Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves eight vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:21217-1 Release Date: 2026-04-11T07:40:52Z Rating: important References: * bsc#1252036 * bsc#1252689 * bsc#1253404 * bsc#1256780 * bsc#1257238 * bsc#1258051 * bsc#1258183 * bsc#1258784 Cross-References: * CVE-2025-39973 * CVE-2025-40018 * CVE-2025-40159 * CVE-2025-71120 * CVE-2026-22999 * CVE-2026-23074 * CVE-2026-23111 * CVE-2026-23209 CVSS scores: * CVE-2025-39973 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-39973 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40018 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40018 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40159 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40159 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71120 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71120 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71120 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-22999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-22999 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23074 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23074 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23111 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23111 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23209 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23209 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues The following security issues were fixed: * CVE-2025-39973: i40e: add validation for ring_len param (bsc#1252036). * CVE-2025-40018: ipvs: Defer ip_vs_ftp unregister during netns cleanup (bsc#1252689). * CVE-2025-40159: xsk: Harden userspace-supplied xdp_desc validation (bsc#1253404). * CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (bsc#1256780). * CVE-2026-22999: net/sched: sch_qfq: do not free existing class in qfq_change_class() (bsc#1257238). * CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1258051). * CVE-2026-23111: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() (bsc#1258183). * CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink() (bsc#1258784). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-530=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-530=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_5-default-debuginfo-9-160000.4.3 * kernel-livepatch-SLE16_Update_0-debugsource-9-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-9-160000.4.3 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_5-default-debuginfo-9-160000.4.3 * kernel-livepatch-SLE16_Update_0-debugsource-9-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-9-160000.4.3 ## References: * https://www.suse.com/security/cve/CVE-2025-39973.html * https://www.suse.com/security/cve/CVE-2025-40018.html * https://www.suse.com/security/cve/CVE-2025-40159.html * https://www.suse.com/security/cve/CVE-2025-71120.html * https://www.suse.com/security/cve/CVE-2026-22999.html * https://www.suse.com/security/cve/CVE-2026-23074.html * https://www.suse.com/security/cve/CVE-2026-23111.html * https://www.suse.com/security/cve/CVE-2026-23209.html * https://bugzilla.suse.com/show_bug.cgi?id=1252036 * https://bugzilla.suse.com/show_bug.cgi?id=1252689 * https://bugzilla.suse.com/show_bug.cgi?id=1253404 * https://bugzilla.suse.com/show_bug.cgi?id=1256780 * https://bugzilla.suse.com/show_bug.cgi?id=1257238 * https://bugzilla.suse.com/show_bug.cgi?id=1258051 * https://bugzilla.suse.com/show_bug.cgi?id=1258183 * https://bugzilla.suse.com/show_bug.cgi?id=1258784 . Update addresses critical issues in SUSE Linux Enterprise Kernel for version 16, impacting system security and stability.. SUSE Linux Enterprise, Kernel Patch, Important Update, Linux Security. . Severity: Important. LinuxSecurity.com Team
