suse-su-2024:4316-1
Vulnerability from csaf_suse
Published
2024-12-13 15:24
Modified
2024-12-13 15:24
Summary
Security update for the Linux Kernel
Notes
Title of the patch
Security update for the Linux Kernel
Description of the patch
The SUSE Linux Enterprise 15 SP6 Azure kernel was updated to receive various security bugfixes.
The following security bugs were fixed:
- CVE-2023-52778: mptcp: deal with large GSO size (bsc#1224948).
- CVE-2023-52920: bpf: support non-r10 register spill/fill to/from stack in precision tracking (bsc#1232823).
- CVE-2024-26596: net: dsa: fix netdev_priv() dereference before check on non-DSA netdevice events (bsc#1220355).
- CVE-2024-26741: dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished() (bsc#1222587).
- CVE-2024-26782: mptcp: fix double-free on socket dismantle (bsc#1222590).
- CVE-2024-26953: net: esp: fix bad handling of pages from page_pool (bsc#1223656).
- CVE-2024-27017: netfilter: nft_set_pipapo: walk over current view on netlink dump (bsc#1223733).
- CVE-2024-35888: erspan: make sure erspan_base_hdr is present in skb->head (bsc#1224518).
- CVE-2024-36000: mm/hugetlb: fix missing hugetlb_lock for resv uncharge (bsc#1224548).
- CVE-2024-36883: net: fix out-of-bounds access in ops_init (bsc#1225725).
- CVE-2024-36886: tipc: fix UAF in error path (bsc#1225730).
- CVE-2024-36905: tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets (bsc#1225742).
- CVE-2024-36927: ipv4: Fix uninit-value access in __ip_make_skb() (bsc#1225813).
- CVE-2024-36954: tipc: fix a possible memleak in tipc_buf_append (bsc#1225764).
- CVE-2024-36968: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() (bsc#1226130).
- CVE-2024-38589: netrom: fix possible dead-lock in nr_rt_ioctl() (bsc#1226748).
- CVE-2024-40914: mm/huge_memory: do not unpoison huge_zero_folio (bsc#1227842).
- CVE-2024-41023: sched/deadline: Fix task_struct reference leak (bsc#1228430).
- CVE-2024-42102: Revert 'mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again' (bsc#1233132).
- CVE-2024-44995: net: hns3: fix a deadlock problem when config TC during resetting (bsc#1230231).
- CVE-2024-46680: Bluetooth: btnxpuart: Fix random crash seen while removing driver (bsc#1230557).
- CVE-2024-46681: pktgen: use cpus_read_lock() in pg_net_init() (bsc#1230558).
- CVE-2024-46765: ice: protect XDP configuration with a mutex (bsc#1230807).
- CVE-2024-46800: sch/netem: fix use after free in netem_dequeue (bsc#1230827).
- CVE-2024-47679: vfs: fix race between evice_inodes() and find_inode()&iput() (bsc#1231930).
- CVE-2024-47701: ext4: avoid OOB when system.data xattr changes underneath the filesystem (bsc#1231920).
- CVE-2024-47703: bpf, lsm: add check for BPF LSM return value (bsc#1231946).
- CVE-2024-49868: btrfs: fix a NULL pointer dereference when failed to start a new trasacntion (bsc#1232272).
- CVE-2024-49888: bpf: Fix a sdiv overflow issue (bsc#1232208).
- CVE-2024-49899: drm/amd/display: Initialize denominators' default to 1 (bsc#1232358).
- CVE-2024-49911: drm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func (bsc#1232366).
- CVE-2024-49912: drm/amd/display: Handle null 'stream_status' in 'planes_changed_for_existing_stream' (bsc#1232367).
- CVE-2024-49921: drm/amd/display: Check null pointers before used (bsc#1232371).
- CVE-2024-49922: drm/amd/display: Check null pointers before using them (bsc#1232374).
- CVE-2024-49923: drm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags (bsc#1232361).
- CVE-2024-49925: fbdev: efifb: Register sysfs groups through driver core (bsc#1232224)
- CVE-2024-49933: blk_iocost: fix more out of bound shifts (bsc#1232368).
- CVE-2024-49934: fs/inode: Prevent dump_mapping() accessing invalid dentry.d_name.name (bsc#1232387).
- CVE-2024-49944: sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start (bsc#1232166).
- CVE-2024-49945: net/ncsi: Disable the ncsi work before freeing the associated structure (bsc#1232165).
- CVE-2024-49952: netfilter: nf_tables: prevent nf_skb_duplicated corruption (bsc#1232157).
- CVE-2024-49968: ext4: filesystems without casefold feature cannot be mounted with siphash (bsc#1232264).
- CVE-2024-49983: ext4: drop ppath from ext4_ext_replay_update_ex() to avoid double-free (bsc#1232096).
- CVE-2024-49987: bpftool: Fix undefined behavior in qsort(NULL, 0, ...) (bsc#1232258).
- CVE-2024-49989: drm/amd/display: fix double free issue during amdgpu module unload (bsc#1232483).
- CVE-2024-50003: drm/amd/display: Fix system hang while resume with TBT monitor (bsc#1232385).
- CVE-2024-50004: drm/amd/display: update DML2 policy EnhancedPrefetchScheduleAccelerationFinal DCN35 (bsc#1232396).
- CVE-2024-50006: ext4: fix i_data_sem unlock order in ext4_ind_migrate() (bsc#1232442).
- CVE-2024-50009: cpufreq: amd-pstate: add check for cpufreq_cpu_get's return value (bsc#1232318).
- CVE-2024-50012: cpufreq: Avoid a bad reference count on CPU node (bsc#1232386).
- CVE-2024-50014: ext4: fix access to uninitialised lock in fc replay path (bsc#1232446).
- CVE-2024-50082: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race (bsc#1232500).
- CVE-2024-50084: net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test() (bsc#1232494).
- CVE-2024-50087: btrfs: fix uninitialized pointer free on read_alloc_one_name() error (bsc#1232499).
- CVE-2024-50088: btrfs: fix uninitialized pointer free in add_inode_ref() (bsc#1232498).
- CVE-2024-50098: scsi: ufs: core: Set SDEV_OFFLINE when UFS is shut down (bsc#1232881).
- CVE-2024-50110: xfrm: fix one more kernel-infoleak in algo dumping (bsc#1232885).
- CVE-2024-50115: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory (bsc#1232919).
- CVE-2024-50124: Bluetooth: ISO: Fix UAF on iso_sock_timeout (bsc#1232926).
- CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout (bsc#1232928).
- CVE-2024-50127: net: sched: fix use-after-free in taprio_change() (bsc#1232907).
- CVE-2024-50128: net: wwan: fix global oob in wwan_rtnl_policy (bsc#1232905).
- CVE-2024-50130: netfilter: bpf: must hold reference on net namespace (bsc#1232894).
- CVE-2024-50138: bpf: Use raw_spinlock_t in ringbuf (bsc#1232935).
- CVE-2024-50139: KVM: arm64: Fix shift-out-of-bounds bug (bsc#1233062).
- CVE-2024-50145: octeon_ep: add SKB allocation failures handling in __octep_oq_process_rx() (bsc#1233044).
- CVE-2024-50153: scsi: target: core: Fix null-ptr-deref in target_alloc_device() (bsc#1233061).
- CVE-2024-50154: tcp/dccp: Do not use timer_pending() in reqsk_queue_unlink() (bsc#1233070).
- CVE-2024-50166: fsl/fman: Fix refcount handling of fman-related devices (bsc#1233050).
- CVE-2024-50167: be2net: fix potential memory leak in be_xmit() (bsc#1233049).
- CVE-2024-50169: vsock: Update rx_bytes on read_skb() (bsc#1233320).
- CVE-2024-50171: net: systemport: fix potential memory leak in bcm_sysport_xmit() (bsc#1233057).
- CVE-2024-50177: drm/amd/display: fix a UBSAN warning in DML2.1 (bsc#1233115).
- CVE-2024-50182: secretmem: disable memfd_secret() if arch cannot set direct map (bsc#1233129).
- CVE-2024-50184: virtio_pmem: Check device status before requesting flush (bsc#1233135).
- CVE-2024-50186: net: explicitly clear the sk pointer, when pf->create fails (bsc#1233110).
- CVE-2024-50192: irqchip/gic-v4: Do not allow a VMOVP on a dying VPE (bsc#1233106).
- CVE-2024-50225: btrfs: fix error propagation of split bios (bsc#1233193).
- CVE-2024-50228: mm: shmem: fix data-race in shmem_getattr() (bsc#1233204).
- CVE-2024-50230: nilfs2: fix kernel bug due to missing clearing of checked flag (bsc#1233206).
- CVE-2024-50245: fs/ntfs3: Fix possible deadlock in mi_read (bsc#1233203).
- CVE-2024-50246: fs/ntfs3: Add rough attr alloc_size check (bsc#1233207).
- CVE-2024-50248: ntfs3: add bounds checking to mi_enum_attr() (bsc#1233219).
- CVE-2024-50250: fsdax: dax_unshare_iter needs to copy entire blocks (bsc#1233226).
- CVE-2024-50252: mlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address (bsc#1233201).
- CVE-2024-50257: netfilter: Fix use-after-free in get_info() (bsc#1233244).
- CVE-2024-50261: macsec: Fix use-after-free while sending the offloading packet (bsc#1233253).
- CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans (bsc#1233453).
- CVE-2024-50271: signal: restore the override_rlimit logic (bsc#1233460).
- CVE-2024-50273: btrfs: reinitialize delayed ref list after deleting it from the list (bsc#1233462).
- CVE-2024-50274: idpf: avoid vport access in idpf_get_link_ksettings (bsc#1233463).
- CVE-2024-50275: arm64/sve: Discard stale CPU state when handling SVE traps (bsc#1233464).
- CVE-2024-50276: net: vertexcom: mse102x: Fix possible double free of TX skb (bsc#1233465).
- CVE-2024-50279: dm cache: fix out-of-bounds access to the dirty bitset when resizing (bsc#1233468).
- CVE-2024-50289: media: av7110: fix a spectre vulnerability (bsc#1233478).
- CVE-2024-50295: net: arc: fix the device for dma_map_single/dma_unmap_single (bsc#1233484).
- CVE-2024-50296: net: hns3: fix kernel crash when uninstalling driver (bsc#1233485).
- CVE-2024-50298: net: enetc: allocate vf_state during PF probes (bsc#1233487).
- CVE-2024-53042: ipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_init_flow() (bsc#1233540).
- CVE-2024-53043: mctp i2c: handle NULL header address (bsc#1233523).
- CVE-2024-53048: ice: fix crash on probe for DPLL enabled E810 LOM (bsc#1233721).
- CVE-2024-53051: drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability (bsc#1233547).
- CVE-2024-53055: wifi: iwlwifi: mvm: fix 6 GHz scan construction (bsc#1233550).
- CVE-2024-53056: drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy() (bsc#1233568).
- CVE-2024-53058: net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data (bsc#1233552).
- CVE-2024-53079: mm/thp: fix deferred split unqueue naming and locking (bsc#1233570).
- CVE-2024-53082: virtio_net: Add hash_key_length check (bsc#1233573).
- CVE-2024-53095: smb: client: Fix use-after-free of network namespace (bsc#1233642).
- CVE-2024-53110: vp_vdpa: fix id_table array not null terminated error (bsc#1234085).
- CVE-2024-53121: net/mlx5: fs, lock FTE when checking if active (bsc#1234078).
- CVE-2024-53138: net/mlx5e: kTLS, Fix incorrect page refcounting (bsc#1234223).
The following non-security bugs were fixed:
- ACPI: CPPC: Fix _CPC register setting issue (git-fixes).
- ALSA: 6fire: Release resources at card release (git-fixes).
- ALSA: ac97: bus: Fix the mistake in the comment (git-fixes).
- ALSA: caiaq: Use snd_card_free_when_closed() at disconnection (git-fixes).
- ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init() (git-fixes).
- ALSA: hda/conexant: fix Z60MR100 startup pop issue (stable-fixes).
- ALSA: hda/realtek - Fixed Clevo platform headset Mic issue (stable-fixes).
- ALSA: hda/realtek - update set GPIO3 to default for Thinkpad with ALC1318 (git-fixes).
- ALSA: hda/realtek: Add support for Samsung Galaxy Book3 360 (NP730QFG) (stable-fixes).
- ALSA: hda/realtek: Apply quirk for Medion E15433 (bsc#1233298).
- ALSA: hda/realtek: Enable mute and micmute LED on HP ProBook 430 G8 (stable-fixes).
- ALSA: hda/realtek: Enable speaker pins for Medion E15443 platform (bsc#1233298).
- ALSA: hda/realtek: Fix Internal Speaker and Mic boost of Infinix Y4 Max (bsc#1233298).
- ALSA: hda/realtek: Set PCBeep to default value for ALC274 (stable-fixes).
- ALSA: hda/realtek: Update ALC225 depop procedure (git-fixes).
- ALSA: hda/realtek: Update ALC256 depop procedure (git-fixes).
- ALSA: hda/realtek: fix mute/micmute LEDs for a HP EliteBook 645 G10 (stable-fixes).
- ALSA: hda: Poll jack events for LS7A HD-Audio (stable-fixes).
- ALSA: hda: Show the codec quirk info at probing (stable-fixes).
- ALSA: ice1712: Remove redundant code in stac9460_dac_vol_put (stable-fixes).
- ALSA: pcm: Add sanity NULL check for the default mmap fault handler (stable-fixes).
- ALSA: ump: Fix evaluation of MIDI 1.0 FB info (git-fixes).
- ALSA: us122l: Use snd_card_free_when_closed() at disconnection (git-fixes).
- ALSA: usb-audio: Add Pioneer DJ/AlphaTheta DJM-A9 Mixer (stable-fixes).
- ALSA: usb-audio: Fix Yamaha P-125 Quirk Entry (stable-fixes).
- ALSA: usb-audio: Fix a DMA to stack memory bug (git-fixes).
- ALSA: usb-audio: Fix out of bounds reads when finding clock sources (stable-fixes).
- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (git-fixes).
- ALSA: usb-audio: Make mic volume workarounds globally applicable (stable-fixes).
- ALSA: usb-audio: Use snprintf instead of sprintf in build_mixer_unit_ctl (stable-fixes).
- ALSA: usb-audio: add mixer mapping for Corsair HS80 (stable-fixes).
- ALSA: usx2y: Use snd_card_free_when_closed() at disconnection (git-fixes).
- ASoC: Intel: avs: da7219: Remove suspend_pre() and resume_post() (stable-fixes).
- ASoC: SOF: Add i2s bt dai configuration support for AMD platforms (bsc#1233305).
- ASoC: SOF: Add support for configuring PDM interface from topology (bsc#1233305).
- ASoC: SOF: Deprecate invalid enums in IPC3 (bsc#1233305).
- ASoC: SOF: IPC4: get pipeline priority from topology (bsc#1233305).
- ASoC: SOF: IPC4: synchronize fw_config_params with fw definitions (bsc#1233305).
- ASoC: SOF: Refactor sof_i2s_tokens reading to update acpbt dai (bsc#1233305).
- ASoC: SOF: Rename amd_bt sof_dai_type (bsc#1233305).
- ASoC: SOF: Wire up buffer flags (bsc#1233305).
- ASoC: SOF: add alignment for topology header file struct definition (bsc#1233305).
- ASoC: SOF: align topology header file with sof topology header (bsc#1233305).
- ASoC: SOF: ipc3-topology: Convert the topology pin index to ALH dai index (git-fixes).
- ASoC: SOF: ipc3-topology: fix resource leaks in sof_ipc3_widget_setup_comp_dai() (git-fixes).
- ASoC: SOF: ipc4-control: Add support for ALSA enum control (bsc#1233305).
- ASoC: SOF: ipc4-control: Add support for ALSA switch control (bsc#1233305).
- ASoC: SOF: ipc4-mtrace: move debug slot related definitions to header.h (bsc#1233305).
- ASoC: SOF: ipc4-topology: Add deep buffer size to debug prints (bsc#1233305).
- ASoC: SOF: ipc4-topology: Add definition for generic switch/enum control (bsc#1233305).
- ASoC: SOF: ipc4-topology: Add module ID print during module set up (bsc#1233305).
- ASoC: SOF: ipc4-topology: Helper to find an swidget by module/instance id (bsc#1233305).
- ASoC: SOF: ipc4-topology: Only handle dai_config with HW_PARAMS for ChainDMA (bsc#1233305).
- ASoC: SOF: ipc4-topology: change chain_dma handling in dai_config (bsc#1233305).
- ASoC: SOF: ipc4-topology: export sof_ipc4_copier_is_single_format (bsc#1233305).
- ASoC: SOF: ipc4-topology: set config_length based on device_count (bsc#1233305).
- ASoC: SOF: ipc4: Add data struct for module notification message from firmware (bsc#1233305).
- ASoC: SOF: ipc4: Add new message type: SOF_IPC4_GLB_LOAD_LIBRARY_PREPARE (bsc#1233305).
- ASoC: SOF: sof-client-probes-ipc4: Set param_size extension bits (git-fixes).
- ASoC: SOF: topology: Parse DAI type token for dspless mode (bsc#1233305).
