64.rpm a56936184935bc91369d4cb160b1ae72 kernel-xenU-devel-2.6.9-55.0.6.EL.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: 765a9f014a98b52c6a71b163744eb723 kernel-2.6.9-55.0.6.EL.src.rpm i386: 5ca649f693fa4dadf3a17cd1c87d3778 kernel-2.6.9-55.0.6.EL.i686.rpm effa7d30c0e6bed0cba0d0802c7984f4 kernel-debuginfo-2.6.9-55.0.6.EL.i686.rpm 70bc806db1f470c0275761d77b4b2e31 kernel-devel-2.6.9-55.0.6.EL.i686.rpm 461a3363011947ed95a34272427ecc05 kernel-hugemem-2.6.9-55.0.6.EL.i686.rpm 09eea38f8458e99035f01b75bc6c2591 kernel-hugemem-devel-2.6.9-55.0.6.EL.i686.rpm 82836f23fac455e0d8c91d65135406c3 kernel-smp-2.6.9-55.0.6.EL.i686.rpm 9de094acb60ee41456f7dc5d5d5ef425 kernel-smp-devel-2.6.9-55.0.6.EL.i686.rpm 457638d044d30bd6254c09481adfb0d6 kernel-xenU-2.6.9-55.0.6.EL.i686.rpm cb7178e80a0a1cc311a0e03202762af3 kernel-xenU-devel-2.6.9-55.0.6.EL.i686.rpm ia64: a34296fd8eb4b1ea772a97504863db3b kernel-2.6.9-55.0.6.EL.ia64.rpm 4180c95dd8656f17e23afbacedc536f8 kernel-debuginfo-2.6.9-55.0.6.EL.ia64.rpm 07d2d09a4551b905e6ea43130a918517 kernel-devel-2.6.9-55.0.6.EL.ia64.rpm 93755492c8cafa8b5eba00188ade56f8 kernel-largesmp-2.6.9-55.0.6.EL.ia64.rpm 24223db0f6610aea7f031b7e2b1731c0 kernel-largesmp-devel-2.6.9-55.0.6.EL.ia64.rpm noarch: 12721d7fbe9f676d333e6bd102450741 kernel-doc-2.6.9-55.0.6.EL.noarch.rpm x86_64: 45b6465b5990b7f15a1bdda3801776ba kernel-2.6.9-55.0.6.EL.x86_64.rpm 87f0be447ef0130568e819e5e0bd0c4b kernel-debuginfo-2.6.9-55.0.6.EL.x86_64.rpm 848643171741d18b3d6cac4cd29a3251 kernel-devel-2.6.9-55.0.6.EL.x86_64.rpm 082aee2e6be21e53e51ffcb18f21c5ea kernel-largesmp-2.6.9-55.0.6.EL.x86_64.rpm f840a93d76ee2911a0954e114b69843b kernel-largesmp-devel-2.6.9-55.0.6.EL.x86_64.rpm 8a05d9a9f805c2d72636d4d143e6954f kernel-smp-2.6.9-55.0.6.EL.x86_64.rpm 9cb515622e094f2aebccfa21844258a5 kernel-smp-devel-2.6.9-55.0.6.EL.x86_64.rpm 7015c4515b1bfdd8058b70a5f3354737 kernel-xenU-2.6.9-55.0.6.EL.x86_64.rpm a56936184935bc91369d4cb160b1ae72 kernel-xenU-devel-2.6.9-55.0.6.EL.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: 765a9f014a98b52c6a71b163744eb723 kernel-2.6.9-55.0.6.EL.src.rpm i386: 5ca649f693fa4dadf3a17cd1c87d3778 kernel-2.6.9-55.0.6.EL.i686.rpm effa7d30c0e6bed0cba0d0802c7984f4 kernel-debuginfo-2.6.9-55.0.6.EL.i686.rpm 70bc806db1f470c0275761d77b4b2e31 kernel-devel-2.6.9-55.0.6.EL.i686.rpm 461a3363011947ed95a34272427ecc05 kernel-hugemem-2.6.9-55.0.6.EL.i686.rpm 09eea38f8458e99035f01b75bc6c2591 kernel-hugemem-devel-2.6.9-55.0.6.EL.i686.rpm 82836f23fac455e0d8c91d65135406c3 kernel-smp-2.6.9-55.0.6.EL.i686.rpm 9de094acb60ee41456f7dc5d5d5ef425 kernel-smp-devel-2.6.9-55.0.6.EL.i686.rpm 457638d044d30bd6254c09481adfb0d6 kernel-xenU-2.6.9-55.0.6.EL.i686.rpm cb7178e80a0a1cc311a0e03202762af3 kernel-xenU-devel-2.6.9-55.0.6.EL.i686.rpm ia64: a34296fd8eb4b1ea772a97504863db3b kernel-2.6.9-55.0.6.EL.ia64.rpm 4180c95dd8656f17e23afbacedc536f8 kernel-debuginfo-2.6.9-55.0.6.EL.ia64.rpm 