* bsc#1225819 * bsc#1227369 * bsc#1227781 * bsc#1227784 * bsc#1228349 . # Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP6) Announcement ID: SUSE-SU-2025:0265-1 Release Date: 2025-01-27T16:33:31Z Rating: important References: * bsc#1225819 * bsc#1227369 * bsc#1227781 * bsc#1227784 * bsc#1228349 * bsc#1228786 * bsc#1229273 * bsc#1229275 * bsc#1229553 * bsc#1233712 Cross-References: * CVE-2023-52752 * CVE-2024-35949 * CVE-2024-36979 * CVE-2024-40909 * CVE-2024-40920 * CVE-2024-40921 * CVE-2024-40954 * CVE-2024-41057 * CVE-2024-43861 * CVE-2024-50264 CVSS scores: * CVE-2023-52752 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52752 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35949 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40909 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-40921 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-40954 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40954 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-41057 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-41057 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-41057 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-43861 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-43861 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_23_17 fixes several issues. The following security issues were fixed: * CVE-2024-40921: net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state (bsc#1227784). * CVE-2024-40920: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state (bsc#1227781). * CVE-2024-36979: net: bridge: mst: fix vlan use-after-free (bsc#1227369). * CVE-2024-41057: cachefiles: fix slab-use-after-free in cachefiles_withdraw_cookie() (bsc#1229275). * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (bsc#1233712). * CVE-2024-43861: Fix memory leak for not ip packets (bsc#1229553). * CVE-2024-35949: btrfs: make sure that WRITTEN is set on all metadata blocks (bsc#1229273). * CVE-2023-52752: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() (bsc#1225819). * CVE-2024-40954: net: do not leave a dangling sk pointer, when socket creation fails (bsc#1227808) * CVE-2024-40909: bpf: Fix a potential use-after-free in bpf_link_free() (bsc#1228349). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-265=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-265=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) *kernel-livepatch-SLE15-SP6_Update_3-debugsource-7-150600.13.6.1 * kernel-livepatch-6_4_0-150600_23_17-default-debuginfo-7-150600.13.6.1 * kernel-livepatch-6_4_0-150600_23_17-default-7-150600.13.6.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_3-debugsource-7-150600.13.6.1 * kernel-livepatch-6_4_0-150600_23_17-default-debuginfo-7-150600.13.6.1 * kernel-livepatch-6_4_0-150600_23_17-default-7-150600.13.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-52752.html * https://www.suse.com/security/cve/CVE-2024-35949.html * https://www.suse.com/security/cve/CVE-2024-36979.html * https://www.suse.com/security/cve/CVE-2024-40909.html * https://www.suse.com/security/cve/CVE-2024-40920.html * https://www.suse.com/security/cve/CVE-2024-40921.html * https://www.suse.com/security/cve/CVE-2024-40954.html * https://www.suse.com/security/cve/CVE-2024-41057.html * https://www.suse.com/security/cve/CVE-2024-43861.html * https://www.suse.com/security/cve/CVE-2024-50264.html * https://bugzilla.suse.com/show_bug.cgi?id=1225819 * https://bugzilla.suse.com/show_bug.cgi?id=1227369 * https://bugzilla.suse.com/show_bug.cgi?id=1227781 * https://bugzilla.suse.com/show_bug.cgi?id=1227784 * https://bugzilla.suse.com/show_bug.cgi?id=1228349 * https://bugzilla.suse.com/show_bug.cgi?id=1228786 * https://bugzilla.suse.com/show_bug.cgi?id=1229273 * https://bugzilla.suse.com/show_bug.cgi?id=1229275 * https://bugzilla.suse.com/show_bug.cgi?id=1229553 * https://bugzilla.suse.com/show_bug.cgi?id=1233712 . Important security patch released for SUSE Linux Kernel rectifying various vulnerabilities and enhancing overall system reliability.. SUSE Security Advisory,Linux Kernel Update,Live Patching,SUSE 15 SP6 Security Fixes. . Severity: Important. LinuxSecurity.com Team