- ASoC: SOF: topology: dynamically allocate and store DAI widget->private (bsc#1233305).
- ASoC: amd: yc: Add quirk for ASUS Vivobook S15 M3502RA (stable-fixes).
- ASoC: amd: yc: Fix for enabling DMIC on acp6x via _DSD entry (git-fixes).
- ASoC: amd: yc: Fix non-functional mic on ASUS E1404FA (stable-fixes).
- ASoC: amd: yc: Support dmic on another model of Lenovo Thinkpad E14 Gen 6 (stable-fixes).
- ASoC: amd: yc: fix internal mic on Xiaomi Book Pro 14 2022 (stable-fixes).
- ASoC: audio-graph-card2: Purge absent supplies for device tree nodes (stable-fixes).
- ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata() (git-fixes).
- ASoC: fsl_micfil: Add sample rate constraint (stable-fixes).
- ASoC: fsl_micfil: fix regmap_write_bits usage (git-fixes).
- ASoC: mediatek: mt8188-mt6359: Remove hardcoded dmic codec (git-fixes).
- ASoC: rt722-sdca: Remove logically deadcode in rt722-sdca.c (git-fixes).
- ASoC: rt722-sdca: increase clk_stop_timeout to fix clock stop issue (stable-fixes).
- ASoC: stm32: spdifrx: fix dma channel release in stm32_spdifrx_remove (git-fixes).
- ASoC: stm: Prevent potential division by zero in stm32_sai_get_clk_div() (stable-fixes).
- ASoC: stm: Prevent potential division by zero in stm32_sai_mclk_round_rate() (stable-fixes).
- ASoC: tas2781: Add new driver version for tas2563 & tas2781 qfn chip (stable-fixes).
- Bluetooth: MGMT: Fix slab-use-after-free Read in set_powered_sync (git-fixes).
- Bluetooth: btintel: Direct exception event to bluetooth stack (git-fixes).
- Bluetooth: btnxpuart: Resolve TX timeout error in power save stress test (bsc#1230557)
- Bluetooth: fix use-after-free in device_for_each_child() (git-fixes).
- Bluetooth: hci_core: Fix calling mgmt_device_connected (git-fixes).
- Documentation: kgdb: Correct parameter error (git-fixes).
- Drop OCFS2 patch causing a regression (bsc#1233255)
- HID: core: zero-initialize the report buffer (git-fixes).
- HID: lenovo: Add support for Thinkpad X1 Tablet Gen 3 keyboard (stable-fixes).
- HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad (stable-fixes).
- HID: multitouch: Add quirk for Logitech Bolt receiver w/ Casa touchpad (stable-fixes).
- HID: multitouch: Add support for B2402FVA track point (stable-fixes).
- HID: wacom: Interpret tilt data from Intuos Pro BT as signed values (git-fixes).
- HID: wacom: fix when get product name maybe null pointer (git-fixes).
- Input: hideep - add missing dependency on REGMAP_I2C (git-fixes).
- Input: hycon-hy46xx - add missing dependency on REGMAP_I2C (git-fixes).
- Input: xpad - add GameSir T4 Kaleid Controller support (git-fixes).
- Input: xpad - add GameSir VID for Xbox One controllers (git-fixes).
- Input: xpad - add support for 8BitDo Ultimate 2C Wireless Controller (git-fixes).
- Input: xpad - add support for MSI Claw A1M (git-fixes).
- Input: xpad - add support for Machenike G5 Pro Controller (git-fixes).
- Input: xpad - fix support for some third-party controllers (git-fixes).
- Input: xpad - sort xpad_device by vendor and product ID (git-fixes).
- Input: xpad - spelling fixes for 'Xbox' (git-fixes).
- KVM: PPC: Book3S HV: Avoid returning to nested hypervisor on pending doorbells (bsc#1215199).
- KVM: PPC: Book3S HV: Stop using vc->dpdes for nested KVM guests (bsc#1215199).
- KVM: PPC: Book3S HV: remove unused varible (bsc#1194869).
- KVM: SEV-ES: Fix svm_get_msr()/svm_set_msr() for KVM_SEV_ES_INIT guests (bsc#1232207).
- KVM: SEV-ES: Prevent MSR access post VMSA encryption (bsc#1232207).
- Move kabi netfilter fix into patches.kabi
- Move upstreamed crypto patches into sorted section
- Move upstreamed patches into sorted section
- NFS: remove revoked delegation from server's delegation list (git-fixes).
- PCI: Add T_PVPERL macro (git-fixes).
- PCI: Fix reset_method_store() memory leak (git-fixes).
- PCI: endpoint: Clear secondary (not primary) EPC in pci_epc_remove_epf() (git-fixes).
- PCI: j721e: Deassert PERST# after a delay of PCIE_T_PVPERL_MS milliseconds (git-fixes).
- PCI: keystone: Add link up check to ks_pcie_other_map_bus() (git-fixes).
- PCI: keystone: Set mode as Root Complex for 'ti,keystone-pcie' compatible (git-fixes).
- PCI: rockchip-ep: Fix address translation unit programming (git-fixes).
- RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey (git-fixes)
- RDMA/hns: Add mutex_destroy() (git-fixes)
- RDMA/hns: Disassociate mmap pages for all uctx when HW is being reset (git-fixes)
- RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() (git-fixes)
- RDMA/hns: Fix an AEQE overflow error caused by untimely update of eq_db_ci (git-fixes)
- RDMA/hns: Fix cpu stuck caused by printings during reset (git-fixes)
- RDMA/hns: Fix different dgids mapping to the same dip_idx (git-fixes)
- RDMA/hns: Fix flush cqe error when racing with destroy qp (git-fixes)
- RDMA/hns: Fix out-of-order issue of requester when setting FENCE (git-fixes)
- RDMA/hns: Use dev_* printings in hem code instead of ibdev_* (git-fixes)
- RDMA/hns: Use macro instead of magic number (git-fixes)
- RDMA/mlx5: Move events notifier registration to be after device registration (git-fixes)
- RDMA/rxe: Fix the qp flush warnings in req (git-fixes)
- RDMA/rxe: Set queue pair cur_qp_state when being queried (git-fixes)
- RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES (git-fixes)
- Revert 'KVM: PPC: Book3S HV Nested: Stop forwarding all HFUs to L1' (bsc#1215199).
- Revert 'RDMA/core: Fix ENODEV error for iWARP test over vlan' (git-fixes)
- Revert 'cgroup: Fix memory leak caused by missing cgroup_bpf_offline' (bsc#1234108).
- Revert 'cpufreq: brcmstb-avs-cpufreq: Fix initial command check' (stable-fixes).
- Revert 'mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K' (git-fixes).
- Revert 'usb: gadget: composite: fix OS descriptors w_value logic' (git-fixes).
- SUNRPC: Remove BUG_ON call sites (git-fixes).
- USB: chaoskey: Fix possible deadlock chaoskey_list_lock (git-fixes).
- USB: chaoskey: fail open after removal (git-fixes).
- USB: gadget: dummy-hcd: Fix 'task hung' problem (git-fixes).
- USB: serial: ftdi_sio: Fix atomicity violation in get_serial_info() (git-fixes).
- USB: serial: io_edgeport: fix use after free in debug printk (git-fixes).
- USB: serial: option: add Fibocom FG132 0x0112 composition (stable-fixes).
- USB: serial: option: add Quectel RG650V (stable-fixes).
- USB: serial: qcserial: add support for Sierra Wireless EM86xx (stable-fixes).
- Update config files (bsc#1218644).
- Update config files. Enabled IDPF for ARM64 (bsc#1221309)
- accel: Use XArray instead of IDR for minors (jsc#PED-11580).
- acpi/arm64: Adjust error handling procedure in gtdt_parse_timer_block() (git-fixes).
- ad7780: fix division by zero in ad7780_write_raw() (git-fixes).
- add bugreference to a hv_netvsc patch (bsc#1232413).
- aes-gcm-p10: Use the correct bit to test for P10 (bsc#1232704).
- amd-pstate: Set min_perf to nominal_perf for active mode performance gov (git-fixes).
- apparmor: fix 'Do simple duplicate message elimination' (git-fixes).
- apparmor: test: Fix memory leak for aa_unpack_strdup() (git-fixes).
- apparmor: use kvfree_sensitive to free data->data (git-fixes).
- arm64: dts: allwinner: pinephone: Add mount matrix to accelerometer (git-fixes)
- arm64: dts: freescale: imx8mm-verdin: Fix SD regulator startup delay (git-fixes)
- arm64: dts: freescale: imx8mp-verdin: Fix SD regulator startup delay (git-fixes)
- arm64: dts: imx8-ss-vpu: Fix imx8qm VPU IRQs (git-fixes)
- arm64: dts: imx8qxp: Add VPU subsystem file (git-fixes)
- arm64: dts: imx93: add nvmem property for eqos (git-fixes)
- arm64: dts: imx93: add nvmem property for fec1 (git-fixes)
- arm64: dts: imx93: add ocotp node (git-fixes)
- arm64: dts: rockchip: Add DTS for FriendlyARM NanoPi R2S Plus (git-fixes)
- arm64: dts: rockchip: Correct GPIO polarity on brcm BT nodes (git-fixes)
- arm64: dts: rockchip: Fix LED triggers on rk3308-roc-cc (git-fixes)
- arm64: dts: rockchip: Fix bluetooth properties on Rock960 boards (git-fixes)
- arm64: dts: rockchip: Fix bluetooth properties on rk3566 box demo (git-fixes)
- arm64: dts: rockchip: Fix reset-gpios property on brcm BT nodes (git-fixes)
- arm64: dts: rockchip: Fix rt5651 compatible value on (git-fixes)
- arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-eaidk-610 (git-fixes)
- arm64: dts: rockchip: Fix wakeup prop names on PineNote BT node (git-fixes)
- arm64: dts: rockchip: Remove #cooling-cells from fan on Theobroma (git-fixes)
- arm64: dts: rockchip: Remove hdmi's 2nd interrupt on rk3328 (git-fixes)
- arm64: dts: rockchip: Remove undocumented supports-emmc property (git-fixes)
- arm64: dts: rockchip: fix i2c2 pinctrl-names property on (git-fixes)
- arm64: dts: rockchip: remove num-slots property from (git-fixes)
- arm64: dts: rockchip: remove orphaned pinctrl-names from pinephone (git-fixes)
- arm64: fix .data.rel.ro size assertion when CONFIG_LTO_CLANG (git-fixes)
- arm64: smccc: Remove broken support for SMCCCv1.3 SVE discard hint (git-fixes)
- arm64: smccc: replace custom COUNT_ARGS() & CONCATENATE() (git-fixes)
- arm64: tegra: Move AGX Orin nodes to correct location (git-fixes)
- arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled (git-fixes)
- bpf, arm64: Fix address emission with tag-based KASAN enabled (git-fixes)
- bpf, arm64: Remove garbage frame for struct_ops trampoline (git-fixes)
- bpf, sockmap: SK_DROP on attempted redirects of unsupported af_vsock (git-fixes).
- bpf, vsock: Drop static vsock_bpf_prot initialization (git-fixes).
- btrfs: merge btrfs_orig_bbio_end_io() into btrfs_bio_end_io() (bsc#1233193)
- can: c_can: c_can_handle_bus_err(): update statistics if skb allocation fails (git-fixes).
- can: c_can: fix {rx,tx}_errors statistics (git-fixes).
- can: dev: can_set_termination(): allow sleeping GPIOs (git-fixes).
- can: ems_usb: ems_usb_rx_err(): fix {rx,tx}_errors statistics (git-fixes).
- can: hi311x: hi3110_can_ist(): fix potential use-after-free (git-fixes).
- can: hi311x: hi3110_can_ist(): fix {rx,tx}_errors statistics (git-fixes).
- can: ifi_canfd: ifi_canfd_handle_lec_err(): fix {rx,tx}_errors statistics (git-fixes).
- can: j1939: j1939_session_new(): fix skb reference counting (git-fixes).
- can: m_can: m_can_handle_lec_err(): fix {rx,tx}_errors statistics (git-fixes).
- can: mcp251xfd: mcp251xfd_get_tef_len(): fix length calculation (git-fixes).
- can: mcp251xfd: mcp251xfd_get_tef_len(): work around erratum DS80000789E 6 (git-fixes).
- can: mcp251xfd: mcp251xfd_ring_alloc(): fix coalescing configuration when switching CAN modes (git-fixes).
- can: sja1000: sja1000_err(): fix {rx,tx}_errors statistics (git-fixes).
- can: sun4i_can: sun4i_can_err(): call can_change_state() even if cf is NULL (git-fixes).
- can: sun4i_can: sun4i_can_err(): fix {rx,tx}_errors statistics (git-fixes).
- cgroup/bpf: only cgroup v2 can be attached by bpf programs (bsc#1234108).
- clk: clk-apple-nco: Add NULL check in applnco_probe (git-fixes).
- clk: clk-axi-clkgen: make sure to enable the AXI bus clock (git-fixes).
- clk: imx: clk-scu: fix clk enable state save and restore (git-fixes).
- clk: imx: fracn-gppll: correct PLL initialization flow (git-fixes).
- clk: imx: fracn-gppll: fix pll power up (git-fixes).
- clk: imx: lpcg-scu: SW workaround for errata (e10858) (git-fixes).
- clk: qcom: clk-alpha-pll: drop lucid-evo pll enabled warning (git-fixes).
- clk: qcom: clk-alpha-pll: fix lucid 5lpe pll enabled check (git-fixes).
- clk: qcom: gcc-qcs404: fix initial rate of GPLL3 (git-fixes).
- clk: renesas: rzg2l: Fix FOUTPOSTDIV clk (git-fixes).
- clk: sunxi-ng: d1: Fix PLL_AUDIO0 preset (git-fixes).
- comedi: Flush partial mappings in error case (git-fixes).
- cpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost() (git-fixes).
- cpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw() (git-fixes).
- cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_cost() (git-fixes).
- cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_power() (git-fixes).
- cpufreq: loongson2: Unregister platform_driver on failure (git-fixes).
- cpufreq: mediatek-hw: Fix wrong return value in mtk_cpufreq_get_cpu_power() (git-fixes).
- crypto: aes-gcm-p10 - Use the correct bit to test for P10 (bsc#1232704).
- crypto: api - Fix liveliness check in crypto_alg_tested (stable-fixes).
- crypto: bcm - add error check in the ahash_hmac_init function (git-fixes).
- crypto: caam - Fix the pointer passed to caam_qi_shutdown() (git-fixes).
- crypto: caam - add error check to caam_rsa_set_priv_key_form (git-fixes).
- crypto: cavium - Fix an error handling path in cpt_ucode_load_fw() (git-fixes).
- crypto: cavium - Fix the if condition to exit loop after timeout (git-fixes).
- crypto: inside-secure - Fix the return value of safexcel_xcbcmac_cra_init() (git-fixes).
- crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY (git-fixes).
- crypto: qat - remove check after debugfs_create_dir() (git-fixes).
- crypto: qat - remove faulty arbiter config reset (git-fixes).
- crypto: qat/qat_4xxx - fix off by one in uof_get_name() (git-fixes).
- crypto: x86/aegis128 - access 32-bit arguments as 32-bit (git-fixes).
- cxl: downgrade a warning message to debug level in cxl_probe_component_regs() (bsc#1229165).
- dma-fence: Fix reference leak on fence merge failure path (git-fixes).
- dma-fence: Use kernel's sort for merging fences (git-fixes).
- doc: rcu: update printed dynticks counter bits (git-fixes).
- drivers: soc: xilinx: add the missing kfree in xlnx_add_cb_for_suspend() (git-fixes).
- drm/amd/display: Adjust VSDB parser for replay feature (stable-fixes).
- drm/amd/display: Fix brightness level not retained over reboot (git-fixes).
- drm/amd/display: Fix null check for pipe_ctx->plane_state in dcn20_program_pipe (git-fixes).
- drm/amd/display: Fix null check for pipe_ctx->plane_state in hwss_setup_dpp (git-fixes).
- drm/amd: Add some missing straps from NBIO 7.11.0 (git-fixes).
- drm/amd: Fix initialization mistake for NBIO 7.7.0 (stable-fixes).
- drm/amdgpu: Adjust debugfs eviction and IB access permissions (stable-fixes).
- drm/amdgpu: Adjust debugfs register access permissions (stable-fixes).
- drm/amdgpu: Fix DPX valid mode check on GC 9.4.3 (git-fixes).
- drm/amdgpu: Fix JPEG v4.0.3 register write (git-fixes).
- drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read() (stable-fixes).
- drm/amdgpu: fix check in gmc_v9_0_get_vm_pte() (git-fixes).
- drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported (git-fixes).
- drm/amdkfd: Accounting pdd vram_usage for svm (stable-fixes).
- drm/amdkfd: Fix wrong usage of INIT_WORK() (git-fixes).
- drm/bridge: anx7625: Drop EDID cache on bridge power off (git-fixes).
- drm/bridge: it6505: Drop EDID cache on bridge power off (git-fixes).
- drm/bridge: tc358767: Fix link properties discovery (git-fixes).