07d2d09a4551b905e6ea43130a918517 kernel-devel-2.6.9-55.0.6.EL.ia64.rpm 93755492c8cafa8b5eba00188ade56f8 kernel-largesmp-2.6.9-55.0.6.EL.ia64.rpm 24223db0f6610aea7f031b7e2b1731c0 kernel-largesmp-devel-2.6.9-55.0.6.EL.ia64.rpm noarch: 12721d7fbe9f676d333e6bd102450741 kernel-doc-2.6.9-55.0.6.EL.noarch.rpm x86_64: 45b6465b5990b7f15a1bdda3801776ba kernel-2.6.9-55.0.6.EL.x86_64.rpm 87f0be447ef0130568e819e5e0bd0c4b kernel-debuginfo-2.6.9-55.0.6.EL.x86_64.rpm 848643171741d18b3d6cac4cd29a3251 kernel-devel-2.6.9-55.0.6.EL.x86_64.rpm 082aee2e6be21e53e51ffcb18f21c5ea kernel-largesmp-2.6.9-55.0.6.EL.x86_64.rpm f840a93d76ee2911a0954e114b69843b kernel-largesmp-devel-2.6.9-55.0.6.EL.x86_64.rpm 8a05d9a9f805c2d72636d4d143e6954f kernel-smp-2.6.9-55.0.6.EL.x86_64.rpm 9cb515622e094f2aebccfa21844258a5 kernel-smp-devel-2.6.9-55.0.6.EL.x86_64.rpm 7015c4515b1bfdd8058b70a5f3354737 kernel-xenU-2.6.9-55.0.6.EL.x86_64.rpm a56936184935bc91369d4cb160b1ae72 kernel-xenU-devel-2.6.9-55.0.6.EL.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2006-0558 https://www.cve.org/CVERecord?id=CVE-2007-1217 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2007 Red Hat, Inc. .Revised kernel updates address vulnerabilities and errors in Red Hat Enterprise Linux 4, presenting a moderate risk. Update today!. RedHat Kernel Update, Linux Kernel Security, Moderate Security Advisory. . LinuxSecurity.com Team
Updated kernel packages that fix several security issues and bugs in the Red Hat Enterprise Linux 3 kernel are now available. These new kernel packages contain fixes for the security issues described below: This security advisory has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: kernel security and bugfix update Advisory ID: RHSA-2007:0671-01 Advisory URL: https://access.redhat.com/errata/RHSA-2007:0671.html Issue date: 2007-08-16 Updated on: 2007-08-16 Product: Red Hat Enterprise Linux Keywords: taroon kernel security errata Obsoletes: RHSA-2007:0436 CVE Names: CVE-2007-1217 CVE-2007-1353 - ---------------------------------------------------------------------1. Summary: Updated kernel packages that fix several security issues and bugs in the Red Hat Enterprise Linux 3 kernel are now available. This security advisory has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: The Linux kernel handles the basic functions of the operating system. These new kernel packages contain fixes for the security issues described below: * a flaw in the ISDN CAPI subsystem that allowed a remote user to cause a denial of service or potential privilege escalation. (CVE-2007-1217, Moderate) * a flaw in the Bluetooth subsystem that allowed a local user to trigger an information leak. (CVE-2007-1353, Low) In addition to the security issues described above, fixes for the following have been included: * a racecondition in the e1000 network driver that could cause ESB2 systems to be started