* bsc#1233712 Cross-References: * CVE-2024-50264 . # Security update for the Linux Kernel RT (Live Patch 5 for SLE 15 SP6) Announcement ID: SUSE-SU-2025:0083-1 Release Date: 2025-01-14T03:34:05Z Rating: important References: * bsc#1233712 Cross-References: * CVE-2024-50264 CVSS scores: * CVE-2024-50264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_10_17 fixes one issue. The following security issue was fixed: * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (bsc#1233712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-83=1 SUSE-SLE- Module-Live-Patching-15-SP6-2025-86=1 SUSE-SLE-Module-Live- Patching-15-SP6-2025-87=1 SUSE-SLE-Module-Live-Patching-15-SP6-2025-88=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (x86_64) * kernel-livepatch-6_4_0-150600_8-rt-7-150600.3.1 * kernel-livepatch-SLE15-SP6-RT_Update_0-debugsource-7-150600.3.1 * kernel-livepatch-6_4_0-150600_10_17-rt-debuginfo-2-150600.1.6.1 * kernel-livepatch-6_4_0-150600_10_11-rt-3-150600.1.6.1 * kernel-livepatch-SLE15-SP6-RT_Update_3-debugsource-3-150600.1.6.1 * kernel-livepatch-6_4_0-150600_10_17-rt-2-150600.1.6.1 *kernel-livepatch-6_4_0-150600_10_11-rt-debuginfo-3-150600.1.6.1 * kernel-livepatch-SLE15-SP6-RT_Update_5-debugsource-2-150600.1.6.1 * kernel-livepatch-6_4_0-150600_10_14-rt-2-150600.1.6.1 * kernel-livepatch-SLE15-SP6-RT_Update_4-debugsource-2-150600.1.6.1 * kernel-livepatch-6_4_0-150600_8-rt-debuginfo-7-150600.3.1 * kernel-livepatch-6_4_0-150600_10_14-rt-debuginfo-2-150600.1.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50264.html * https://bugzilla.suse.com/show_bug.cgi?id=1233712 . Crucial patch released for the Linux Kernel RT targeting CVE-2024-50264. Ensure to apply these updates swiftly to maintain security.. SUSE Linux Enterprise, Kernel Live Patching, Security Patch, Linux Kernel RT, CVE 2024. . Severity: Important. LinuxSecurity.com Team
* bsc#1232528 Cross-References: * CVE-2024-9681 . # Security update for curl Announcement ID: SUSE-SU-2024:3925-1 Release Date: 2024-11-06T10:14:33Z Rating: moderate References: * bsc#1232528 Cross-References: * CVE-2024-9681 CVSS scores: * CVE-2024-9681 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-9681 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2024-9681: Fixed HSTS subdomain overwrites parent cache entry (bsc#1232528) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-3925=1 openSUSE-SLE-15.6-2024-3925=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-3925=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libcurl4-debuginfo-8.6.0-150600.4.12.1 * curl-debugsource-8.6.0-150600.4.12.1 * libcurl4-8.6.0-150600.4.12.1 * curl-debuginfo-8.6.0-150600.4.12.1 * libcurl-devel-8.6.0-150600.4.12.1 * curl-8.6.0-150600.4.12.1 * openSUSE Leap 15.6 (x86_64) * libcurl-devel-32bit-8.6.0-150600.4.12.1 * libcurl4-32bit-debuginfo-8.6.0-150600.4.12.1 * libcurl4-32bit-8.6.0-150600.4.12.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libcurl4-64bit-debuginfo-8.6.0-150600.4.12.1 * libcurl-devel-64bit-8.6.0-150600.4.12.1 * libcurl4-64bit-8.6.0-150600.4.12.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390xx86_64) * libcurl4-debuginfo-8.6.0-150600.4.12.1 * curl-debugsource-8.6.0-150600.4.12.1 * libcurl4-8.6.0-150600.4.12.1 * curl-debuginfo-8.6.0-150600.4.12.1 * libcurl-devel-8.6.0-150600.4.12.1 * curl-8.6.0-150600.4.12.1 * Basesystem Module 15-SP6 (x86_64) * libcurl4-32bit-8.6.0-150600.4.12.1 * libcurl4-32bit-debuginfo-8.6.0-150600.4.12.1 ## References: * https://www.suse.com/security/cve/CVE-2024-9681.html * https://bugzilla.suse.com/show_bug.cgi?id=1232528 . SUSE has issued a security patch for curl to mitigate moderate CVE-2024-9681 vulnerabilities; instructions for installation included.. curl security update, SUSE advisory, openSUSE patch. . LinuxSecurity.com Team