- drm/bridge: tc358768: Fix DSI command tx (git-fixes).
- drm/etnaviv: Request pages from DMA32 zone on addressing_limited (git-fixes).
- drm/etnaviv: hold GPU lock across perfmon sampling (git-fixes).
- drm/imx/dcss: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).
- drm/imx/ipuv3: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).
- drm/mediatek: Fix child node refcount handling in early exit (git-fixes).
- drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused (git-fixes).
- drm/msm/adreno: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).
- drm/msm/dpu: cast crtc_clk calculation to u64 in _dpu_core_perf_calc_clk() (git-fixes).
- drm/msm/dpu: drop LM_3 / LM_4 on MSM8998 (git-fixes).
- drm/msm/dpu: drop LM_3 / LM_4 on SDM845 (git-fixes).
- drm/msm/dpu: on SDM845 move DSPP_3 to LM_5 block (git-fixes).
- drm/msm/gpu: Check the status of registration to PM QoS (git-fixes).
- drm/msm: Fix some typos in comment (git-fixes).
- drm/nouveau/gr/gf100: Fix missing unlock in gf100_gr_chan_new() (git-fixes).
- drm/omap: Fix locking in omap_gem_new_dmabuf() (git-fixes).
- drm/omap: Fix possible NULL dereference (git-fixes).
- drm/panfrost: Add missing OPP table refcnt decremental (git-fixes).
- drm/panfrost: Remove unused id_mask from struct panfrost_model (git-fixes).
- drm/rockchip: vop: Fix a dereferenced before check warning (git-fixes).
- drm/sti: Add __iomem for mixer_dbg_mxn's parameter (git-fixes).
- drm/sti: avoid potential dereference of error pointers (git-fixes).
- drm/sti: avoid potential dereference of error pointers in sti_gdp_atomic_check (git-fixes).
- drm/sti: avoid potential dereference of error pointers in sti_hqvdp_atomic_check (git-fixes).
- drm/v3d: Address race-condition in MMU flush (git-fixes).
- drm/v3d: Enable Performance Counters before clearing them (git-fixes).
- drm/vc4: Match drm_dev_enter and exit calls in vc4_hvs_atomic_flush (git-fixes).
- drm/vc4: Match drm_dev_enter and exit calls in vc4_hvs_lut_load (git-fixes).
- drm/vc4: hdmi: Avoid hang with debug registers when suspended (git-fixes).
- drm/vc4: hvs: Correct logic on stopping an HVS channel (git-fixes).
- drm/vc4: hvs: Do not write gamma luts on 2711 (git-fixes).
- drm/vc4: hvs: Fix dlist debug not resetting the next entry pointer (git-fixes).
- drm/vc4: hvs: Remove incorrect limit from hvs_dlist debugfs function (git-fixes).
- drm/vkms: Drop unnecessary call to drm_crtc_cleanup() (git-fixes).
- drm/vmwgfx: Limit display layout ioctl array size to VMWGFX_NUM_DISPLAY_UNITS (stable-fixes).
- drm: Expand max DRM device number to full MINORBITS (jsc#PED-11580).
- drm: Use XArray instead of IDR for minors (jsc#PED-11580).
- drm: use ATOMIC64_INIT() for atomic64_t (git-fixes).
- drm: xlnx: zynqmp_dpsub: fix hotplug detection (git-fixes).
- drm: zynqmp_kms: Unplug DRM device before removal (git-fixes).
- e1000e: Remove Meteor Lake SMBUS workarounds (git-fixes).
- efi/libstub: Free correct pointer on failure (git-fixes).
- efi/libstub: fix efi_parse_options() ignoring the default command line (git-fixes).
- efi/libstub: zboot.lds: Discard .discard sections (stable-fixes).
- efi/memattr: Ignore table if the size is clearly bogus (bsc#1231465).
- ext4: fix unttached inode after power cut with orphan file feature enabled (bsc#1234009).
- f2fs: get out of a repeat loop when getting a locked data page (bsc#1234011).
- fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem() (git-fixes).
- firmware: arm_scpi: Check the DVFS OPP count returned by the firmware (git-fixes).
- firmware: google: Unregister driver_info on failure (git-fixes).
- firmware_loader: Fix possible resource leak in fw_log_firmware_info() (git-fixes).
- fs/ntfs3: Add more attributes checks in mi_enum_attr() (bsc#1233207)
- fs/ntfs3: Fixed overflow check in mi_enum_attr() (bsc#1233207)
- fs/ntfs3: Sequential field availability check in mi_enum_attr() (bsc#1233207)
- fs: Fix uninitialized value issue in from_kuid and from_kgid (git-fixes).
- goldfish: Fix unused const variable 'goldfish_pipe_acpi_match' (git-fixes).
- gpio: exar: set value when external pull-up or pull-down is present (git-fixes).
- gpio: zevio: Add missed label initialisation (git-fixes).
- hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer (git-fixes).
- hwmon: (nct6775-core) Fix overflows seen when writing limit attributes (git-fixes).
- hwmon: (tps23861) Fix reporting of negative temperatures (git-fixes).
- i2c: designware: do not hold SCL low when I2C_DYNAMIC_TAR_UPDATE is not set (git-fixes).
- i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs() (git-fixes).
- i3c: master: svc: Fix pm_runtime_set_suspended() with runtime pm enabled (git-fixes).
- i40e: fix race condition by adding filter's intermediate sync state (git-fixes).
- iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call (git-fixes).
- igb: Disable threaded IRQ for igb_msix_other (git-fixes).
- iio: Fix fwnode_handle in __fwnode_iio_channel_get_by_name() (git-fixes).
- iio: accel: kx022a: Fix raw read format (git-fixes).
- iio: adc: ad7606: Fix typo in the driver name (git-fixes).
- iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer (git-fixes).
- iio: gts: Fix uninitialized symbol 'ret' (git-fixes).
- iio: gts: fix infinite loop for gain_to_scaletables() (git-fixes).
- iio: light: al3010: Fix an error handling path in al3010_probe() (git-fixes).
- ima: fix buffer overrun in ima_eventdigest_init_common (git-fixes).
- initramfs: avoid filename buffer overrun (bsc#1232436).
- intel_idle: add Granite Rapids Xeon support (bsc#1231630).
- intel_idle: fix ACPI _CST matching for newer Xeon platforms (bsc#1231630).
- io_uring/rw: fix missing NOWAIT check for O_DIRECT start write (git-fixes).
- io_uring/sqpoll: close race on waiting for sqring entries (git-fixes).
- irqchip/gic-v3-its: Avoid explicit cpumask allocation on stack (git-fixes).
- jbd2: Move j_transaction_overhead_buffers into a hole (bsc#1234042).
- jbd2: avoid infinite transaction commit loop (bsc#1234039).
- jbd2: avoid memleak in jbd2_journal_write_metadata_buffer (bsc#1234043).
- jbd2: avoid mount failed when commit block is partial submitted (bsc#1234040).
- jbd2: correct the printing of write_flags in jbd2_write_superblock() (bsc#1234045).
- jbd2: fix kernel-doc for j_transaction_overhead_buffers (bsc#1234042).
- jbd2: fix potential data lost in recovering journal raced with synchronizing fs bdev (bsc#1234044).
- jbd2: fix soft lockup in journal_finish_inode_data_buffers() (bsc#1234046).
- jbd2: make jbd2_journal_get_max_txn_bufs() internal (bsc#1234041).
- jbd2: precompute number of transaction descriptor blocks (bsc#1234042).
- kABI workaround for ASoC SOF (bsc#1233305).
- kABI: Restore exported __arm_smccc_sve_check (git-fixes)
- kabi, mm: refactor arch_calc_vm_flag_bits() and arm64 MTE handling (git-fixes kabi).
- kasan: move checks to do_strncpy_from_user (git-fixes).
- kernel-binary: Enable livepatch package only when livepatch is enabled Otherwise the filelist may be empty failing the build (bsc#1218644).
- kexec_file: fix elfcorehdr digest exclusion when CONFIG_CRASH_HOTPLUG=y (git-fixes).
- leds: lp55xx: Remove redundant test for invalid channel number (git-fixes).
- lib: string_helpers: silence snprintf() output truncation warning (git-fixes).
- mailbox: arm_mhuv2: clean up loop in get_irq_chan_comb() (git-fixes).
- maple_tree: fix alloc node fail issue (git-fixes).
- maple_tree: refine mas_store_root() on storing NULL (git-fixes).
- media: adv7604: prevent underflow condition when reporting colorspace (git-fixes).
- media: amphion: Fix pm_runtime_set_suspended() with runtime pm enabled (git-fixes).
- media: amphion: Set video drvdata before register video device (git-fixes).
- media: ar0521: do not overflow when checking PLL values (git-fixes).
- media: atomisp: Add check for rgby_data memory allocation failure (git-fixes).
- media: cx24116: prevent overflows on SNR calculus (git-fixes).
- media: dvb_frontend: do not play tricks with underflow values (git-fixes).
- media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set (stable-fixes).
- media: dvbdev: prevent the risk of out of memory access (git-fixes).
- media: gspca: ov534-ov772x: Fix off-by-one error in set_frame_rate() (git-fixes).
- media: i2c: dw9768: Fix pm_runtime_set_suspended() with runtime pm enabled (git-fixes).
- media: i2c: tc358743: Fix crash in the probe error path when using polling (git-fixes).
- media: imx-jpeg: Ensure power suppliers be suspended before detach them (git-fixes).
- media: imx-jpeg: Set video drvdata before register video device (git-fixes).
- media: mantis: remove orphan mantis_core.h (git-fixes).
- media: mtk-jpeg: Fix null-ptr-deref during unload module (git-fixes).
- media: platform: allegro-dvt: Fix possible memory leak in allocate_buffers_internal() (git-fixes).
- media: platform: exynos4-is: Fix an OF node reference leak in fimc_md_is_isp_available (git-fixes).
- media: pulse8-cec: fix data timestamp at pulse8_setup() (git-fixes).
- media: s5p-jpeg: prevent buffer overflows (git-fixes).
- media: stb0899_algo: initialize cfr before using it (git-fixes).
- media: ts2020: fix null-ptr-deref in ts2020_probe() (git-fixes).
- media: uvcvideo: Require entities to have a non-zero unique ID (git-fixes).
- media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (git-fixes).
- media: uvcvideo: Stop stream during unregister (git-fixes).
- media: v4l2-ctrls-api: fix error handling for v4l2_g_ctrl() (git-fixes).
- media: v4l2-tpg: prevent the risk of a division by zero (git-fixes).
- media: vb2: Fix comment (git-fixes).
- media: venus: Fix pm_runtime_set_suspended() with runtime pm enabled (git-fixes).
- media: wl128x: Fix atomicity violation in fmc_send_cmd() (git-fixes).
- mfd: rt5033: Fix missing regmap_del_irq_chip() (git-fixes).
- mfd: tps65010: Use IRQF_NO_AUTOEN flag in request_irq() to fix race (git-fixes).
- minmax: scsi: fix mis-use of 'clamp()' in sr.c (git-fixes).
- misc: apds990x: Fix missing pm_runtime_disable() (git-fixes).
- mlxbf_gige: disable RX filters until RX path initialized (git-fixes).
- mm/hugetlb: fix nodes huge page allocation when there are surplus pages (bsc#1234012).
- mm: avoid unsafe VMA hook invocation when error arises on mmap hook (git-fixes).
- mm: move dummy_vm_ops out of a header (git-fixes prerequisity).
- mm: refactor arch_calc_vm_flag_bits() and arm64 MTE handling (git-fixes).
- mm: refactor map_deny_write_exec() (git-fixes).
- mm: resolve faulty mmap_region() error path behaviour (git-fixes).
- mm: unconditionally close VMAs on error (git-fixes).
- mmc: core: Further prevent card detect during shutdown (git-fixes).
- mmc: mmc_spi: drop buggy snprintf() (git-fixes).
- mmc: sunxi-mmc: Fix A100 compatible description (git-fixes).
- modpost: remove incorrect code in do_eisa_entry() (git-fixes).
- mtd: rawnand: atmel: Fix possible memory leak (git-fixes).
- mtd: spi-nor: core: replace dummy buswidth from addr to data (git-fixes).
- net: mdio-ipq4019: add missing error check (git-fixes).
- net: phy: dp83822: Fix reset pin definitions (git-fixes).
- net: phy: ti: add PHY_RST_AFTER_CLK_EN flag (git-fixes).
- net: relax socket state check at accept time (git-fixes).
- net: usb: lan78xx: Fix double free issue with interrupt buffer allocation (git-fixes).
- net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device (git-fixes).
- net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL configuration (git-fixes).
- net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition (stable-fixes).
- net: wwan: fix global oob in wwan_rtnl_policy (git-fixes).
- net: wwan: t7xx: Fix off-by-one error in t7xx_dpmaif_rx_buf_alloc() (git-fixes).
- net: xfrm: preserve kabi for xfrm_state (bsc#1233754).
- netdevsim: copy addresses for both in and out paths (git-fixes).
- netfilter: nf_tables: missing iterator type in lookup walk (git-fixes).
- nfs: Fix KMSAN warning in decode_getfattr_attrs() (git-fixes).
- nfs: avoid i_lock contention in nfs_clear_invalid_mapping (git-fixes).
- nfsd: remove unsafe BUG_ON from set_change_info (bsc#1234121).
- nilfs2: fix potential deadlock with newly created symlinks (git-fixes).
- nouveau/dp: handle retries for AUX CH transfers with GSP (git-fixes).
- nouveau: fw: sync dma after setup is called (git-fixes).
- nouveau: handle EBUSY and EAGAIN for GSP aux errors (git-fixes).
- ntfs3: Add bounds checking to mi_enum_attr() (bsc#1233207)
- nvme-fabrics: fix kernel crash while shutting down controller (git-fixes).
- nvme-loop: flush off pending I/O while shutting down loop controller (git-fixes).
- nvme-pci: fix freeing of the HMB descriptor table (git-fixes).
- nvme-pci: reverse request order in nvme_queue_rqs (git-fixes).
- nvme/host: Fix RCU list traversal to use SRCU primitive (git-fixes).
- nvme: tcp: avoid race between queue_lock lock and destroy (git-fixes).
- ocfs2: fix UBSAN warning in ocfs2_verify_volume() (git-fixes).
- ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove() (git-fixes).
- ocfs2: uncache inode which has failed entering the group (git-fixes).
- of: Add cleanup.h based auto release via __free(device_node) markings (bsc#1232386)
- pinctrl: k210: Undef K210_PC_DEFAULT (git-fixes).
- pinctrl: qcom: spmi: fix debugfs drive strength (git-fixes).
- pinctrl: zynqmp: drop excess struct member description (git-fixes).
- platform/chrome: cros_ec_typec: fix missing fwnode reference decrement (git-fixes).
- platform/x86/amd/pmc: Detect when STB is not available (git-fixes).
- platform/x86: panasonic-laptop: Return errno correctly in show callback (git-fixes).
- posix-cpu-timers: Clear TICK_DEP_BIT_POSIX_TIMER on clone (bsc#1234098).
- power: supply: bq27xxx: Fix registers of bq27426 (git-fixes).
- power: supply: core: Remove might_sleep() from power_supply_put() (git-fixes).
- power: supply: rt9471: Fix wrong WDT function regfield declaration (git-fixes).
- power: supply: rt9471: Use IC status regfield to report real charger status (git-fixes).
- powerpc/64s: Fix unnecessary copy to 0 when kernel is booted at address 0 (bsc#1215199).
- powerpc/atomic: Use YZ constraints for DS-form instructions (bsc#1194869).
- powerpc/fadump: Move fadump_cma_init to setup_arch() after initmem_init() (bsc#1215199).
- powerpc/fadump: Refactor and prepare fadump_cma_init for late init (bsc#1215199).
- powerpc/kexec: Fix return of uninitialized variable (bsc#1194869).
- powerpc/mm/fault: Fix kfence page fault reporting (bsc#1194869).
- powerpc/mm: Fix boot crash with FLATMEM (bsc#1194869).
- powerpc/mm: Fix boot warning with hugepages and CONFIG_DEBUG_VIRTUAL (bsc#1194869).
- powerpc/powernv: Free name on error in opal_event_init() (bsc#1194869).
- powerpc/pseries: Fix KVM guest detection for disabling hardlockup detector (bsc#1194869).
- powerpc/pseries: Fix dtl_access_lock to be a rw_semaphore (bsc#1194869).
- powerpc/pseries: Use correct data types from pseries_hp_errorlog struct (bsc#1215199).
- powerpc/vdso: Inconditionally use CFUNC macro (bsc#1215199).
- pwm: imx-tpm: Use correct MODULO value for EPWM mode (git-fixes).
- regmap: detach regmap from dev on regmap_exit (git-fixes).
- regmap: irq: Set lockdep class for hierarchical IRQ domains (git-fixes).
- rpm/scripts: Remove obsolete Symbols.list Symbols.list is not longer needed by the new klp-convert implementation. (bsc#1218644)
- rtc: ab-eoz9: do not fail temperature reads on undervoltage notification (git-fixes).
- rtc: abx80x: Fix WDT bit position of the status register (git-fixes).
- rtc: bbnsm: add remove hook (git-fixes).