without the RX unit being turned on. * a related e1000 bug on ESB2 systems that could cause rlogin to fail. Red Hat would like to thank Ilja van Sprundel for reporting an issue fixed in this erratum. Note: The kernel-unsupported package contains various drivers and modules that are unsupported and therefore might contain security problems that have not been addressed. All Red Hat Enterprise Linux 3 users are advised to upgrade their kernels to the packages associated with their machine architecture and configurations as listed in this erratum. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bug IDs fixed (http://bugzilla.redhat.com/): 231069 - CVE-2007-1217 Overflow in CAPI subsystem 234294 - CVE-2007-1353 Bluetooth setsockopt() information leaks 6. RPMs required: Red Hat Enterprise Linux AS version 3: SRPMS: 3e94648c83b62fb9cc401b53ca5f6096 kernel-2.4.21-51.EL.src.rpm i386: 1b001b9748c4626e16e3eec657b65e1b kernel-2.4.21-51.EL.athlon.rpm 81412b55ba69d85064b55114fc4cadd3 kernel-2.4.21-51.EL.i686.rpm 45e16d49aa290a4bd0efe33bba627f5b kernel-BOOT-2.4.21-51.EL.i386.rpm fded238337854d3044eb5004996b36a6 kernel-debuginfo-2.4.21-51.EL.athlon.rpm db091f1f057aa3aeb3134352151e6246 kernel-debuginfo-2.4.21-51.EL.i386.rpm 953fb8b53bf60d64a250c2d9cd6e956d kernel-debuginfo-2.4.21-51.EL.i686.rpm 32eb10ebb7e3c890cea0da9f49c6d56a kernel-doc-2.4.21-51.EL.i386.rpm d5bffec510ed2d2c09edb881bcbb19bb kernel-hugemem-2.4.21-51.EL.i686.rpm 9e4729d4981d0f371b9e34d3b04badd6 kernel-hugemem-unsupported-2.4.21-51.EL.i686.rpm 3336bf85d01e863d41a021a348088216 kernel-smp-2.4.21-51.EL.athlon.rpm b98cf89374f00c81691ee57392b1d768 kernel-smp-2.4.21-51.EL.i686.rpm f1e7de77a0acbe3d007571d38b84947a kernel-smp-unsupported-2.4.21-51.EL.athlon.rpm 2ad659821179db2f3a78d44ce62990de kernel-smp-unsupported-2.4.21-51.EL.i686.rpm 4a2dcd9e3b3c1db9152f4415e5a1699a kernel-source-2.4.21-51.EL.i386.rpm 6aa9025e30a16389480c4ccadaa9057f kernel-unsupported-2.4.21-51.EL.athlon.rpm c442a88cf82f11be01e0a335cc3c0856 kernel-unsupported-2.4.21-51.EL.i686.rpm ia64: f43eba731b22b5956aabaccff6c70abe kernel-2.4.21-51.EL.ia64.rpm 80ed8856d2713f931b8543926d29d4a8 kernel-debuginfo-2.4.21-51.EL.ia64.rpm 2209a4a2680c0eb7acee8df8d47d4028 kernel-doc-2.4.21-51.EL.ia64.rpm 863b02755f6641944114f052ad3e9a0e kernel-source-2.4.21-51.EL.ia64.rpm 8f84b0001c83b99fddbd28bcde5f806f kernel-unsupported-2.4.21-51.EL.ia64.rpm ppc: 5da6c0c9a5f0ac9c328fdb4b711299ad kernel-2.4.21-51.EL.ppc64iseries.rpm f5400b322cfaee4392aaf3771e73d157 kernel-2.4.21-51.EL.ppc64pseries.rpm 01b2f5c1155fb3f0774eda66571b3666 kernel-debuginfo-2.4.21-51.EL.ppc64.rpm 08805438592e26ae2ba699ea1196ee1e kernel-debuginfo-2.4.21-51.EL.ppc64iseries.rpm fe6024efc0f249d880059deca27a4cf2 kernel-debuginfo-2.4.21-51.EL.ppc64pseries.rpm 5ce4268e6403de5f971457ea229e451d kernel-doc-2.4.21-51.EL.ppc64.rpm e2cddede0dbeadb64bea2266ed2a0a8d kernel-source-2.4.21-51.EL.ppc64.rpm 