* bsc#1225309 * bsc#1225311 * bsc#1225819 * bsc#1227471 * bsc#1227472 . # Security update for the Linux Kernel (Live Patch 43 for SLE 15 SP2) Announcement ID: SUSE-SU-2024:3794-1 Release Date: 2024-10-30T11:03:58Z Rating: important References: * bsc#1225309 * bsc#1225311 * bsc#1225819 * bsc#1227471 * bsc#1227472 Cross-References: * CVE-2021-47598 * CVE-2021-47600 * CVE-2023-52752 * CVE-2024-35862 * CVE-2024-35864 CVSS scores: * CVE-2021-47598 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2021-47598 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2021-47600 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2021-47600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52752 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52752 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35862 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35864 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise Live Patching 15-SP2 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150200_24_172 fixes several issues. The following security issues were fixed: * CVE-2021-47600: dm btree remove: fix use after free in rebalance_children() (bsc#1227472). * CVE-2021-47598: sch_cake: do not call cake_destroy() from cake_init() (bsc#1227471). * CVE-2023-52752: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() (bsc#1225819). * CVE-2024-35862: Fixed potential UAF in smb2_is_network_name_deleted() (bsc#1225311). * CVE-2024-35864: Fixed potential UAF in smb2_is_valid_lease_break() (bsc#1225309). ## PatchInstructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP2 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP2-2024-3794=1 SUSE-SLE- Module-Live-Patching-15-SP2-2024-3795=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP2 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150200_24_172-default-debuginfo-13-150200.2.1 * kernel-livepatch-SLE15-SP2_Update_43-debugsource-13-150200.2.1 * kernel-livepatch-5_3_18-150200_24_169-default-15-150200.2.1 * kernel-livepatch-SLE15-SP2_Update_42-debugsource-15-150200.2.1 * kernel-livepatch-5_3_18-150200_24_172-default-13-150200.2.1 * kernel-livepatch-5_3_18-150200_24_169-default-debuginfo-15-150200.2.1 ## References: * https://www.suse.com/security/cve/CVE-2021-47598.html * https://www.suse.com/security/cve/CVE-2021-47600.html * https://www.suse.com/security/cve/CVE-2023-52752.html * https://www.suse.com/security/cve/CVE-2024-35862.html * https://www.suse.com/security/cve/CVE-2024-35864.html * https://bugzilla.suse.com/show_bug.cgi?id=1225309 * https://bugzilla.suse.com/show_bug.cgi?id=1225311 * https://bugzilla.suse.com/show_bug.cgi?id=1225819 * https://bugzilla.suse.com/show_bug.cgi?id=1227471 * https://bugzilla.suse.com/show_bug.cgi?id=1227472 . SUSE releases significant security enhancements for Linux Kernel Live Patch 43, tackling several critical vulnerabilities.. Linux Kernel,SUSE Security Update,Patch 43,Critical Threats,Software Security. . Severity: Important. LinuxSecurity.com Team
* bsc#1228120 Cross-References: * CVE-2024-6655 . # Security update for gtk3 Announcement ID: SUSE-SU-2024:2612-1 Rating: important References: * bsc#1228120 Cross-References: * CVE-2024-6655 CVSS scores: * CVE-2024-6655 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gtk3 fixes the following issues: * CVE-2024-6655: Fixed library injection from current working directory (bsc#1228120) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-2612=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2612=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2612=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2612=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * gtk3-devel-3.20.10-17.16.1 * gtk3-debugsource-3.20.10-17.16.1 * gtk3-devel-debuginfo-3.20.10-17.16.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * gtk3-data-3.20.10-17.16.1 * gtk3-lang-3.20.10-17.16.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * libgtk-3-0-3.20.10-17.16.1 * gtk3-debugsource-3.20.10-17.16.1 * gtk3-tools-debuginfo-3.20.10-17.16.1 * libgtk-3-0-debuginfo-3.20.10-17.16.1 *gtk3-tools-3.20.10-17.16.1 * typelib-1_0-Gtk-3_0-3.20.10-17.16.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * gtk3-tools-32bit-3.20.10-17.16.1 * libgtk-3-0-debuginfo-32bit-3.20.10-17.16.1 * gtk3-tools-debuginfo-32bit-3.20.10-17.16.1 * libgtk-3-0-32bit-3.20.10-17.16.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * gtk3-data-3.20.10-17.16.1 * gtk3-lang-3.20.10-17.16.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * libgtk-3-0-3.20.10-17.16.1 * gtk3-debugsource-3.20.10-17.16.1 * gtk3-tools-debuginfo-3.20.10-17.16.1 * libgtk-3-0-debuginfo-3.20.10-17.16.1 * gtk3-tools-3.20.10-17.16.1 * typelib-1_0-Gtk-3_0-3.20.10-17.16.