- rtc: check if __rtc_read_time was successful in rtc_timer_do_work() (git-fixes).
- rtc: rzn1: fix BCD to rtc_time conversion errors (git-fixes).
- rtc: st-lpc: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).
- scsi: NCR5380: Check for phase match during PDMA fixup (git-fixes).
- scsi: NCR5380: Initialize buffer for MSG IN and STATUS transfers (git-fixes).
- scsi: Remove scsi device no_start_on_resume flag (git-fixes).
- scsi: aacraid: Rearrange order of struct aac_srb_unit (git-fixes).
- scsi: cdrom: kABI: fix cdrom_dev_ops change (git-fixes).
- scsi: core: Disable CDL by default (git-fixes).
- scsi: core: Fix handling of SCMD_FAIL_IF_RECOVERING (git-fixes).
- scsi: core: Fix the return value of scsi_logical_block_count() (git-fixes).
- scsi: core: Handle devices which return an unusually large VPD page count (git-fixes).
- scsi: core: alua: I/O errors for ALUA state transitions (git-fixes).
- scsi: hisi_sas: Handle the NCQ error returned by D2H frame (git-fixes).
- scsi: hpsa: Fix allocation size for Scsi_Host private data (git-fixes).
- scsi: kABI: restore no_start_on_resume to scsi_device (git-fixes).
- scsi: libsas: Fix exp-attached device scan after probe failure scanned in again after probe failed (git-fixes).
- scsi: libsas: Fix the failure of adding phy with zero-address to port (git-fixes).
- scsi: lpfc: Add cleanup of nvmels_wq after HBA reset (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Call lpfc_sli4_queue_unset() in restart and rmmod paths (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Change lpfc_nodelist nlp_flag member into a bitmask (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Check SLI_ACTIVE flag in FDMI cmpl before submitting follow up FDMI (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Check devloss callbk done flag for potential stale NDLP ptrs (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Copyright updates for 14.4.0.6 patches (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Modify CGN warning signal calculation based on EDC response (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Prevent NDLP reference count underflow in dev_loss_tmo callback (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Remove NLP_RELEASE_RPI flag from nodelist structure (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Update lpfc version to 14.4.0.6 (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Update lpfc_els_flush_cmd() to check for SLI_ACTIVE before BSG flag (bsc#1233241 jsc#PED-9943).
- scsi: mac_scsi: Disallow bus errors during PDMA send (git-fixes).
- scsi: mac_scsi: Refactor polling loop (git-fixes).
- scsi: mac_scsi: Revise printk(KERN_DEBUG ...) messages (git-fixes).
- scsi: mpi3mr: Avoid IOMMU page faults on REPORT ZONES (git-fixes).
- scsi: mpi3mr: Avoid memcpy field-spanning write WARNING (git-fixes).
- scsi: mpi3mr: Avoid possible run-time warning with long manufacturer strings (git-fixes).
- scsi: mpi3mr: Fix ATA NCQ priority support (git-fixes).
- scsi: mpi3mr: Validate SAS port assignments (git-fixes).
- scsi: mpt3sas: Avoid IOMMU page faults on REPORT ZONES (git-fixes).
- scsi: pm8001: Do not overwrite PCI queue mapping (git-fixes).
- scsi: pm80xx: Set phy->enable_completion only when we wait for it (git-fixes).
- scsi: qedf: Set qed_slowpath_params to zero before use (git-fixes).
- scsi: scsi_transport_fc: Allow setting rport state to current state (git-fixes).
- scsi: sd: Ignore command SYNCHRONIZE CACHE error if format in progress (git-fixes).
- scsi: sd_zbc: Use kvzalloc() to allocate REPORT ZONES buffer (git-fixes).
- scsi: smartpqi: correct stream detection (git-fixes).
- scsi: smartpqi: revert propagate-the-multipath-failure-to-SML-quickly (git-fixes).
- scsi: spi: Fix sshdr use (git-fixes).
- scsi: sr: Fix unintentional arithmetic wraparound (git-fixes).
- scsi: wd33c93: Do not use stale scsi_pointer value (git-fixes).
- security/keys: fix slab-out-of-bounds in key_task_permission (git-fixes).
- serial: 8250: omap: Move pm_runtime_get_sync (git-fixes).
- signal: Replace BUG_ON()s (bsc#1234093).
- soc: fsl: rcpm: fix missing of_node_put() in copy_ippdexpcr1_setting() (git-fixes).
- soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get() (git-fixes).
- soc: ti: smartreflex: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).
- spi: Fix acpi deferred irq probe (git-fixes).
- spi: atmel-quadspi: Fix register name in verbose logging function (git-fixes).
- spi: mpc52xx: Add cancel_work_sync before module remove (git-fixes).
- spi: tegra210-quad: Avoid shift-out-of-bounds (git-fixes).
- tcp: Fix refcnt handling in __inet_hash_connect() (git-fixes).
- thermal: core: Initialize thermal zones before registering them (git-fixes).
- thermal: int3400: Fix reading of current_uuid for active policy (git-fixes).
- thermal: intel: int340x: processor: Fix warning during module unload (git-fixes).
- thunderbolt: Honor TMU requirements in the domain when setting TMU mode (stable-fixes).
- tools/lib/thermal: Fix sampling handler context ptr (git-fixes).
- tools/power turbostat: Fix trailing '\n' parsing (git-fixes).
- tools/power turbostat: Increase the limit for fd opened (bsc#1233119).
- tpm: Lock TPM chip in tpm_pm_suspend() first (bsc#1082555 git-fixes).
- tpm: fix signed/unsigned bug when checking event logs (git-fixes).
- tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler (git-fixes).
- u64_stats: fix u64_stats_init() for lockdep when used repeatedly in one file (git-fixes).
- ucounts: fix counter leak in inc_rlimit_get_ucounts() (bsc#1233460).
- unicode: Fix utf8_load() error path (git-fixes).
- usb: dwc3: gadget: Add missing check for single port RAM in TxFIFO resizing logic (git-fixes).
- usb: dwc3: gadget: Fix checking for number of TRBs left (git-fixes).
- usb: dwc3: gadget: Fix looping of queued SG entries (git-fixes).
- usb: ehci-spear: fix call balance of sehci clk handling routines (git-fixes).
- usb: gadget: dummy_hcd: Set transfer interval to 1 microframe (stable-fixes).
- usb: gadget: dummy_hcd: Switch to hrtimer transfer scheduler (stable-fixes).
- usb: gadget: dummy_hcd: execute hrtimer callback in softirq context (git-fixes).
- usb: musb: Fix hardware lockup on first Rx endpoint request (git-fixes).
- usb: musb: sunxi: Fix accessing an released usb phy (git-fixes).
- usb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd() (git-fixes).
- usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read() (git-fixes).
- usb: xhci: Fix TD invalidation under pending Set TR Dequeue (git-fixes).
- usb: yurex: make waiting on yurex_write interruptible (git-fixes).
- vsock: Update msg_count on read_skb() (git-fixes).
- watchdog: apple: Actually flush writes after requesting watchdog restart (git-fixes).
- watchdog: mediatek: Make sure system reset gets asserted in mtk_wdt_restart() (git-fixes).
- watchdog: rti: of: honor timeout-sec property (git-fixes).
- wifi: ath10k: fix invalid VHT parameters in supported_vht_mcs_rate_nss1 (git-fixes).
- wifi: ath10k: fix invalid VHT parameters in supported_vht_mcs_rate_nss2 (git-fixes).
- wifi: ath11k: Fix CE offset address calculation for WCN6750 in SSR (git-fixes).
- wifi: ath12k: Skip Rx TID cleanup for self peer (git-fixes).
- wifi: ath12k: fix crash when unbinding (git-fixes).
- wifi: ath12k: fix warning when unbinding (git-fixes).
- wifi: ath12k: remove msdu_end structure for WCN7850 (git-fixes).
- wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() (git-fixes).
- wifi: brcmfmac: release 'root' node in all execution paths (git-fixes).
- wifi: cw1200: Fix potential NULL dereference (git-fixes).
- wifi: iwlegacy: Clear stale interrupts before resuming device (stable-fixes).
- wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan() (git-fixes).
- wifi: mwifiex: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).
- wifi: p54: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).
- wifi: wfx: Fix error handling in wfx_core_init() (git-fixes).
- x86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client (bsc#1233443).
- x86/microcode/intel: Remove unnecessary cache writeback and invalidation (git-fixes).
- x86/resctrl: Remove hard-coded memory bandwidth limit (git-fixes).
- x86/syscall: Avoid memcpy() for ia32 syscall_get_arguments() (git-fixes).
- x86/tdx: Dynamically disable SEPT violations from causing #VEs (git-fixes).
- x86/tdx: Enable CPU topology enumeration (git-fixes).
- x86/tdx: Introduce wrappers to read and write TD metadata (git-fixes).
- x86/tdx: Rename tdx_parse_tdinfo() to tdx_setup() (git-fixes).
- x86/traps: move kmsan check after instrumentation_begin (git-fixes).
- x86: Increase brk randomness entropy for 64-bit systems (git-fixes).
- x86: fix off-by-one in access_ok() (git-fixes).
- xfrm: Export symbol xfrm_dev_state_delete (bsc#1233754).
- xfrm: Fix unregister netdevice hang on hardware offload (bsc#1233754).
- drm: Expand max DRM device number to full MINORBITS (jsc#PED-11580).
- accel: Use XArray instead of IDR for minors (jsc#PED-11580).
- drm: Use XArray instead of IDR for minors (jsc#PED-11580).
- scsi: lpfc: Copyright updates for 14.4.0.6 patches (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Update lpfc version to 14.4.0.6 (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Change lpfc_nodelist nlp_flag member into a bitmask (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Remove NLP_RELEASE_RPI flag from nodelist structure (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Prevent NDLP reference count underflow in dev_loss_tmo callback (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Add cleanup of nvmels_wq after HBA reset (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Check SLI_ACTIVE flag in FDMI cmpl before submitting follow up FDMI (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Update lpfc_els_flush_cmd() to check for SLI_ACTIVE before BSG flag (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Call lpfc_sli4_queue_unset() in restart and rmmod paths (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Check devloss callbk done flag for potential stale NDLP ptrs (bsc#1233241 jsc#PED-9943).
- scsi: lpfc: Modify CGN warning signal calculation based on EDC response (bsc#1233241 jsc#PED-9943).
Patchnames
SUSE-2024-4316,SUSE-SLE-Module-Public-Cloud-15-SP6-2024-4316,openSUSE-SLE-15.6-2024-4316
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "important" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for the Linux Kernel", "title": "Title of the patch" }, { "category": "description", "text": "\nThe SUSE Linux Enterprise 15 SP6 Azure kernel was updated to receive various security bugfixes.\n\nThe following security bugs were fixed:\n\n- CVE-2023-52778: mptcp: deal with large GSO size (bsc#1224948).\n- CVE-2023-52920: bpf: support non-r10 register spill/fill to/from stack in precision tracking (bsc#1232823).\n- CVE-2024-26596: net: dsa: fix netdev_priv() dereference before check on non-DSA netdevice events (bsc#1220355).\n- CVE-2024-26741: dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished() (bsc#1222587).\n- CVE-2024-26782: mptcp: fix double-free on socket dismantle (bsc#1222590).\n- CVE-2024-26953: net: esp: fix bad handling of pages from page_pool (bsc#1223656).\n- CVE-2024-27017: netfilter: nft_set_pipapo: walk over current view on netlink dump (bsc#1223733).\n- CVE-2024-35888: erspan: make sure erspan_base_hdr is present in skb-\u003ehead (bsc#1224518).\n- CVE-2024-36000: mm/hugetlb: fix missing hugetlb_lock for resv uncharge (bsc#1224548).\n- CVE-2024-36883: net: fix out-of-bounds access in ops_init (bsc#1225725).\n- CVE-2024-36886: tipc: fix UAF in error path (bsc#1225730).\n- CVE-2024-36905: tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets (bsc#1225742).\n- CVE-2024-36927: ipv4: Fix uninit-value access in __ip_make_skb() (bsc#1225813).\n- CVE-2024-36954: tipc: fix a possible memleak in tipc_buf_append (bsc#1225764).\n- CVE-2024-36968: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() (bsc#1226130).\n- CVE-2024-38589: netrom: fix possible dead-lock in nr_rt_ioctl() (bsc#1226748).\n- CVE-2024-40914: mm/huge_memory: do not unpoison huge_zero_folio (bsc#1227842).\n- CVE-2024-41023: sched/deadline: Fix task_struct reference leak (bsc#1228430).\n- CVE-2024-42102: Revert \u0027mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again\u0027 (bsc#1233132).\n- CVE-2024-44995: net: hns3: fix a deadlock problem when config TC during resetting (bsc#1230231).\n- CVE-2024-46680: Bluetooth: btnxpuart: Fix random crash seen while removing driver (bsc#1230557).\n- CVE-2024-46681: pktgen: use cpus_read_lock() in pg_net_init() (bsc#1230558).\n- CVE-2024-46765: ice: protect XDP configuration with a mutex (bsc#1230807).\n- CVE-2024-46800: sch/netem: fix use after free in netem_dequeue (bsc#1230827).\n- CVE-2024-47679: vfs: fix race between evice_inodes() and find_inode()\u0026iput() (bsc#1231930).\n- CVE-2024-47701: ext4: avoid OOB when system.data xattr changes underneath the filesystem (bsc#1231920).\n- CVE-2024-47703: bpf, lsm: add check for BPF LSM return value (bsc#1231946).\n- CVE-2024-49868: btrfs: fix a NULL pointer dereference when failed to start a new trasacntion (bsc#1232272).\n- CVE-2024-49888: bpf: Fix a sdiv overflow issue (bsc#1232208).\n- CVE-2024-49899: drm/amd/display: Initialize denominators\u0027 default to 1 (bsc#1232358).\n- CVE-2024-49911: drm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func (bsc#1232366).\n- CVE-2024-49912: drm/amd/display: Handle null \u0027stream_status\u0027 in \u0027planes_changed_for_existing_stream\u0027 (bsc#1232367).\n- CVE-2024-49921: drm/amd/display: Check null pointers before used (bsc#1232371).\n- CVE-2024-49922: drm/amd/display: Check null pointers before using them (bsc#1232374).\n- CVE-2024-49923: drm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags (bsc#1232361).\n- CVE-2024-49925: fbdev: efifb: Register sysfs groups through driver core (bsc#1232224)\n- CVE-2024-49933: blk_iocost: fix more out of bound shifts (bsc#1232368).\n- CVE-2024-49934: fs/inode: Prevent dump_mapping() accessing invalid dentry.d_name.name (bsc#1232387).\n- CVE-2024-49944: sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start (bsc#1232166).\n- CVE-2024-49945: net/ncsi: Disable the ncsi work before freeing the associated structure (bsc#1232165).\n- CVE-2024-49952: netfilter: nf_tables: prevent nf_skb_duplicated corruption (bsc#1232157).\n- CVE-2024-49968: ext4: filesystems without casefold feature cannot be mounted with siphash (bsc#1232264).\n- CVE-2024-49983: ext4: drop ppath from ext4_ext_replay_update_ex() to avoid double-free (bsc#1232096).\n- CVE-2024-49987: bpftool: Fix undefined behavior in qsort(NULL, 0, ...) (bsc#1232258).\n- CVE-2024-49989: drm/amd/display: fix double free issue during amdgpu module unload (bsc#1232483).\n- CVE-2024-50003: drm/amd/display: Fix system hang while resume with TBT monitor (bsc#1232385).\n- CVE-2024-50004: drm/amd/display: update DML2 policy EnhancedPrefetchScheduleAccelerationFinal DCN35 (bsc#1232396).\n- CVE-2024-50006: ext4: fix i_data_sem unlock order in ext4_ind_migrate() (bsc#1232442).\n- CVE-2024-50009: cpufreq: amd-pstate: add check for cpufreq_cpu_get\u0027s return value (bsc#1232318).\n- CVE-2024-50012: cpufreq: Avoid a bad reference count on CPU node (bsc#1232386).