08561aeefce58d9a685da5da95118348 kernel-unsupported-2.4.21-51.EL.ppc64iseries.rpm 41003f17bf7da307c97b2c754a4b5621 kernel-unsupported-2.4.21-51.EL.ppc64pseries.rpm s390: 18e99d6dd147612fa221ed6c64345ed7 kernel-2.4.21-51.EL.s390.rpm 98808ddf3c5566588819ef8fc9eae930 kernel-debuginfo-2.4.21-51.EL.s390.rpm c0061a5cae943a826d56e996a22d4c1b kernel-doc-2.4.21-51.EL.s390.rpm 1e94e756a1ad2778f384639abeaac3cf kernel-source-2.4.21-51.EL.s390.rpm 3125a4e5c820acb28307d5dd1d8b624a kernel-unsupported-2.4.21-51.EL.s390.rpm s390x: 86cc02e371c1253ec2fa7ba31cb17595 kernel-2.4.21-51.EL.s390x.rpm fcf253f707acf26b668444f426c792d2 kernel-debuginfo-2.4.21-51.EL.s390x.rpm a49b8aed89e64f29505369bde2ea7e62 kernel-doc-2.4.21-51.EL.s390x.rpm 62d185eb16102d2aa8d2a82601d8768e kernel-source-2.4.21-51.EL.s390x.rpm 5968a0d4b0a129445ee801b82f3c2321 kernel-unsupported-2.4.21-51.EL.s390x.rpm x86_64: a2c87d889cbd620e5ef6012dd565785f kernel-2.4.21-51.EL.ia32e.rpm 6be6ea30748554962f126c81441768ed kernel-2.4.21-51.EL.x86_64.rpm 572777549a1530d34b8cc1c66e715471 kernel-debuginfo-2.4.21-51.EL.ia32e.rpm 9d1251676ba50ba4b4ba80b4b18d2ec4 kernel-debuginfo-2.4.21-51.EL.x86_64.rpm 21c16e560705f14421a1d669a27a54df kernel-doc-2.4.21-51.EL.x86_64.rpm aecd821b741c859535a6e2e6cf3ab0f5 kernel-smp-2.4.21-51.EL.x86_64.rpm 70a8d74ffc53e619fd8948ae76309f1b kernel-smp-unsupported-2.4.21-51.EL.x86_64.rpm 66cbc0771e3be71408cae29636881ca7 kernel-source-2.4.21-51.EL.x86_64.rpm 13078e7d42ad160d1c304f722ac0f721 kernel-unsupported-2.4.21-51.EL.ia32e.rpm ca57b82d95a3f1c3b32e632175f46898 kernel-unsupported-2.4.21-51.EL.x86_64.rpm Red Hat Desktop version 3: SRPMS: 3e94648c83b62fb9cc401b53ca5f6096 kernel-2.4.21-51.EL.src.rpm i386: 1b001b9748c4626e16e3eec657b65e1b kernel-2.4.21-51.EL.athlon.rpm 81412b55ba69d85064b55114fc4cadd3 kernel-2.4.21-51.EL.i686.rpm 45e16d49aa290a4bd0efe33bba627f5b kernel-BOOT-2.4.21-51.EL.i386.rpm fded238337854d3044eb5004996b36a6 kernel-debuginfo-2.4.21-51.EL.athlon.rpm db091f1f057aa3aeb3134352151e6246 kernel-debuginfo-2.4.21-51.EL.i386.rpm 953fb8b53bf60d64a250c2d9cd6e956d kernel-debuginfo-2.4.21-51.EL.i686.rpm 32eb10ebb7e3c890cea0da9f49c6d56a kernel-doc-2.4.21-51.EL.i386.rpm d5bffec510ed2d2c09edb881bcbb19bb kernel-hugemem-2.4.21-51.EL.i686.rpm 9e4729d4981d0f371b9e34d3b04badd6 kernel-hugemem-unsupported-2.4.21-51.EL.i686.rpm 3336bf85d01e863d41a021a348088216 kernel-smp-2.4.21-51.EL.athlon.rpm b98cf89374f00c81691ee57392b1d768 kernel-smp-2.4.21-51.EL.i686.rpm f1e7de77a0acbe3d007571d38b84947a kernel-smp-unsupported-2.4.21-51.EL.athlon.rpm 2ad659821179db2f3a78d44ce62990de kernel-smp-unsupported-2.4.21-51.EL.i686.rpm 4a2dcd9e3b3c1db9152f4415e5a1699a kernel-source-2.4.21-51.EL.i386.rpm 6aa9025e30a16389480c4ccadaa9057f kernel-unsupported-2.4.21-51.EL.athlon.rpm c442a88cf82f11be01e0a335cc3c0856 kernel-unsupported-2.4.21-51.EL.i686.rpm x86_64: a2c87d889cbd620e5ef6012dd565785f kernel-2.4.21-51.EL.ia32e.rpm 