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * gtk3-tools-32bit-3.20.10-17.16.1 * libgtk-3-0-debuginfo-32bit-3.20.10-17.16.1 * gtk3-tools-debuginfo-32bit-3.20.10-17.16.1 * libgtk-3-0-32bit-3.20.10-17.16.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * gtk3-data-3.20.10-17.16.1 * gtk3-lang-3.20.10-17.16.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * libgtk-3-0-3.20.10-17.16.1 * gtk3-debugsource-3.20.10-17.16.1 * gtk3-tools-debuginfo-3.20.10-17.16.1 * libgtk-3-0-debuginfo-3.20.10-17.16.1 * gtk3-tools-3.20.10-17.16.1 * typelib-1_0-Gtk-3_0-3.20.10-17.16.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * gtk3-tools-32bit-3.20.10-17.16.1 * libgtk-3-0-debuginfo-32bit-3.20.10-17.16.1 * gtk3-tools-debuginfo-32bit-3.20.10-17.16.1 * libgtk-3-0-32bit-3.20.10-17.16.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6655.html * https://bugzilla.suse.com/show_bug.cgi?id=1228120 . gtk3 has released a vital security patch tackling a serious library incorporation vulnerability. Ensure you install the updates to maintain the safety of your systems.. gtk3 Update, SUSE Security, Library Injection, Linux Patch, Security Advisory. . Severity:Critical. LinuxSecurity.com Team
* bsc#1215868 * bsc#1215869 * bsc#1215870 * bsc#1218033 * bsc#1222905 . # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2024:1976-1 Rating: important References: * bsc#1215868 * bsc#1215869 * bsc#1215870 * bsc#1218033 * bsc#1222905 * bsc#1225071 Cross-References: * CVE-2023-42843 * CVE-2023-42950 * CVE-2023-42956 * CVE-2024-23226 * CVE-2024-23252 * CVE-2024-23254 * CVE-2024-23263 * CVE-2024-23280 * CVE-2024-23284 * CVE-2024-27834 CVSS scores: * CVE-2023-42843 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2023-42950 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-42950 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-42956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-23226 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-23252 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-23254 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-23263 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2024-23280 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2024-23284 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2024-27834 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: * Update to version 2.44.2 (bsc#1225071) * CVE-2024-27834: Fixed a vulnerability where an attacker with arbitrary read and writecapability may be able to bypass Pointer Authentication. (bsc#1225071) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1976=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1976=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1976=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1976=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2024-1976=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * webkit2gtk3-debugsource-2.44.2-4.7.1 * typelib-1_0-WebKit2WebExtension-4_0-2.44.2-4.7.1 * webkit2gtk3-devel-2.44.2-4.7.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * libwebkit2gtk-4_0-37-2.44.2-4.7.1 * libwebkit2gtk-4_0-37-debuginfo-2.44.2-4.7.1 * typelib-1_0-JavaScriptCore-4_0-2.44.2-4.7.1 * webkit2gtk3-debugsource-2.44.2-4.7.1 * typelib-1_0-WebKit2WebExtension-4_0-2.44.2-4.7.1 * webkit2gtk-4_0-injected-bundles-2.44.2-4.7.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.44.2-4.7.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.44.2-4.7.1 * typelib-1_0-WebKit2-4_0-2.44.2-4.7.1 * libjavascriptcoregtk-4_0-18-2.44.2-4.7.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * libwebkit2gtk3-lang-2.44.2-4.7.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * libwebkit2gtk-4_0-37-2.44.2-4.7.1 * libwebkit2gtk-4_0-37-debuginfo-2.44.2-4.7.1 * typelib-1_0-JavaScriptCore-4_0-2.44.2-4.7.1 * webkit2gtk3-debugsource-2.44.2-4.7.1 *typelib-1_0-WebKit2WebExtension-4_0-2.44.2-4.7.1 * webkit2gtk-4_0-injected-bundles-2.44.2-4.7.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.44.2-4.7.