An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 54 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:02418-1 Release Date: 2025-07-21T08:04:41Z Rating: important References: * bsc#1238912 * bsc#1238920 * bsc#1243648 Cross-References: * CVE-2022-49465 * CVE-2024-56558 * CVE-2025-21772 CVSS scores: * CVE-2022-49465 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2022-49465 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-49465 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56558 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56558 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-56558 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21772 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-21772 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves three vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_195 fixes several issues. The following security issues were fixed: * CVE-2022-49465: blk-throttle: Set BIO_THROTTLED when bio has been throttled (bsc#1238920). * CVE-2025-21772: partitions: mac: fix handling of bogus partition table (bsc#1238912). * CVE-2024-56558: nfsd: make sure exp active before svc_export_show (bsc#1243648). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or"zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-2418=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-2418=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP3_Update_54-debugsource-4-150300.2.1 * kernel-livepatch-5_3_18-150300_59_195-default-debuginfo-4-150300.2.1 * kernel-livepatch-5_3_18-150300_59_195-default-4-150300.2.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_195-preempt-4-150300.2.1 * kernel-livepatch-5_3_18-150300_59_195-preempt-debuginfo-4-150300.2.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_195-default-4-150300.2.1 ## References: * https://www.suse.com/security/cve/CVE-2022-49465.html * https://www.suse.com/security/cve/CVE-2024-56558.html * https://www.suse.com/security/cve/CVE-2025-21772.html * https://bugzilla.suse.com/show_bug.cgi?id=1238912 * https://bugzilla.suse.com/show_bug.cgi?id=1238920 * https://bugzilla.suse.com/show_bug.cgi?id=1243648 . Mandatory patch release for Fedora Linux Kernel addressing a range of security flaws jeopardizing system stability.. openSUSE security update, Linux Kernel issues, security patches, system vulnerabilities. . Severity: Important. LinuxSecurity.com Team
A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix client. (CVE-2024-10394) An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash. (CVE-2024-10396) A malicious server can crash the OpenAFS cache manager and other client . MGASA-2025-0013 - Updated openafs packages fix security vulnerabilities Publication date: 18 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0013.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-10394, CVE-2024-10396, CVE-2024-10397 A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix client. (CVE-2024-10394) An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash. (CVE-2024-10396) A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code. (CVE-2024-10397) References: - https://bugs.mageia.org/show_bug.cgi?id=33916 - https://www.cve.org/CVERecord?id=CVE-2024-10394 - https://www.cve.org/CVERecord?id=CVE-2024-10396 - https://www.cve.org/CVERecord?id=CVE-2024-10397 SRPMS: - 9/core/openafs-1.8.13.1-1.mga9 . Local users may leverage vulnerabilities in OpenAFS to circumvent security protocols, resulting in possible system failures and the execution of unauthorized commands.. OpenAFS Vulnerability, Mageia Advisory, Process Authentication Group, Security Updates. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.