\n- CVE-2024-50014: ext4: fix access to uninitialised lock in fc replay path (bsc#1232446).\n- CVE-2024-50082: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race (bsc#1232500).\n- CVE-2024-50084: net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test() (bsc#1232494).\n- CVE-2024-50087: btrfs: fix uninitialized pointer free on read_alloc_one_name() error (bsc#1232499).\n- CVE-2024-50088: btrfs: fix uninitialized pointer free in add_inode_ref() (bsc#1232498).\n- CVE-2024-50098: scsi: ufs: core: Set SDEV_OFFLINE when UFS is shut down (bsc#1232881).\n- CVE-2024-50110: xfrm: fix one more kernel-infoleak in algo dumping (bsc#1232885).\n- CVE-2024-50115: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory (bsc#1232919).\n- CVE-2024-50124: Bluetooth: ISO: Fix UAF on iso_sock_timeout (bsc#1232926).\n- CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout (bsc#1232928).\n- CVE-2024-50127: net: sched: fix use-after-free in taprio_change() (bsc#1232907).\n- CVE-2024-50128: net: wwan: fix global oob in wwan_rtnl_policy (bsc#1232905).\n- CVE-2024-50130: netfilter: bpf: must hold reference on net namespace (bsc#1232894).\n- CVE-2024-50138: bpf: Use raw_spinlock_t in ringbuf (bsc#1232935).\n- CVE-2024-50139: KVM: arm64: Fix shift-out-of-bounds bug (bsc#1233062).\n- CVE-2024-50145: octeon_ep: add SKB allocation failures handling in __octep_oq_process_rx() (bsc#1233044).\n- CVE-2024-50153: scsi: target: core: Fix null-ptr-deref in target_alloc_device() (bsc#1233061).\n- CVE-2024-50154: tcp/dccp: Do not use timer_pending() in reqsk_queue_unlink() (bsc#1233070).\n- CVE-2024-50166: fsl/fman: Fix refcount handling of fman-related devices (bsc#1233050).\n- CVE-2024-50167: be2net: fix potential memory leak in be_xmit() (bsc#1233049).\n- CVE-2024-50169: vsock: Update rx_bytes on read_skb() (bsc#1233320).\n- CVE-2024-50171: net: systemport: fix potential memory leak in bcm_sysport_xmit() (bsc#1233057).\n- CVE-2024-50177: drm/amd/display: fix a UBSAN warning in DML2.1 (bsc#1233115).\n- CVE-2024-50182: secretmem: disable memfd_secret() if arch cannot set direct map (bsc#1233129).\n- CVE-2024-50184: virtio_pmem: Check device status before requesting flush (bsc#1233135).\n- CVE-2024-50186: net: explicitly clear the sk pointer, when pf-\u003ecreate fails (bsc#1233110).\n- CVE-2024-50192: irqchip/gic-v4: Do not allow a VMOVP on a dying VPE (bsc#1233106).\n- CVE-2024-50225: btrfs: fix error propagation of split bios (bsc#1233193).\n- CVE-2024-50228: mm: shmem: fix data-race in shmem_getattr() (bsc#1233204).\n- CVE-2024-50230: nilfs2: fix kernel bug due to missing clearing of checked flag (bsc#1233206).\n- CVE-2024-50245: fs/ntfs3: Fix possible deadlock in mi_read (bsc#1233203).\n- CVE-2024-50246: fs/ntfs3: Add rough attr alloc_size check (bsc#1233207).\n- CVE-2024-50248: ntfs3: add bounds checking to mi_enum_attr() (bsc#1233219).\n- CVE-2024-50250: fsdax: dax_unshare_iter needs to copy entire blocks (bsc#1233226).\n- CVE-2024-50252: mlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address (bsc#1233201).\n- CVE-2024-50257: netfilter: Fix use-after-free in get_info() (bsc#1233244).\n- CVE-2024-50261: macsec: Fix use-after-free while sending the offloading packet (bsc#1233253).\n- CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-\u003etrans (bsc#1233453).\n- CVE-2024-50271: signal: restore the override_rlimit logic (bsc#1233460).\n- CVE-2024-50273: btrfs: reinitialize delayed ref list after deleting it from the list (bsc#1233462).\n- CVE-2024-50274: idpf: avoid vport access in idpf_get_link_ksettings (bsc#1233463).\n- CVE-2024-50275: arm64/sve: Discard stale CPU state when handling SVE traps (bsc#1233464).\n- CVE-2024-50276: net: vertexcom: mse102x: Fix possible double free of TX skb (bsc#1233465).\n- CVE-2024-50279: dm cache: fix out-of-bounds access to the dirty bitset when resizing (bsc#1233468).\n- CVE-2024-50289: media: av7110: fix a spectre vulnerability (bsc#1233478).\n- CVE-2024-50295: net: arc: fix the device for dma_map_single/dma_unmap_single (bsc#1233484).\n- CVE-2024-50296: net: hns3: fix kernel crash when uninstalling driver (bsc#1233485).\n- CVE-2024-50298: net: enetc: allocate vf_state during PF probes (bsc#1233487).\n- CVE-2024-53042: ipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_init_flow() (bsc#1233540).\n- CVE-2024-53043: mctp i2c: handle NULL header address (bsc#1233523).\n- CVE-2024-53048: ice: fix crash on probe for DPLL enabled E810 LOM (bsc#1233721).\n- CVE-2024-53051: drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability (bsc#1233547).\n- CVE-2024-53055: wifi: iwlwifi: mvm: fix 6 GHz scan construction (bsc#1233550).\n- CVE-2024-53056: drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy() (bsc#1233568).\n- CVE-2024-53058: net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data (bsc#1233552).\n- CVE-2024-53079: mm/thp: fix deferred split unqueue naming and locking (bsc#1233570).\n- CVE-2024-53082: virtio_net: Add hash_key_length check (bsc#1233573).\n- CVE-2024-53095: smb: client: Fix use-after-free of network namespace (bsc#1233642).\n- CVE-2024-53110: vp_vdpa: fix id_table array not null terminated error (bsc#1234085).\n- CVE-2024-53121: net/mlx5: fs, lock FTE when checking if active (bsc#1234078).\n- CVE-2024-53138: net/mlx5e: kTLS, Fix incorrect page refcounting (bsc#1234223).\n\nThe following non-security bugs were fixed:\n\n- ACPI: CPPC: Fix _CPC register setting issue (git-fixes).\n- ALSA: 6fire: Release resources at card release (git-fixes).\n- ALSA: ac97: bus: Fix the mistake in the comment (git-fixes).\n- ALSA: caiaq: Use snd_card_free_when_closed() at disconnection (git-fixes).\n- ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init() (git-fixes).\n- ALSA: hda/conexant: fix Z60MR100 startup pop issue (stable-fixes).\n- ALSA: hda/realtek - Fixed Clevo platform headset Mic issue (stable-fixes).\n- ALSA: hda/realtek - update set GPIO3 to default for Thinkpad with ALC1318 (git-fixes).\n- ALSA: hda/realtek: Add support for Samsung Galaxy Book3 360 (NP730QFG) (stable-fixes).\n- ALSA: hda/realtek: Apply quirk for Medion E15433 (bsc#1233298).\n- ALSA: hda/realtek: Enable mute and micmute LED on HP ProBook 430 G8 (stable-fixes).\n- ALSA: hda/realtek: Enable speaker pins for Medion E15443 platform (bsc#1233298).\n- ALSA: hda/realtek: Fix Internal Speaker and Mic boost of Infinix Y4 Max (bsc#1233298).\n- ALSA: hda/realtek: Set PCBeep to default value for ALC274 (stable-fixes).\n- ALSA: hda/realtek: Update ALC225 depop procedure (git-fixes).\n- ALSA: hda/realtek: Update ALC256 depop procedure (git-fixes).\n- ALSA: hda/realtek: fix mute/micmute LEDs for a HP EliteBook 645 G10 (stable-fixes).\n- ALSA: hda: Poll jack events for LS7A HD-Audio (stable-fixes).\n- ALSA: hda: Show the codec quirk info at probing (stable-fixes).\n- ALSA: ice1712: Remove redundant code in stac9460_dac_vol_put (stable-fixes).\n- ALSA: pcm: Add sanity NULL check for the default mmap fault handler (stable-fixes).\n- ALSA: ump: Fix evaluation of MIDI 1.0 FB info (git-fixes).\n- ALSA: us122l: Use snd_card_free_when_closed() at disconnection (git-fixes).\n- ALSA: usb-audio: Add Pioneer DJ/AlphaTheta DJM-A9 Mixer (stable-fixes).\n- ALSA: usb-audio: Fix Yamaha P-125 Quirk Entry (stable-fixes).\n- ALSA: usb-audio: Fix a DMA to stack memory bug (git-fixes).\n- ALSA: usb-audio: Fix out of bounds reads when finding clock sources (stable-fixes).\n- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (git-fixes).\n- ALSA: usb-audio: Make mic volume workarounds globally applicable (stable-fixes).\n- ALSA: usb-audio: Use snprintf instead of sprintf in build_mixer_unit_ctl (stable-fixes).\n- ALSA: usb-audio: add mixer mapping for Corsair HS80 (stable-fixes).\n- ALSA: usx2y: Use snd_card_free_when_closed() at disconnection (git-fixes).\n- ASoC: Intel: avs: da7219: Remove suspend_pre() and resume_post() (stable-fixes).\n- ASoC: SOF: Add i2s bt dai configuration support for AMD platforms (bsc#1233305).\n- ASoC: SOF: Add support for configuring PDM interface from topology (bsc#1233305).\n- ASoC: SOF: Deprecate invalid enums in IPC3 (bsc#1233305).\n- ASoC: SOF: IPC4: get pipeline priority from topology (bsc#1233305).\n- ASoC: SOF: IPC4: synchronize fw_config_params with fw definitions (bsc#1233305).\n- ASoC: SOF: Refactor sof_i2s_tokens reading to update acpbt dai (bsc#1233305).\n- ASoC: SOF: Rename amd_bt sof_dai_type (bsc#1233305).\n- ASoC: SOF: Wire up buffer flags (bsc#1233305).\n- ASoC: SOF: add alignment for topology header file struct definition (bsc#1233305).\n- ASoC: SOF: align topology header file with sof topology header (bsc#1233305).\n- ASoC: SOF: ipc3-topology: Convert the topology pin index to ALH dai index (git-fixes).\n- ASoC: SOF: ipc3-topology: fix resource leaks in sof_ipc3_widget_setup_comp_dai() (git-fixes).\n- ASoC: SOF: ipc4-control: Add support for ALSA enum control (bsc#1233305).\n- ASoC: SOF: ipc4-control: Add support for ALSA switch control (bsc#1233305).\n- ASoC: SOF: ipc4-mtrace: move debug slot related definitions to header.h (bsc#1233305).\n- ASoC: SOF: ipc4-topology: Add deep buffer size to debug prints (bsc#1233305).\n- ASoC: SOF: ipc4-topology: Add definition for generic switch/enum control (bsc#1233305).\n- ASoC: SOF: ipc4-topology: Add module ID print during module set up (bsc#1233305).\n- ASoC: SOF: ipc4-topology: Helper to find an swidget by module/instance id (bsc#1233305).\n- ASoC: SOF: ipc4-topology: Only handle dai_config with HW_PARAMS for ChainDMA (bsc#1233305).\n- ASoC: SOF: ipc4-topology: change chain_dma handling in dai_config (bsc#1233305).\n- ASoC: SOF: ipc4-topology: export sof_ipc4_copier_is_single_format (bsc#1233305).\n- ASoC: SOF: ipc4-topology: set config_length based on device_count (bsc#1233305).\n- ASoC: SOF: ipc4: Add data struct for module notification message from firmware (bsc#1233305).\n- ASoC: SOF: ipc4: Add new message type: SOF_IPC4_GLB_LOAD_LIBRARY_PREPARE (bsc#1233305).\n- ASoC: SOF: sof-client-probes-ipc4: Set param_size extension bits (git-fixes).\n- ASoC: SOF: topology: Parse DAI type token for dspless mode (bsc#1233305).\n- ASoC: SOF: topology: dynamically allocate and store DAI widget-\u003eprivate (bsc#1233305).\n- ASoC: amd: yc: Add quirk for ASUS Vivobook S15 M3502RA (stable-fixes).\n- ASoC: amd: yc: Fix for enabling DMIC on acp6x via _DSD entry (git-fixes).\n- ASoC: amd: yc: Fix non-functional mic on ASUS E1404FA (stable-fixes).\n- ASoC: amd: yc: Support dmic on another model of Lenovo Thinkpad E14 Gen 6 (stable-fixes).\n- ASoC: amd: yc: fix internal mic on Xiaomi Book Pro 14 2022 (stable-fixes).\n- ASoC: audio-graph-card2: Purge absent supplies for device tree nodes (stable-fixes).\n- ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata() (git-fixes).\n- ASoC: fsl_micfil: Add sample rate constraint (stable-fixes).\n- ASoC: fsl_micfil: fix regmap_write_bits usage (git-fixes).\n- ASoC: mediatek: mt8188-mt6359: Remove hardcoded dmic codec (git-fixes).\n- ASoC: rt722-sdca: Remove logically deadcode in rt722-sdca.c (git-fixes).\n- ASoC: rt722-sdca: increase clk_stop_timeout to fix clock stop issue (stable-fixes).\n- ASoC: stm32: spdifrx: fix dma channel release in stm32_spdifrx_remove (git-fixes).\n- ASoC: stm: Prevent potential division by zero in stm32_sai_get_clk_div() (stable-fixes).\n- ASoC: stm: Prevent potential division by zero in stm32_sai_mclk_round_rate() (stable-fixes).\n- ASoC: tas2781: Add new driver version for tas2563 \u0026 tas2781 qfn chip (stable-fixes).\n- Bluetooth: MGMT: Fix slab-use-after-free Read in set_powered_sync (git-fixes).\n- Bluetooth: btintel: Direct exception event to bluetooth stack (git-fixes).\n- Bluetooth: btnxpuart: Resolve TX timeout error in power save stress test (bsc#1230557)\n- Bluetooth: fix use-after-free in device_for_each_child() (git-fixes).\n- Bluetooth: hci_core: Fix calling mgmt_device_connected (git-fixes).\n- Documentation: kgdb: Correct parameter error (git-fixes).\n- Drop OCFS2 patch causing a regression (bsc#1233255)\n- HID: core: zero-initialize the report buffer (git-fixes).\n- HID: lenovo: Add support for Thinkpad X1 Tablet Gen 3 keyboard (stable-fixes).\n- HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad (stable-fixes).\n- HID: multitouch: Add quirk for Logitech Bolt receiver w/ Casa touchpad (stable-fixes).\n- HID: multitouch: Add support for B2402FVA track point (stable-fixes).\n- HID: wacom: Interpret tilt data from Intuos Pro BT as signed values (git-fixes).\n- HID: wacom: fix when get product name maybe null pointer (git-fixes).\n- Input: hideep - add missing dependency on REGMAP_I2C (git-fixes).\n- Input: hycon-hy46xx - add missing dependency on REGMAP_I2C (git-fixes).\n- Input: xpad - add GameSir T4 Kaleid Controller support (git-fixes).\n- Input: xpad - add GameSir VID for Xbox One controllers (git-fixes).\n- Input: xpad - add support for 8BitDo Ultimate 2C Wireless Controller (git-fixes).\n- Input: xpad - add support for MSI Claw A1M (git-fixes).\n- Input: xpad - add support for Machenike G5 Pro Controller (git-fixes).\n- Input: xpad - fix support for some third-party controllers (git-fixes).\n- Input: xpad - sort xpad_device by vendor and product ID (git-fixes).\n- Input: xpad - spelling fixes for \u0027Xbox\u0027 (git-fixes).\n- KVM: PPC: Book3S HV: Avoid returning to nested hypervisor on pending doorbells (bsc#1215199).\n- KVM: PPC: Book3S HV: Stop using vc-\u003edpdes for nested KVM guests (bsc#1215199).\n- KVM: PPC: Book3S HV: remove unused varible (bsc#1194869).\n- KVM: SEV-ES: Fix svm_get_msr()/svm_set_msr() for KVM_SEV_ES_INIT guests (bsc#1232207).\n- KVM: SEV-ES: Prevent MSR access post VMSA encryption (bsc#1232207).\n- Move kabi netfilter fix into patches.kabi\n- Move upstreamed crypto patches into sorted section\n- Move upstreamed patches into sorted section\n- NFS: remove revoked delegation from server\u0027s delegation list (git-fixes).\n- PCI: Add T_PVPERL macro (git-fixes).\n- PCI: Fix reset_method_store() memory leak (git-fixes).\n- PCI: endpoint: Clear secondary (not primary) EPC in pci_epc_remove_epf() (git-fixes).\n- PCI: j721e: Deassert PERST# after a delay of PCIE_T_PVPERL_MS milliseconds (git-fixes).\n- PCI: keystone: Add link up check to ks_pcie_other_map_bus() (git-fixes).\n- PCI: keystone: Set mode as Root Complex for \u0027ti,keystone-pcie\u0027 compatible (git-fixes).\n- PCI: rockchip-ep: Fix address translation unit programming (git-fixes).\n- RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey (git-fixes)\n- RDMA/hns: Add mutex_destroy() (git-fixes)\n- RDMA/hns: Disassociate mmap pages for all uctx when HW is being reset (git-fixes)\n- RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() (git-fixes)\n- RDMA/hns: Fix an AEQE overflow error caused by untimely update of eq_db_ci (git-fixes)\n- RDMA/hns: Fix cpu stuck caused by printings during reset (git-fixes)\n- RDMA/hns: Fix different dgids mapping to the same dip_idx (git-fixes)\n- RDMA/hns: Fix flush cqe error when racing with destroy qp (git-fixes)\n- RDMA/hns: Fix out-of-order issue of requester when setting FENCE (git-fixes)\n- RDMA/hns: Use dev_* printings in hem code instead of ibdev_* (git-fixes)\n- RDMA/hns: Use macro instead of magic number (git-fixes)\n- RDMA/mlx5: Move events notifier registration to be after device registration (git-fixes)\n- RDMA/rxe: Fix the qp flush warnings in req (git-fixes)\n- RDMA/rxe: Set queue pair cur_qp_state when being queried (git-fixes)\n- RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES (git-fixes)\n- Revert \u0027KVM: PPC: Book3S HV Nested: Stop forwarding all HFUs to L1\u0027 (bsc#1215199).