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.44.2-4.7.1 * typelib-1_0-WebKit2-4_0-2.44.2-4.7.1 * libjavascriptcoregtk-4_0-18-2.44.2-4.7.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * libwebkit2gtk3-lang-2.44.2-4.7.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * libwebkit2gtk-4_0-37-2.44.2-4.7.1 * libwebkit2gtk-4_0-37-debuginfo-2.44.2-4.7.1 * typelib-1_0-JavaScriptCore-4_0-2.44.2-4.7.1 * webkit2gtk3-debugsource-2.44.2-4.7.1 * typelib-1_0-WebKit2WebExtension-4_0-2.44.2-4.7.1 * webkit2gtk-4_0-injected-bundles-2.44.2-4.7.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.44.2-4.7.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.44.2-4.7.1 * typelib-1_0-WebKit2-4_0-2.44.2-4.7.1 * libjavascriptcoregtk-4_0-18-2.44.2-4.7.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * libwebkit2gtk3-lang-2.44.2-4.7.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * libjavascriptcoregtk-4_0-18-32bit-2.44.2-4.7.1 ## References: * https://www.suse.com/security/cve/CVE-2023-42843.html * https://www.suse.com/security/cve/CVE-2023-42950.html * https://www.suse.com/security/cve/CVE-2023-42956.html * https://www.suse.com/security/cve/CVE-2024-23226.html * https://www.suse.com/security/cve/CVE-2024-23252.html * https://www.suse.com/security/cve/CVE-2024-23254.html * https://www.suse.com/security/cve/CVE-2024-23263.html * https://www.suse.com/security/cve/CVE-2024-23280.html * https://www.suse.com/security/cve/CVE-2024-23284.html * https://www.suse.com/security/cve/CVE-2024-27834.html * https://bugzilla.suse.com/show_bug.cgi?id=1215868 * https://bugzilla.suse.com/show_bug.cgi?id=1215869 * https://bugzilla.suse.com/show_bug.cgi?id=1215870 * https://bugzilla.suse.com/show_bug.cgi?id=1218033 *https://bugzilla.suse.com/show_bug.cgi?id=1222905 * https://bugzilla.suse.com/show_bug.cgi?id=1225071 . Critical vulnerability patch for webkit2gtk3 resolves numerous flaws on SUSE Linux Enterprise systems. Discover the specifics today.. SUSE Enterprise, webkit2gtk3, security patch, software fixes, Linux updates. . Severity: Important. LinuxSecurity.com Team
* bsc#1202903 * bsc#1219187 Cross-References: * CVE-2022-2132 . # Security update for dpdk Announcement ID: SUSE-SU-2024:0531-1 Rating: important References: * bsc#1202903 * bsc#1219187 Cross-References: * CVE-2022-2132 CVSS scores: * CVE-2022-2132 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2022-2132 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for dpdk fixes the following issues: * Fixed a regression caused by incomplete fix for CVE-2022-2132 (bsc#1219187). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-531=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-531=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-531=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-531=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-531=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le x86_64) * dpdk-devel-19.11.4-150300.21.1 * dpdk-kmp-default-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 *dpdk-tools-debuginfo-19.11.4-150300.21.1 * dpdk-debugsource-19.11.4-150300.21.1 * dpdk-debuginfo-19.11.4-150300.21.1 * libdpdk-20_0-19.11.4-150300.21.1 * dpdk-devel-debuginfo-19.11.4-150300.21.1 * dpdk-tools-19.11.4-150300.21.1 * dpdk-examples-debuginfo-19.11.4-150300.21.1 * dpdk-examples-19.11.4-150300.21.1 * dpdk-19.11.4-150300.21.1 * libdpdk-20_0-debuginfo-19.11.4-150300.21.1 * openSUSE Leap 15.3 (noarch) * dpdk-doc-19.11.4-150300.21.1 * dpdk-thunderx-doc-19.11.4-150300.21.1 * openSUSE Leap 15.3 (aarch64 x86_64) * dpdk-kmp-preempt-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-kmp-preempt-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 * openSUSE Leap 15.3 (aarch64) * dpdk-thunderx-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-devel-19.11.4-150300.21.1 * dpdk-thunderx-kmp-default-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-thunderx-debugsource-19.11.4-150300.21.1 * dpdk-thunderx-kmp-preempt-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-thunderx-19.11.4-150300.21.1 * dpdk-thunderx-examples-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-devel-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-tools-19.11.4-150300.21.1 * dpdk-thunderx-kmp-preempt-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-thunderx-examples-19.11.4-150300.21.1 * dpdk-thunderx-tools-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-kmp-default-19.11.4_k5.3.18_150300.59.147-150300.21.