6be6ea30748554962f126c81441768ed kernel-2.4.21-51.EL.x86_64.rpm 572777549a1530d34b8cc1c66e715471 kernel-debuginfo-2.4.21-51.EL.ia32e.rpm 9d1251676ba50ba4b4ba80b4b18d2ec4 kernel-debuginfo-2.4.21-51.EL.x86_64.rpm 21c16e560705f14421a1d669a27a54df kernel-doc-2.4.21-51.EL.x86_64.rpm aecd821b741c859535a6e2e6cf3ab0f5 kernel-smp-2.4.21-51.EL.x86_64.rpm 70a8d74ffc53e619fd8948ae76309f1b kernel-smp-unsupported-2.4.21-51.EL.x86_64.rpm 66cbc0771e3be71408cae29636881ca7 kernel-source-2.4.21-51.EL.x86_64.rpm 13078e7d42ad160d1c304f722ac0f721 kernel-unsupported-2.4.21-51.EL.ia32e.rpm ca57b82d95a3f1c3b32e632175f46898 kernel-unsupported-2.4.21-51.EL.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 3e94648c83b62fb9cc401b53ca5f6096 kernel-2.4.21-51.EL.src.rpm i386: 1b001b9748c4626e16e3eec657b65e1b kernel-2.4.21-51.EL.athlon.rpm 81412b55ba69d85064b55114fc4cadd3 kernel-2.4.21-51.EL.i686.rpm 45e16d49aa290a4bd0efe33bba627f5b kernel-BOOT-2.4.21-51.EL.i386.rpm fded238337854d3044eb5004996b36a6 kernel-debuginfo-2.4.21-51.EL.athlon.rpm db091f1f057aa3aeb3134352151e6246 kernel-debuginfo-2.4.21-51.EL.i386.rpm 953fb8b53bf60d64a250c2d9cd6e956d kernel-debuginfo-2.4.21-51.EL.i686.rpm 32eb10ebb7e3c890cea0da9f49c6d56a kernel-doc-2.4.21-51.EL.i386.rpm d5bffec510ed2d2c09edb881bcbb19bb kernel-hugemem-2.4.21-51.EL.i686.rpm 9e4729d4981d0f371b9e34d3b04badd6 kernel-hugemem-unsupported-2.4.21-51.EL.i686.rpm 3336bf85d01e863d41a021a348088216 kernel-smp-2.4.21-51.EL.athlon.rpm b98cf89374f00c81691ee57392b1d768 kernel-smp-2.4.21-51.EL.i686.rpm f1e7de77a0acbe3d007571d38b84947a kernel-smp-unsupported-2.4.21-51.EL.athlon.rpm 2ad659821179db2f3a78d44ce62990de kernel-smp-unsupported-2.4.21-51.EL.i686.rpm 4a2dcd9e3b3c1db9152f4415e5a1699a kernel-source-2.4.21-51.EL.i386.rpm 6aa9025e30a16389480c4ccadaa9057f kernel-unsupported-2.4.21-51.EL.athlon.rpm c442a88cf82f11be01e0a335cc3c0856 kernel-unsupported-2.4.21-51.EL.i686.rpm ia64: f43eba731b22b5956aabaccff6c70abe kernel-2.4.21-51.EL.ia64.rpm 80ed8856d2713f931b8543926d29d4a8 kernel-debuginfo-2.4.21-51.EL.ia64.rpm 2209a4a2680c0eb7acee8df8d47d4028 kernel-doc-2.4.21-51.EL.ia64.rpm 863b02755f6641944114f052ad3e9a0e kernel-source-2.4.21-51.EL.ia64.rpm 8f84b0001c83b99fddbd28bcde5f806f kernel-unsupported-2.4.21-51.EL.ia64.rpm x86_64: a2c87d889cbd620e5ef6012dd565785f kernel-2.4.21-51.EL.ia32e.rpm 6be6ea30748554962f126c81441768ed kernel-2.4.21-51.EL.x86_64.rpm 572777549a1530d34b8cc1c66e715471 kernel-debuginfo-2.4.21-51.EL.ia32e.rpm 9d1251676ba50ba4b4ba80b4b18d2ec4 kernel-debuginfo-2.4.21-51.EL.x86_64.rpm 21c16e560705f14421a1d669a27a54df kernel-doc-2.4.21-51.EL.x86_64.rpm aecd821b741c859535a6e2e6cf3ab0f5 kernel-smp-2.4.21-51.EL.x86_64.rpm 70a8d74ffc53e619fd8948ae76309f1b kernel-smp-unsupported-2.4.21-51.EL.x86_64.rpm 66cbc0771e3be71408cae29636881ca7 kernel-source-2.4.21-51.EL.x86_64.rpm 13078e7d42ad160d1c304f722ac0f721 kernel-unsupported-2.4.21-51.EL.ia32e.rpm ca57b82d95a3f1c3b32e632175f46898 kernel-unsupported-2.4.21-51.EL.