\n- Revert \u0027RDMA/core: Fix ENODEV error for iWARP test over vlan\u0027 (git-fixes)\n- Revert \u0027cgroup: Fix memory leak caused by missing cgroup_bpf_offline\u0027 (bsc#1234108).\n- Revert \u0027cpufreq: brcmstb-avs-cpufreq: Fix initial command check\u0027 (stable-fixes).\n- Revert \u0027mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K\u0027 (git-fixes).\n- Revert \u0027usb: gadget: composite: fix OS descriptors w_value logic\u0027 (git-fixes).\n- SUNRPC: Remove BUG_ON call sites (git-fixes).\n- USB: chaoskey: Fix possible deadlock chaoskey_list_lock (git-fixes).\n- USB: chaoskey: fail open after removal (git-fixes).\n- USB: gadget: dummy-hcd: Fix \u0027task hung\u0027 problem (git-fixes).\n- USB: serial: ftdi_sio: Fix atomicity violation in get_serial_info() (git-fixes).\n- USB: serial: io_edgeport: fix use after free in debug printk (git-fixes).\n- USB: serial: option: add Fibocom FG132 0x0112 composition (stable-fixes).\n- USB: serial: option: add Quectel RG650V (stable-fixes).\n- USB: serial: qcserial: add support for Sierra Wireless EM86xx (stable-fixes).\n- Update config files (bsc#1218644).\n- Update config files. Enabled IDPF for ARM64 (bsc#1221309)\n- accel: Use XArray instead of IDR for minors (jsc#PED-11580).\n- acpi/arm64: Adjust error handling procedure in gtdt_parse_timer_block() (git-fixes).\n- ad7780: fix division by zero in ad7780_write_raw() (git-fixes).\n- add bugreference to a hv_netvsc patch (bsc#1232413).\n- aes-gcm-p10: Use the correct bit to test for P10 (bsc#1232704).\n- amd-pstate: Set min_perf to nominal_perf for active mode performance gov (git-fixes).\n- apparmor: fix \u0027Do simple duplicate message elimination\u0027 (git-fixes).\n- apparmor: test: Fix memory leak for aa_unpack_strdup() (git-fixes).\n- apparmor: use kvfree_sensitive to free data-\u003edata (git-fixes).\n- arm64: dts: allwinner: pinephone: Add mount matrix to accelerometer (git-fixes)\n- arm64: dts: freescale: imx8mm-verdin: Fix SD regulator startup delay (git-fixes)\n- arm64: dts: freescale: imx8mp-verdin: Fix SD regulator startup delay (git-fixes)\n- arm64: dts: imx8-ss-vpu: Fix imx8qm VPU IRQs (git-fixes)\n- arm64: dts: imx8qxp: Add VPU subsystem file (git-fixes)\n- arm64: dts: imx93: add nvmem property for eqos (git-fixes)\n- arm64: dts: imx93: add nvmem property for fec1 (git-fixes)\n- arm64: dts: imx93: add ocotp node (git-fixes)\n- arm64: dts: rockchip: Add DTS for FriendlyARM NanoPi R2S Plus (git-fixes)\n- arm64: dts: rockchip: Correct GPIO polarity on brcm BT nodes (git-fixes)\n- arm64: dts: rockchip: Fix LED triggers on rk3308-roc-cc (git-fixes)\n- arm64: dts: rockchip: Fix bluetooth properties on Rock960 boards (git-fixes)\n- arm64: dts: rockchip: Fix bluetooth properties on rk3566 box demo (git-fixes)\n- arm64: dts: rockchip: Fix reset-gpios property on brcm BT nodes (git-fixes)\n- arm64: dts: rockchip: Fix rt5651 compatible value on (git-fixes)\n- arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-eaidk-610 (git-fixes)\n- arm64: dts: rockchip: Fix wakeup prop names on PineNote BT node (git-fixes)\n- arm64: dts: rockchip: Remove #cooling-cells from fan on Theobroma (git-fixes)\n- arm64: dts: rockchip: Remove hdmi\u0027s 2nd interrupt on rk3328 (git-fixes)\n- arm64: dts: rockchip: Remove undocumented supports-emmc property (git-fixes)\n- arm64: dts: rockchip: fix i2c2 pinctrl-names property on (git-fixes)\n- arm64: dts: rockchip: remove num-slots property from (git-fixes)\n- arm64: dts: rockchip: remove orphaned pinctrl-names from pinephone (git-fixes)\n- arm64: fix .data.rel.ro size assertion when CONFIG_LTO_CLANG (git-fixes)\n- arm64: smccc: Remove broken support for SMCCCv1.3 SVE discard hint (git-fixes)\n- arm64: smccc: replace custom COUNT_ARGS() \u0026 CONCATENATE() (git-fixes)\n- arm64: tegra: Move AGX Orin nodes to correct location (git-fixes)\n- arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled (git-fixes)\n- bpf, arm64: Fix address emission with tag-based KASAN enabled (git-fixes)\n- bpf, arm64: Remove garbage frame for struct_ops trampoline (git-fixes)\n- bpf, sockmap: SK_DROP on attempted redirects of unsupported af_vsock (git-fixes).\n- bpf, vsock: Drop static vsock_bpf_prot initialization (git-fixes).\n- btrfs: merge btrfs_orig_bbio_end_io() into btrfs_bio_end_io() (bsc#1233193)\n- can: c_can: c_can_handle_bus_err(): update statistics if skb allocation fails (git-fixes).\n- can: c_can: fix {rx,tx}_errors statistics (git-fixes).\n- can: dev: can_set_termination(): allow sleeping GPIOs (git-fixes).\n- can: ems_usb: ems_usb_rx_err(): fix {rx,tx}_errors statistics (git-fixes).\n- can: hi311x: hi3110_can_ist(): fix potential use-after-free (git-fixes).\n- can: hi311x: hi3110_can_ist(): fix {rx,tx}_errors statistics (git-fixes).\n- can: ifi_canfd: ifi_canfd_handle_lec_err(): fix {rx,tx}_errors statistics (git-fixes).\n- can: j1939: j1939_session_new(): fix skb reference counting (git-fixes).\n- can: m_can: m_can_handle_lec_err(): fix {rx,tx}_errors statistics (git-fixes).\n- can: mcp251xfd: mcp251xfd_get_tef_len(): fix length calculation (git-fixes).\n- can: mcp251xfd: mcp251xfd_get_tef_len(): work around erratum DS80000789E 6 (git-fixes).\n- can: mcp251xfd: mcp251xfd_ring_alloc(): fix coalescing configuration when switching CAN modes (git-fixes).\n- can: sja1000: sja1000_err(): fix {rx,tx}_errors statistics (git-fixes).\n- can: sun4i_can: sun4i_can_err(): call can_change_state() even if cf is NULL (git-fixes).\n- can: sun4i_can: sun4i_can_err(): fix {rx,tx}_errors statistics (git-fixes).\n- cgroup/bpf: only cgroup v2 can be attached by bpf programs (bsc#1234108).\n- clk: clk-apple-nco: Add NULL check in applnco_probe (git-fixes).\n- clk: clk-axi-clkgen: make sure to enable the AXI bus clock (git-fixes).\n- clk: imx: clk-scu: fix clk enable state save and restore (git-fixes).\n- clk: imx: fracn-gppll: correct PLL initialization flow (git-fixes).\n- clk: imx: fracn-gppll: fix pll power up (git-fixes).\n- clk: imx: lpcg-scu: SW workaround for errata (e10858) (git-fixes).\n- clk: qcom: clk-alpha-pll: drop lucid-evo pll enabled warning (git-fixes).\n- clk: qcom: clk-alpha-pll: fix lucid 5lpe pll enabled check (git-fixes).\n- clk: qcom: gcc-qcs404: fix initial rate of GPLL3 (git-fixes).\n- clk: renesas: rzg2l: Fix FOUTPOSTDIV clk (git-fixes).\n- clk: sunxi-ng: d1: Fix PLL_AUDIO0 preset (git-fixes).\n- comedi: Flush partial mappings in error case (git-fixes).\n- cpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost() (git-fixes).\n- cpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw() (git-fixes).\n- cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_cost() (git-fixes).\n- cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_power() (git-fixes).\n- cpufreq: loongson2: Unregister platform_driver on failure (git-fixes).\n- cpufreq: mediatek-hw: Fix wrong return value in mtk_cpufreq_get_cpu_power() (git-fixes).\n- crypto: aes-gcm-p10 - Use the correct bit to test for P10 (bsc#1232704).\n- crypto: api - Fix liveliness check in crypto_alg_tested (stable-fixes).\n- crypto: bcm - add error check in the ahash_hmac_init function (git-fixes).\n- crypto: caam - Fix the pointer passed to caam_qi_shutdown() (git-fixes).\n- crypto: caam - add error check to caam_rsa_set_priv_key_form (git-fixes).\n- crypto: cavium - Fix an error handling path in cpt_ucode_load_fw() (git-fixes).\n- crypto: cavium - Fix the if condition to exit loop after timeout (git-fixes).\n- crypto: inside-secure - Fix the return value of safexcel_xcbcmac_cra_init() (git-fixes).\n- crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY (git-fixes).\n- crypto: qat - remove check after debugfs_create_dir() (git-fixes).\n- crypto: qat - remove faulty arbiter config reset (git-fixes).\n- crypto: qat/qat_4xxx - fix off by one in uof_get_name() (git-fixes).\n- crypto: x86/aegis128 - access 32-bit arguments as 32-bit (git-fixes).\n- cxl: downgrade a warning message to debug level in cxl_probe_component_regs() (bsc#1229165).\n- dma-fence: Fix reference leak on fence merge failure path (git-fixes).\n- dma-fence: Use kernel\u0027s sort for merging fences (git-fixes).\n- doc: rcu: update printed dynticks counter bits (git-fixes).\n- drivers: soc: xilinx: add the missing kfree in xlnx_add_cb_for_suspend() (git-fixes).\n- drm/amd/display: Adjust VSDB parser for replay feature (stable-fixes).\n- drm/amd/display: Fix brightness level not retained over reboot (git-fixes).\n- drm/amd/display: Fix null check for pipe_ctx-\u003eplane_state in dcn20_program_pipe (git-fixes).\n- drm/amd/display: Fix null check for pipe_ctx-\u003eplane_state in hwss_setup_dpp (git-fixes).\n- drm/amd: Add some missing straps from NBIO 7.11.0 (git-fixes).\n- drm/amd: Fix initialization mistake for NBIO 7.7.0 (stable-fixes).\n- drm/amdgpu: Adjust debugfs eviction and IB access permissions (stable-fixes).\n- drm/amdgpu: Adjust debugfs register access permissions (stable-fixes).\n- drm/amdgpu: Fix DPX valid mode check on GC 9.4.3 (git-fixes).\n- drm/amdgpu: Fix JPEG v4.0.3 register write (git-fixes).\n- drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read() (stable-fixes).\n- drm/amdgpu: fix check in gmc_v9_0_get_vm_pte() (git-fixes).\n- drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported (git-fixes).\n- drm/amdkfd: Accounting pdd vram_usage for svm (stable-fixes).\n- drm/amdkfd: Fix wrong usage of INIT_WORK() (git-fixes).\n- drm/bridge: anx7625: Drop EDID cache on bridge power off (git-fixes).\n- drm/bridge: it6505: Drop EDID cache on bridge power off (git-fixes).\n- drm/bridge: tc358767: Fix link properties discovery (git-fixes).\n- drm/bridge: tc358768: Fix DSI command tx (git-fixes).\n- drm/etnaviv: Request pages from DMA32 zone on addressing_limited (git-fixes).\n- drm/etnaviv: hold GPU lock across perfmon sampling (git-fixes).\n- drm/imx/dcss: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).\n- drm/imx/ipuv3: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).\n- drm/mediatek: Fix child node refcount handling in early exit (git-fixes).\n- drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused (git-fixes).\n- drm/msm/adreno: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).\n- drm/msm/dpu: cast crtc_clk calculation to u64 in _dpu_core_perf_calc_clk() (git-fixes).\n- drm/msm/dpu: drop LM_3 / LM_4 on MSM8998 (git-fixes).\n- drm/msm/dpu: drop LM_3 / LM_4 on SDM845 (git-fixes).\n- drm/msm/dpu: on SDM845 move DSPP_3 to LM_5 block (git-fixes).\n- drm/msm/gpu: Check the status of registration to PM QoS (git-fixes).\n- drm/msm: Fix some typos in comment (git-fixes).\n- drm/nouveau/gr/gf100: Fix missing unlock in gf100_gr_chan_new() (git-fixes).\n- drm/omap: Fix locking in omap_gem_new_dmabuf() (git-fixes).\n- drm/omap: Fix possible NULL dereference (git-fixes).\n- drm/panfrost: Add missing OPP table refcnt decremental (git-fixes).\n- drm/panfrost: Remove unused id_mask from struct panfrost_model (git-fixes).\n- drm/rockchip: vop: Fix a dereferenced before check warning (git-fixes).\n- drm/sti: Add __iomem for mixer_dbg_mxn\u0027s parameter (git-fixes).\n- drm/sti: avoid potential dereference of error pointers (git-fixes).\n- drm/sti: avoid potential dereference of error pointers in sti_gdp_atomic_check (git-fixes).\n- drm/sti: avoid potential dereference of error pointers in sti_hqvdp_atomic_check (git-fixes).\n- drm/v3d: Address race-condition in MMU flush (git-fixes).\n- drm/v3d: Enable Performance Counters before clearing them (git-fixes).\n- drm/vc4: Match drm_dev_enter and exit calls in vc4_hvs_atomic_flush (git-fixes).\n- drm/vc4: Match drm_dev_enter and exit calls in vc4_hvs_lut_load (git-fixes).\n- drm/vc4: hdmi: Avoid hang with debug registers when suspended (git-fixes).\n- drm/vc4: hvs: Correct logic on stopping an HVS channel (git-fixes).\n- drm/vc4: hvs: Do not write gamma luts on 2711 (git-fixes).\n- drm/vc4: hvs: Fix dlist debug not resetting the next entry pointer (git-fixes).\n- drm/vc4: hvs: Remove incorrect limit from hvs_dlist debugfs function (git-fixes).\n- drm/vkms: Drop unnecessary call to drm_crtc_cleanup() (git-fixes).\n- drm/vmwgfx: Limit display layout ioctl array size to VMWGFX_NUM_DISPLAY_UNITS (stable-fixes).\n- drm: Expand max DRM device number to full MINORBITS (jsc#PED-11580).\n- drm: Use XArray instead of IDR for minors (jsc#PED-11580).\n- drm: use ATOMIC64_INIT() for atomic64_t (git-fixes).\n- drm: xlnx: zynqmp_dpsub: fix hotplug detection (git-fixes).\n- drm: zynqmp_kms: Unplug DRM device before removal (git-fixes).\n- e1000e: Remove Meteor Lake SMBUS workarounds (git-fixes).\n- efi/libstub: Free correct pointer on failure (git-fixes).\n- efi/libstub: fix efi_parse_options() ignoring the default command line (git-fixes).\n- efi/libstub: zboot.lds: Discard .discard sections (stable-fixes).\n- efi/memattr: Ignore table if the size is clearly bogus (bsc#1231465).\n- ext4: fix unttached inode after power cut with orphan file feature enabled (bsc#1234009).\n- f2fs: get out of a repeat loop when getting a locked data page (bsc#1234011).\n- fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem() (git-fixes).\n- firmware: arm_scpi: Check the DVFS OPP count returned by the firmware (git-fixes).\n- firmware: google: Unregister driver_info on failure (git-fixes).\n- firmware_loader: Fix possible resource leak in fw_log_firmware_info() (git-fixes).\n- fs/ntfs3: Add more attributes checks in mi_enum_attr() (bsc#1233207)\n- fs/ntfs3: Fixed overflow check in mi_enum_attr() (bsc#1233207)\n- fs/ntfs3: Sequential field availability check in mi_enum_attr() (bsc#1233207)\n- fs: Fix uninitialized value issue in from_kuid and from_kgid (git-fixes).\n- goldfish: Fix unused const variable \u0027goldfish_pipe_acpi_match\u0027 (git-fixes).\n- gpio: exar: set value when external pull-up or pull-down is present (git-fixes).\n- gpio: zevio: Add missed label initialisation (git-fixes).\n- hv_sock: Initializing vsk-\u003etrans to NULL to prevent a dangling pointer (git-fixes).\n- hwmon: (nct6775-core) Fix overflows seen when writing limit attributes (git-fixes).\n- hwmon: (tps23861) Fix reporting of negative temperatures (git-fixes).\n- i2c: designware: do not hold SCL low when I2C_DYNAMIC_TAR_UPDATE is not set (git-fixes).\n- i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs() (git-fixes).\n- i3c: master: svc: Fix pm_runtime_set_suspended() with runtime pm enabled (git-fixes).\n- i40e: fix race condition by adding filter\u0027s intermediate sync state (git-fixes).\n- iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call (git-fixes).\n- igb: Disable threaded IRQ for igb_msix_other (git-fixes).\n- iio: Fix fwnode_handle in __fwnode_iio_channel_get_by_name() (git-fixes).\n- iio: accel: kx022a: Fix raw read format (git-fixes).\n- iio: adc: ad7606: Fix typo in the driver name (git-fixes).\n- iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer (git-fixes).\n- iio: gts: Fix uninitialized symbol \u0027ret\u0027 (git-fixes).\n- iio: gts: fix infinite loop for gain_to_scaletables() (git-fixes).\n- iio: light: al3010: Fix an error handling path in al3010_probe() (git-fixes).