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * dpdk-devel-19.11.4-150300.21.1 * dpdk-kmp-default-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-tools-debuginfo-19.11.4-150300.21.1 * dpdk-debugsource-19.11.4-150300.21.1 * dpdk-debuginfo-19.11.4-150300.21.1 * libdpdk-20_0-19.11.4-150300.21.1 * dpdk-devel-debuginfo-19.11.4-150300.21.1 * dpdk-tools-19.11.4-150300.21.1 * dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 *dpdk-19.11.4-150300.21.1 * libdpdk-20_0-debuginfo-19.11.4-150300.21.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64) * dpdk-thunderx-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-devel-19.11.4-150300.21.1 * dpdk-thunderx-kmp-default-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-thunderx-debugsource-19.11.4-150300.21.1 * dpdk-thunderx-19.11.4-150300.21.1 * dpdk-thunderx-devel-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-kmp-default-19.11.4_k5.3.18_150300.59.147-150300.21.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le x86_64) * dpdk-devel-19.11.4-150300.21.1 * dpdk-kmp-default-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-tools-debuginfo-19.11.4-150300.21.1 * dpdk-debugsource-19.11.4-150300.21.1 * dpdk-debuginfo-19.11.4-150300.21.1 * libdpdk-20_0-19.11.4-150300.21.1 * dpdk-devel-debuginfo-19.11.4-150300.21.1 * dpdk-tools-19.11.4-150300.21.1 * dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-19.11.4-150300.21.1 * libdpdk-20_0-debuginfo-19.11.4-150300.21.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64) * dpdk-thunderx-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-devel-19.11.4-150300.21.1 * dpdk-thunderx-kmp-default-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-thunderx-debugsource-19.11.4-150300.21.1 * dpdk-thunderx-19.11.4-150300.21.1 * dpdk-thunderx-devel-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-kmp-default-19.11.4_k5.3.18_150300.59.147-150300.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * dpdk-devel-19.11.4-150300.21.1 * dpdk-kmp-default-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-tools-debuginfo-19.11.4-150300.21.1 * dpdk-debugsource-19.11.4-150300.21.1 * dpdk-debuginfo-19.11.4-150300.21.1 * libdpdk-20_0-19.11.4-150300.21.1 * dpdk-devel-debuginfo-19.11.4-150300.21.1 * dpdk-tools-19.11.4-150300.21.1 *dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-19.11.4-150300.21.1 * libdpdk-20_0-debuginfo-19.11.4-150300.21.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * dpdk-devel-19.11.4-150300.21.1 * dpdk-kmp-default-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-tools-debuginfo-19.11.4-150300.21.1 * dpdk-debugsource-19.11.4-150300.21.1 * dpdk-debuginfo-19.11.4-150300.21.1 * libdpdk-20_0-19.11.4-150300.21.1 * dpdk-devel-debuginfo-19.11.4-150300.21.1 * dpdk-tools-19.11.4-150300.21.1 * dpdk-kmp-default-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-19.11.4-150300.21.1 * libdpdk-20_0-debuginfo-19.11.4-150300.21.1 * SUSE Enterprise Storage 7.1 (aarch64) * dpdk-thunderx-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-devel-19.11.4-150300.21.1 * dpdk-thunderx-kmp-default-debuginfo-19.11.4_k5.3.18_150300.59.147-150300.21.1 * dpdk-thunderx-debugsource-19.11.4-150300.21.1 * dpdk-thunderx-19.11.4-150300.21.1 * dpdk-thunderx-devel-debuginfo-19.11.4-150300.21.1 * dpdk-thunderx-kmp-default-19.11.4_k5.3.18_150300.59.147-150300.21.1 ## References: * https://www.suse.com/security/cve/CVE-2022-2132.html * https://bugzilla.suse.com/show_bug.cgi?id=1202903 * https://bugzilla.suse.com/show_bug.cgi?id=1219187 . A recent SUSE patch addresses a significant vulnerability within dpdk. Comprehensive guidelines for applying the update are provided within this notice.. SUSE Update, DPDK Security, OpenSUSE Patch, Linux Enterprise, Security Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.