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 3e94648c83b62fb9cc401b53ca5f6096 kernel-2.4.21-51.EL.src.rpm i386: 1b001b9748c4626e16e3eec657b65e1b kernel-2.4.21-51.EL.athlon.rpm 81412b55ba69d85064b55114fc4cadd3 kernel-2.4.21-51.EL.i686.rpm 45e16d49aa290a4bd0efe33bba627f5b kernel-BOOT-2.4.21-51.EL.i386.rpm fded238337854d3044eb5004996b36a6 kernel-debuginfo-2.4.21-51.EL.athlon.rpm db091f1f057aa3aeb3134352151e6246 kernel-debuginfo-2.4.21-51.EL.i386.rpm 953fb8b53bf60d64a250c2d9cd6e956d kernel-debuginfo-2.4.21-51.EL.i686.rpm 32eb10ebb7e3c890cea0da9f49c6d56a kernel-doc-2.4.21-51.EL.i386.rpm d5bffec510ed2d2c09edb881bcbb19bb kernel-hugemem-2.4.21-51.EL.i686.rpm 9e4729d4981d0f371b9e34d3b04badd6 kernel-hugemem-unsupported-2.4.21-51.EL.i686.rpm 3336bf85d01e863d41a021a348088216 kernel-smp-2.4.21-51.EL.athlon.rpm b98cf89374f00c81691ee57392b1d768 kernel-smp-2.4.21-51.EL.i686.rpm f1e7de77a0acbe3d007571d38b84947a kernel-smp-unsupported-2.4.21-51.EL.athlon.rpm 2ad659821179db2f3a78d44ce62990de kernel-smp-unsupported-2.4.21-51.EL.i686.rpm 4a2dcd9e3b3c1db9152f4415e5a1699a kernel-source-2.4.21-51.EL.i386.rpm 6aa9025e30a16389480c4ccadaa9057f kernel-unsupported-2.4.21-51.EL.athlon.rpm c442a88cf82f11be01e0a335cc3c0856 kernel-unsupported-2.4.21-51.EL.i686.rpm ia64: f43eba731b22b5956aabaccff6c70abe kernel-2.4.21-51.EL.ia64.rpm 80ed8856d2713f931b8543926d29d4a8 kernel-debuginfo-2.4.21-51.EL.ia64.rpm 2209a4a2680c0eb7acee8df8d47d4028 kernel-doc-2.4.21-51.EL.ia64.rpm 863b02755f6641944114f052ad3e9a0e kernel-source-2.4.21-51.EL.ia64.rpm 8f84b0001c83b99fddbd28bcde5f806f kernel-unsupported-2.4.21-51.EL.ia64.rpm x86_64: a2c87d889cbd620e5ef6012dd565785f kernel-2.4.21-51.EL.ia32e.rpm 6be6ea30748554962f126c81441768ed kernel-2.4.21-51.EL.x86_64.rpm 572777549a1530d34b8cc1c66e715471 kernel-debuginfo-2.4.21-51.EL.ia32e.rpm 9d1251676ba50ba4b4ba80b4b18d2ec4 kernel-debuginfo-2.4.21-51.EL.x86_64.rpm 21c16e560705f14421a1d669a27a54df kernel-doc-2.4.21-51.EL.x86_64.rpm aecd821b741c859535a6e2e6cf3ab0f5 kernel-smp-2.4.21-51.EL.x86_64.rpm 70a8d74ffc53e619fd8948ae76309f1b kernel-smp-unsupported-2.4.21-51.EL.x86_64.rpm 66cbc0771e3be71408cae29636881ca7 kernel-source-2.4.21-51.EL.x86_64.rpm 13078e7d42ad160d1c304f722ac0f721 kernel-unsupported-2.4.21-51.EL.ia32e.rpm ca57b82d95a3f1c3b32e632175f46898 kernel-unsupported-2.4.21-51.EL.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7.References: https://www.cve.org/CVERecord?id=CVE-2007-1217 https://www.cve.org/CVERecord?id=CVE-2007-1353 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2007 Red Hat, Inc. . Updates to kernel packages released by Red Hat address a range of bugs and vulnerabilities assessed as moderate by the Security Response Team.. kernel update,Red Hat,security issues,enterprise linux,bug fixes. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.