\n- ima: fix buffer overrun in ima_eventdigest_init_common (git-fixes).\n- initramfs: avoid filename buffer overrun (bsc#1232436).\n- intel_idle: add Granite Rapids Xeon support (bsc#1231630).\n- intel_idle: fix ACPI _CST matching for newer Xeon platforms (bsc#1231630).\n- io_uring/rw: fix missing NOWAIT check for O_DIRECT start write (git-fixes).\n- io_uring/sqpoll: close race on waiting for sqring entries (git-fixes).\n- irqchip/gic-v3-its: Avoid explicit cpumask allocation on stack (git-fixes).\n- jbd2: Move j_transaction_overhead_buffers into a hole (bsc#1234042).\n- jbd2: avoid infinite transaction commit loop (bsc#1234039).\n- jbd2: avoid memleak in jbd2_journal_write_metadata_buffer (bsc#1234043).\n- jbd2: avoid mount failed when commit block is partial submitted (bsc#1234040).\n- jbd2: correct the printing of write_flags in jbd2_write_superblock() (bsc#1234045).\n- jbd2: fix kernel-doc for j_transaction_overhead_buffers (bsc#1234042).\n- jbd2: fix potential data lost in recovering journal raced with synchronizing fs bdev (bsc#1234044).\n- jbd2: fix soft lockup in journal_finish_inode_data_buffers() (bsc#1234046).\n- jbd2: make jbd2_journal_get_max_txn_bufs() internal (bsc#1234041).\n- jbd2: precompute number of transaction descriptor blocks (bsc#1234042).\n- kABI workaround for ASoC SOF (bsc#1233305).\n- kABI: Restore exported __arm_smccc_sve_check (git-fixes)\n- kabi, mm: refactor arch_calc_vm_flag_bits() and arm64 MTE handling (git-fixes kabi).\n- kasan: move checks to do_strncpy_from_user (git-fixes).\n- kernel-binary: Enable livepatch package only when livepatch is enabled Otherwise the filelist may be empty failing the build (bsc#1218644).\n- kexec_file: fix elfcorehdr digest exclusion when CONFIG_CRASH_HOTPLUG=y (git-fixes).\n- leds: lp55xx: Remove redundant test for invalid channel number (git-fixes).\n- lib: string_helpers: silence snprintf() output truncation warning (git-fixes).\n- mailbox: arm_mhuv2: clean up loop in get_irq_chan_comb() (git-fixes).\n- maple_tree: fix alloc node fail issue (git-fixes).\n- maple_tree: refine mas_store_root() on storing NULL (git-fixes).\n- media: adv7604: prevent underflow condition when reporting colorspace (git-fixes).\n- media: amphion: Fix pm_runtime_set_suspended() with runtime pm enabled (git-fixes).\n- media: amphion: Set video drvdata before register video device (git-fixes).\n- media: ar0521: do not overflow when checking PLL values (git-fixes).\n- media: atomisp: Add check for rgby_data memory allocation failure (git-fixes).\n- media: cx24116: prevent overflows on SNR calculus (git-fixes).\n- media: dvb_frontend: do not play tricks with underflow values (git-fixes).\n- media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set (stable-fixes).\n- media: dvbdev: prevent the risk of out of memory access (git-fixes).\n- media: gspca: ov534-ov772x: Fix off-by-one error in set_frame_rate() (git-fixes).\n- media: i2c: dw9768: Fix pm_runtime_set_suspended() with runtime pm enabled (git-fixes).\n- media: i2c: tc358743: Fix crash in the probe error path when using polling (git-fixes).\n- media: imx-jpeg: Ensure power suppliers be suspended before detach them (git-fixes).\n- media: imx-jpeg: Set video drvdata before register video device (git-fixes).\n- media: mantis: remove orphan mantis_core.h (git-fixes).\n- media: mtk-jpeg: Fix null-ptr-deref during unload module (git-fixes).\n- media: platform: allegro-dvt: Fix possible memory leak in allocate_buffers_internal() (git-fixes).\n- media: platform: exynos4-is: Fix an OF node reference leak in fimc_md_is_isp_available (git-fixes).\n- media: pulse8-cec: fix data timestamp at pulse8_setup() (git-fixes).\n- media: s5p-jpeg: prevent buffer overflows (git-fixes).\n- media: stb0899_algo: initialize cfr before using it (git-fixes).\n- media: ts2020: fix null-ptr-deref in ts2020_probe() (git-fixes).\n- media: uvcvideo: Require entities to have a non-zero unique ID (git-fixes).\n- media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (git-fixes).\n- media: uvcvideo: Stop stream during unregister (git-fixes).\n- media: v4l2-ctrls-api: fix error handling for v4l2_g_ctrl() (git-fixes).\n- media: v4l2-tpg: prevent the risk of a division by zero (git-fixes).\n- media: vb2: Fix comment (git-fixes).\n- media: venus: Fix pm_runtime_set_suspended() with runtime pm enabled (git-fixes).\n- media: wl128x: Fix atomicity violation in fmc_send_cmd() (git-fixes).\n- mfd: rt5033: Fix missing regmap_del_irq_chip() (git-fixes).\n- mfd: tps65010: Use IRQF_NO_AUTOEN flag in request_irq() to fix race (git-fixes).\n- minmax: scsi: fix mis-use of \u0027clamp()\u0027 in sr.c (git-fixes).\n- misc: apds990x: Fix missing pm_runtime_disable() (git-fixes).\n- mlxbf_gige: disable RX filters until RX path initialized (git-fixes).\n- mm/hugetlb: fix nodes huge page allocation when there are surplus pages (bsc#1234012).\n- mm: avoid unsafe VMA hook invocation when error arises on mmap hook (git-fixes).\n- mm: move dummy_vm_ops out of a header (git-fixes prerequisity).\n- mm: refactor arch_calc_vm_flag_bits() and arm64 MTE handling (git-fixes).\n- mm: refactor map_deny_write_exec() (git-fixes).\n- mm: resolve faulty mmap_region() error path behaviour (git-fixes).\n- mm: unconditionally close VMAs on error (git-fixes).\n- mmc: core: Further prevent card detect during shutdown (git-fixes).\n- mmc: mmc_spi: drop buggy snprintf() (git-fixes).\n- mmc: sunxi-mmc: Fix A100 compatible description (git-fixes).\n- modpost: remove incorrect code in do_eisa_entry() (git-fixes).\n- mtd: rawnand: atmel: Fix possible memory leak (git-fixes).\n- mtd: spi-nor: core: replace dummy buswidth from addr to data (git-fixes).\n- net: mdio-ipq4019: add missing error check (git-fixes).\n- net: phy: dp83822: Fix reset pin definitions (git-fixes).\n- net: phy: ti: add PHY_RST_AFTER_CLK_EN flag (git-fixes).\n- net: relax socket state check at accept time (git-fixes).\n- net: usb: lan78xx: Fix double free issue with interrupt buffer allocation (git-fixes).\n- net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device (git-fixes).\n- net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL configuration (git-fixes).\n- net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition (stable-fixes).\n- net: wwan: fix global oob in wwan_rtnl_policy (git-fixes).\n- net: wwan: t7xx: Fix off-by-one error in t7xx_dpmaif_rx_buf_alloc() (git-fixes).\n- net: xfrm: preserve kabi for xfrm_state (bsc#1233754).\n- netdevsim: copy addresses for both in and out paths (git-fixes).\n- netfilter: nf_tables: missing iterator type in lookup walk (git-fixes).\n- nfs: Fix KMSAN warning in decode_getfattr_attrs() (git-fixes).\n- nfs: avoid i_lock contention in nfs_clear_invalid_mapping (git-fixes).\n- nfsd: remove unsafe BUG_ON from set_change_info (bsc#1234121).\n- nilfs2: fix potential deadlock with newly created symlinks (git-fixes).\n- nouveau/dp: handle retries for AUX CH transfers with GSP (git-fixes).\n- nouveau: fw: sync dma after setup is called (git-fixes).\n- nouveau: handle EBUSY and EAGAIN for GSP aux errors (git-fixes).\n- ntfs3: Add bounds checking to mi_enum_attr() (bsc#1233207)\n- nvme-fabrics: fix kernel crash while shutting down controller (git-fixes).\n- nvme-loop: flush off pending I/O while shutting down loop controller (git-fixes).\n- nvme-pci: fix freeing of the HMB descriptor table (git-fixes).\n- nvme-pci: reverse request order in nvme_queue_rqs (git-fixes).\n- nvme/host: Fix RCU list traversal to use SRCU primitive (git-fixes).\n- nvme: tcp: avoid race between queue_lock lock and destroy (git-fixes).\n- ocfs2: fix UBSAN warning in ocfs2_verify_volume() (git-fixes).\n- ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove() (git-fixes).\n- ocfs2: uncache inode which has failed entering the group (git-fixes).\n- of: Add cleanup.h based auto release via __free(device_node) markings (bsc#1232386)\n- pinctrl: k210: Undef K210_PC_DEFAULT (git-fixes).\n- pinctrl: qcom: spmi: fix debugfs drive strength (git-fixes).\n- pinctrl: zynqmp: drop excess struct member description (git-fixes).\n- platform/chrome: cros_ec_typec: fix missing fwnode reference decrement (git-fixes).\n- platform/x86/amd/pmc: Detect when STB is not available (git-fixes).\n- platform/x86: panasonic-laptop: Return errno correctly in show callback (git-fixes).\n- posix-cpu-timers: Clear TICK_DEP_BIT_POSIX_TIMER on clone (bsc#1234098).\n- power: supply: bq27xxx: Fix registers of bq27426 (git-fixes).\n- power: supply: core: Remove might_sleep() from power_supply_put() (git-fixes).\n- power: supply: rt9471: Fix wrong WDT function regfield declaration (git-fixes).\n- power: supply: rt9471: Use IC status regfield to report real charger status (git-fixes).\n- powerpc/64s: Fix unnecessary copy to 0 when kernel is booted at address 0 (bsc#1215199).\n- powerpc/atomic: Use YZ constraints for DS-form instructions (bsc#1194869).\n- powerpc/fadump: Move fadump_cma_init to setup_arch() after initmem_init() (bsc#1215199).\n- powerpc/fadump: Refactor and prepare fadump_cma_init for late init (bsc#1215199).\n- powerpc/kexec: Fix return of uninitialized variable (bsc#1194869).\n- powerpc/mm/fault: Fix kfence page fault reporting (bsc#1194869).\n- powerpc/mm: Fix boot crash with FLATMEM (bsc#1194869).\n- powerpc/mm: Fix boot warning with hugepages and CONFIG_DEBUG_VIRTUAL (bsc#1194869).\n- powerpc/powernv: Free name on error in opal_event_init() (bsc#1194869).\n- powerpc/pseries: Fix KVM guest detection for disabling hardlockup detector (bsc#1194869).\n- powerpc/pseries: Fix dtl_access_lock to be a rw_semaphore (bsc#1194869).\n- powerpc/pseries: Use correct data types from pseries_hp_errorlog struct (bsc#1215199).\n- powerpc/vdso: Inconditionally use CFUNC macro (bsc#1215199).\n- pwm: imx-tpm: Use correct MODULO value for EPWM mode (git-fixes).\n- regmap: detach regmap from dev on regmap_exit (git-fixes).\n- regmap: irq: Set lockdep class for hierarchical IRQ domains (git-fixes).\n- rpm/scripts: Remove obsolete Symbols.list Symbols.list is not longer needed by the new klp-convert implementation. (bsc#1218644)\n- rtc: ab-eoz9: do not fail temperature reads on undervoltage notification (git-fixes).\n- rtc: abx80x: Fix WDT bit position of the status register (git-fixes).\n- rtc: bbnsm: add remove hook (git-fixes).\n- rtc: check if __rtc_read_time was successful in rtc_timer_do_work() (git-fixes).\n- rtc: rzn1: fix BCD to rtc_time conversion errors (git-fixes).\n- rtc: st-lpc: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).\n- scsi: NCR5380: Check for phase match during PDMA fixup (git-fixes).\n- scsi: NCR5380: Initialize buffer for MSG IN and STATUS transfers (git-fixes).\n- scsi: Remove scsi device no_start_on_resume flag (git-fixes).\n- scsi: aacraid: Rearrange order of struct aac_srb_unit (git-fixes).\n- scsi: cdrom: kABI: fix cdrom_dev_ops change (git-fixes).\n- scsi: core: Disable CDL by default (git-fixes).\n- scsi: core: Fix handling of SCMD_FAIL_IF_RECOVERING (git-fixes).\n- scsi: core: Fix the return value of scsi_logical_block_count() (git-fixes).\n- scsi: core: Handle devices which return an unusually large VPD page count (git-fixes).\n- scsi: core: alua: I/O errors for ALUA state transitions (git-fixes).\n- scsi: hisi_sas: Handle the NCQ error returned by D2H frame (git-fixes).\n- scsi: hpsa: Fix allocation size for Scsi_Host private data (git-fixes).\n- scsi: kABI: restore no_start_on_resume to scsi_device (git-fixes).\n- scsi: libsas: Fix exp-attached device scan after probe failure scanned in again after probe failed (git-fixes).\n- scsi: libsas: Fix the failure of adding phy with zero-address to port (git-fixes).\n- scsi: lpfc: Add cleanup of nvmels_wq after HBA reset (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Call lpfc_sli4_queue_unset() in restart and rmmod paths (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Change lpfc_nodelist nlp_flag member into a bitmask (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Check SLI_ACTIVE flag in FDMI cmpl before submitting follow up FDMI (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Check devloss callbk done flag for potential stale NDLP ptrs (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Copyright updates for 14.4.0.6 patches (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Modify CGN warning signal calculation based on EDC response (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Prevent NDLP reference count underflow in dev_loss_tmo callback (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Remove NLP_RELEASE_RPI flag from nodelist structure (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Update lpfc version to 14.4.0.6 (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Update lpfc_els_flush_cmd() to check for SLI_ACTIVE before BSG flag (bsc#1233241 jsc#PED-9943).\n- scsi: mac_scsi: Disallow bus errors during PDMA send (git-fixes).\n- scsi: mac_scsi: Refactor polling loop (git-fixes).\n- scsi: mac_scsi: Revise printk(KERN_DEBUG ...) messages (git-fixes).\n- scsi: mpi3mr: Avoid IOMMU page faults on REPORT ZONES (git-fixes).\n- scsi: mpi3mr: Avoid memcpy field-spanning write WARNING (git-fixes).\n- scsi: mpi3mr: Avoid possible run-time warning with long manufacturer strings (git-fixes).\n- scsi: mpi3mr: Fix ATA NCQ priority support (git-fixes).\n- scsi: mpi3mr: Validate SAS port assignments (git-fixes).\n- scsi: mpt3sas: Avoid IOMMU page faults on REPORT ZONES (git-fixes).\n- scsi: pm8001: Do not overwrite PCI queue mapping (git-fixes).\n- scsi: pm80xx: Set phy-\u003eenable_completion only when we wait for it (git-fixes).\n- scsi: qedf: Set qed_slowpath_params to zero before use (git-fixes).\n- scsi: scsi_transport_fc: Allow setting rport state to current state (git-fixes).\n- scsi: sd: Ignore command SYNCHRONIZE CACHE error if format in progress (git-fixes).\n- scsi: sd_zbc: Use kvzalloc() to allocate REPORT ZONES buffer (git-fixes).\n- scsi: smartpqi: correct stream detection (git-fixes).\n- scsi: smartpqi: revert propagate-the-multipath-failure-to-SML-quickly (git-fixes).\n- scsi: spi: Fix sshdr use (git-fixes).\n- scsi: sr: Fix unintentional arithmetic wraparound (git-fixes).\n- scsi: wd33c93: Do not use stale scsi_pointer value (git-fixes).\n- security/keys: fix slab-out-of-bounds in key_task_permission (git-fixes).\n- serial: 8250: omap: Move pm_runtime_get_sync (git-fixes).\n- signal: Replace BUG_ON()s (bsc#1234093).\n- soc: fsl: rcpm: fix missing of_node_put() in copy_ippdexpcr1_setting() (git-fixes).\n- soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get() (git-fixes).\n- soc: ti: smartreflex: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).\n- spi: Fix acpi deferred irq probe (git-fixes).\n- spi: atmel-quadspi: Fix register name in verbose logging function (git-fixes).\n- spi: mpc52xx: Add cancel_work_sync before module remove (git-fixes).\n- spi: tegra210-quad: Avoid shift-out-of-bounds (git-fixes).\n- tcp: Fix refcnt handling in __inet_hash_connect() (git-fixes).\n- thermal: core: Initialize thermal zones before registering them (git-fixes).\n- thermal: int3400: Fix reading of current_uuid for active policy (git-fixes).\n- thermal: intel: int340x: processor: Fix warning during module unload (git-fixes).\n- thunderbolt: Honor TMU requirements in the domain when setting TMU mode (stable-fixes).\n- tools/lib/thermal: Fix sampling handler context ptr (git-fixes).\n- tools/power turbostat: Fix trailing \u0027\\n\u0027 parsing (git-fixes).\n- tools/power turbostat: Increase the limit for fd opened (bsc#1233119).\n- tpm: Lock TPM chip in tpm_pm_suspend() first (bsc#1082555 git-fixes).\n- tpm: fix signed/unsigned bug when checking event logs (git-fixes).\n- tty: ldsic: fix tty_ldisc_autoload sysctl\u0027s proc_handler (git-fixes).\n- u64_stats: fix u64_stats_init() for lockdep when used repeatedly in one file (git-fixes).\n- ucounts: fix counter leak in inc_rlimit_get_ucounts() (bsc#1233460).\n- unicode: Fix utf8_load() error path (git-fixes).\n- usb: dwc3: gadget: Add missing check for single port RAM in TxFIFO resizing logic (git-fixes).\n- usb: dwc3: gadget: Fix checking for number of TRBs left (git-fixes).\n- usb: dwc3: gadget: Fix looping of queued SG entries (git-fixes).\n- usb: ehci-spear: fix call balance of sehci clk handling routines (git-fixes).\n- usb: gadget: dummy_hcd: Set transfer interval to 1 microframe (stable-fixes).\n- usb: gadget: dummy_hcd: Switch to hrtimer transfer scheduler (stable-fixes).\n- usb: gadget: dummy_hcd: execute hrtimer callback in softirq context (git-fixes).\n- usb: musb: Fix hardware lockup on first Rx endpoint request (git-fixes).\n- usb: musb: sunxi: Fix accessing an released usb phy (git-fixes).\n- usb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd() (git-fixes).\n- usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read() (git-fixes).\n- usb: xhci: Fix TD invalidation under pending Set TR Dequeue (git-fixes).\n- usb: yurex: make waiting on yurex_write interruptible (git-fixes).\n- vsock: Update msg_count on read_skb() (git-fixes).\n- watchdog: apple: Actually flush writes after requesting watchdog restart (git-fixes).\n- watchdog: mediatek: Make sure system reset gets asserted in mtk_wdt_restart() (git-fixes).\n- watchdog: rti: of: honor timeout-sec property (git-fixes).\n- wifi: ath10k: fix invalid VHT parameters in supported_vht_mcs_rate_nss1 (git-fixes).\n- wifi: ath10k: fix invalid VHT parameters in supported_vht_mcs_rate_nss2 (git-fixes).\n- wifi: ath11k: Fix CE offset address calculation for WCN6750 in SSR (git-fixes).\n- wifi: ath12k: Skip Rx TID cleanup for self peer (git-fixes).\n- wifi: ath12k: fix crash when unbinding (git-fixes).\n- wifi: ath12k: fix warning when unbinding (git-fixes).\n- wifi: ath12k: remove msdu_end structure for WCN7850 (git-fixes).\n- wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() (git-fixes).\n- wifi: brcmfmac: release \u0027root\u0027 node in all execution paths (git-fixes).\n- wifi: cw1200: Fix potential NULL dereference (git-fixes).\n- wifi: iwlegacy: Clear stale interrupts before resuming device (stable-fixes).\n- wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan() (git-fixes).\n- wifi: mwifiex: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).\n- wifi: p54: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).\n- wifi: wfx: Fix error handling in wfx_core_init() (git-fixes).\n- x86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client (bsc#1233443).\n- x86/microcode/intel: Remove unnecessary cache writeback and invalidation (git-fixes).\n- x86/resctrl: Remove hard-coded memory bandwidth limit (git-fixes).\n- x86/syscall: Avoid memcpy() for ia32 syscall_get_arguments() (git-fixes).\n- x86/tdx: Dynamically disable SEPT violations from causing #VEs (git-fixes).\n- x86/tdx: Enable CPU topology enumeration (git-fixes).\n- x86/tdx: Introduce wrappers to read and write TD metadata (git-fixes).\n- x86/tdx: Rename tdx_parse_tdinfo() to tdx_setup() (git-fixes).\n- x86/traps: move kmsan check after instrumentation_begin (git-fixes).\n- x86: Increase brk randomness entropy for 64-bit systems (git-fixes).\n- x86: fix off-by-one in access_ok() (git-fixes).\n- xfrm: Export symbol xfrm_dev_state_delete (bsc#1233754).\n- xfrm: Fix unregister netdevice hang on hardware offload (bsc#1233754).\n- drm: Expand max DRM device number to full MINORBITS (jsc#PED-11580).\n- accel: Use XArray instead of IDR for minors (jsc#PED-11580).\n- drm: Use XArray instead of IDR for minors (jsc#PED-11580).\n- scsi: lpfc: Copyright updates for 14.4.0.6 patches (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Update lpfc version to 14.4.0.6 (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Change lpfc_nodelist nlp_flag member into a bitmask (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Remove NLP_RELEASE_RPI flag from nodelist structure (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Prevent NDLP reference count underflow in dev_loss_tmo callback (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Add cleanup of nvmels_wq after HBA reset (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Check SLI_ACTIVE flag in FDMI cmpl before submitting follow up FDMI (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Update lpfc_els_flush_cmd() to check for SLI_ACTIVE before BSG flag (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Call lpfc_sli4_queue_unset() in restart and rmmod paths (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Check devloss callbk done flag for potential stale NDLP ptrs (bsc#1233241 jsc#PED-9943).\n- scsi: lpfc: Modify CGN warning signal calculation based on EDC response (bsc#1233241 jsc#PED-9943).\n\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-2024-4316,SUSE-SLE-Module-Public-Cloud-15-SP6-2024-4316,openSUSE-SLE-15.6-2024-4316", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2024_4316-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2024:4316-1", "url": "https://www.suse.com/support/update/announcement/2024/suse-su-20244316-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2024:4316-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2024-December/020001.html" }, { "category": "self", "summary": "SUSE Bug 1012628", "url": "https://bugzilla.suse.com/1012628" }, { "category": "self", "summary": "SUSE Bug 1082555", "url": "https://bugzilla.suse.com/1082555" }, { "category": "self", "summary": "SUSE Bug 1194869", "url": "https://bugzilla.suse.com/1194869" }, { "category": "self", "summary": "SUSE Bug 1215199", "url": "https://bugzilla.suse.com/1215199" }, { "category": "self", "summary": "SUSE Bug 1218644", "url": "https://bugzilla.suse.com/1218644" }, { "category": "self", "summary": "SUSE Bug 1220355", "url": "https://bugzilla.suse.com/1220355" }, { "category": "self", "summary": "SUSE Bug 1221309", "url": "https://bugzilla.suse.com/1221309" }, { "category": "self", "summary": "SUSE Bug 1222423", "url": "https://bugzilla.suse.com/1222423" }, { "category": "self", "summary": "SUSE Bug 1222587", "url": "https://bugzilla.suse.com/1222587" }, { "category": "self", "summary": "SUSE Bug 1222590", "url": "https://bugzilla.suse.com/1222590" }, { "category": "self", "summary": "SUSE Bug 1223112", "url": "https://bugzilla.suse.com/1223112" }, { "category": "self", "summary": "SUSE Bug 1223656", "url": "https://bugzilla.suse.com/1223656" }, { "category": "self", "summary": "SUSE Bug 1223733", "url": "https://bugzilla.suse.com/1223733" }, { "category": "self", "summary": "SUSE Bug 1224429", "url": "https://bugzilla.suse.com/1224429" }, { "category": "self", "summary": "SUSE Bug 1224518", "url": "https://bugzilla.suse.com/1224518" }, { "category": "self", "summary": "SUSE Bug 1224548", "url": "https://bugzilla.suse.com/1224548" }, { "category": "self", "summary": "SUSE Bug 1224948", "url": "https://bugzilla.suse.com/1224948" }, { "category": "self", "summary": "SUSE Bug 1225713", "url": "https://bugzilla.suse.com/1225713" }, { "category": "self", "summary": "SUSE Bug 1225725", "url": "https://bugzilla.suse.com/1225725" }, { "category": "self", "summary": "SUSE Bug 1225730", "url": "https://bugzilla.suse.com/1225730" }, { "category": "self", "summary": "SUSE Bug 1225742", "url": "https://bugzilla.suse.com/1225742" }, { "category": "self", "summary": "SUSE Bug 1225764", "url": "https://bugzilla.suse.com/1225764" }, { "category": "self", "summary": "SUSE Bug 1225768", "url": "https://bugzilla.suse.com/1225768" }, { "category": "self", "summary": "SUSE Bug 1225813", "url": "https://bugzilla.suse.com/1225813" }, { "category": "self", "summary": "SUSE Bug 1225903", "url": "https://bugzilla.suse.com/1225903" }, { "category": "self", "summary": "SUSE Bug 1226130", "url": "https://bugzilla.suse.com/1226130" }, { "category": "self", "summary": "SUSE Bug 1226748", "url": "https://bugzilla.suse.com/1226748" }, { "category": "self", "summary": "SUSE Bug 1226872", "url": "https://bugzilla.suse.com/1226872" }, { "category": "self", "summary": "SUSE Bug 1227726", "url": "https://bugzilla.suse.com/1227726" }, { "category": "self", "summary": "SUSE Bug 1227842", "url": "https://bugzilla.suse.com/1227842" }, { "category": "self", "summary": "SUSE Bug 1228430", "url": "https://bugzilla.suse.com/1228430" }, { "category": "self", "summary": "SUSE Bug 1228850", "url": "https://bugzilla.suse.com/1228850" }, { "category": "self", "summary": "SUSE Bug 1229165", "url": "https://bugzilla.suse.com/1229165" }, { "category": "self", "summary": "SUSE Bug 1230231", "url": "https://bugzilla.suse.com/1230231" }, { "category": "self", "summary": "SUSE Bug 1230557", "url": "https://bugzilla.suse.com/1230557" }, { "category": "self", "summary": "SUSE Bug 1230558", "url": "https://bugzilla.suse.com/1230558" }, { "category": "self", "summary": "SUSE Bug 1230733", "url": "https://bugzilla.suse.com/1230733" }, { "category": "self", "summary": "SUSE Bug 1230807", "url": "https://bugzilla.suse.com/1230807" }, { "category": "self", "summary": "SUSE Bug 1230817", "url": "https://bugzilla.suse.com/1230817" }, { "category": "self", "summary": "SUSE Bug 1230827", "url": "https://bugzilla.suse.com/1230827" }, { "category": "self", "summary": "SUSE Bug 1230971", "url": "https://bugzilla.suse.com/1230971" }, { "category": "self", "summary": "SUSE Bug 1231076", "url": "https://bugzilla.suse.com/1231076" }, { "category": "self", "summary": "SUSE Bug 1231114", "url": "https://bugzilla.suse.com/1231114" }, { "category": "self", "summary": "SUSE Bug 1231182", "url": "https://bugzilla.suse.com/1231182" }, { "category": "self", "summary": "SUSE Bug 1231453", "url": "https://bugzilla.suse.com/1231453" }, { "category": "self", "summary": "SUSE Bug 1231465", "url": "https://bugzilla.suse.com/1231465" }, { "category": "self", "summary": "SUSE Bug 1231630", "url": "https://bugzilla.suse.com/1231630" }, { "category": "self", "summary": "SUSE Bug 1231920", "url": "https://bugzilla.suse.com/1231920" }, { "category": "self", "summary": "SUSE Bug 1231930", "url": "https://bugzilla.suse.com/1231930" }, { "category": "self", "summary": "SUSE Bug 1231946", "url": "https://bugzilla.suse.com/1231946" }, { "category": "self", "summary": "SUSE Bug 1231952", "url": "https://bugzilla.suse.com/1231952" }, { "category": "self", "summary": "SUSE Bug 1232096", "url": "https://bugzilla.suse.com/1232096" }, { "category": "self", "summary": "SUSE Bug 1232103", "url": "https://bugzilla.suse.com/1232103" }, { "category": "self", "summary": "SUSE Bug 1232104", "url": "https://bugzilla.suse.com/1232104" }, { "category": "self", "summary": "SUSE Bug 1232157", "url": "https://bugzilla.suse.com/1232157" }, { "category": "self", "summary": "SUSE Bug 1232165", "url": "https://bugzilla.suse.com/1232165" }, { "category": "self", "summary": "SUSE Bug 1232166", "url": "https://bugzilla.suse.com/1232166" }, { "category": "self", "summary": "SUSE Bug 1232198", "url": "https://bugzilla.suse.com/1232198" }, { "category": "self", "summary": "SUSE Bug 1232201", "url": "https://bugzilla.suse.com/1232201" }, { "category": "self", "summary": "SUSE Bug 1232207", "url": "https://bugzilla.suse.com/1232207" }, { "category": "self", "summary": "SUSE Bug 1232208", "url": "https://bugzilla.suse.com/1232208" }, { "category": "self", "summary": "SUSE Bug 1232224", "url": "https://bugzilla.suse.com/1232224" }, { "category": "self", "summary": "SUSE Bug 1232258", "url": "https://bugzilla.suse.com/1232258" }, { "category": "self", "summary": "SUSE Bug 1232264", "url": "https://bugzilla.suse.com/1232264" }, { "category": "self", "summary": "SUSE Bug 1232272", "url": "https://bugzilla.suse.com/1232272" }, { "category": "self", "summary": "SUSE Bug 1232318", "url": "https://bugzilla.suse.com/1232318" }, { "category": "self", "summary": "SUSE Bug 1232335", "url": "https://bugzilla.suse.com/1232335" }, { "category": "self", "summary": "SUSE Bug 1232357", "url": "https://bugzilla.suse.com/1232357" }, { "category": "self", "summary": "SUSE Bug 1232358", "url": "https://bugzilla.suse.com/1232358" }, { "category": "self", "summary": "SUSE Bug 1232361", "url": "https://bugzilla.suse.com/1232361" }, { "category": "self", "summary": "SUSE Bug 1232366", "url": "https://bugzilla.suse.com/1232366" }, { "category": "self", "summary": "SUSE Bug 1232367", "url": "https://bugzilla.suse.com/1232367" }, { "category": "self", "summary": "SUSE Bug 1232368", "url": "https://bugzilla.suse.com/1232368" }, { "category": "self", "summary": "SUSE Bug 1232371", "url": "https://bugzilla.suse.com/1232371" }, { "category": "self", "summary": "SUSE Bug 1232374", "url": "https://bugzilla.suse.com/1232374" }, { "category": "self", "summary": "SUSE Bug 1232385", "url": "https://bugzilla.suse.com/1232385" }, { "category": "self", "summary": "SUSE Bug 1232386", "url": "https://bugzilla.suse.com/1232386" }, { "category": "self", "summary": "SUSE Bug 1232387", "url": "https://bugzilla.suse.com/1232387" }, { "category": "self", "summary": "SUSE Bug 1232396", "url": "https://bugzilla.suse.com/1232396" }, { "category": "self", "summary": "SUSE Bug 1232413", "url": "https://bugzilla.suse.com/1232413" }, { "category": "self", "summary": "SUSE Bug 1232416", "url": "https://bugzilla.suse.com/1232416" }, { "category": "self", "summary": "SUSE Bug 1232436", "url": "https://bugzilla.suse.com/1232436" }, { "category": "self", "summary": "SUSE Bug 1232442", "url": "https://bugzilla.suse.com/1232442" }, { "category": "self", "summary": "SUSE Bug 1232446", "url": "https://bugzilla.suse.com/1232446" }, { "category": "self", "summary": "SUSE Bug 1232483", "url": "https://bugzilla.suse.com/1232483" }, { "category": "self", "summary": "SUSE Bug 1232494", "url": "https://bugzilla.suse.com/1232494" }, { "category": "self", "summary": "SUSE Bug 1232498", "url": "https://bugzilla.suse.com/1232498" }, { "category": "self", "summary": "SUSE Bug 1232499", "url": "https://bugzilla.suse.com/1232499" }, { "category": "self", "summary": "SUSE Bug 1232500", "url": "https://bugzilla.suse.com/1232500" }, { "category": "self", "summary": "SUSE Bug 1232704", "url": "https://bugzilla.suse.com/1232704" }, { "category": "self", "summary": "SUSE Bug 1232757", "url": "https://bugzilla.suse.com/1232757" }, { "category": "self", "summary": "SUSE Bug 1232823", "url": "https://bugzilla.suse.com/1232823" }, { "category": "self", "summary": "SUSE Bug 1232860", "url": "https://bugzilla.suse.com/1232860" }, { "category": "self", "summary": "SUSE Bug 1232869", "url": "https://bugzilla.suse.com/1232869" }, { "category": "self", "summary": "SUSE Bug 1232870", "url": "https://bugzilla.suse.com/1232870" }, { "category": "self", "summary": "SUSE Bug 1232873", "url": "https://bugzilla.suse.com/1232873" }, { "category": "self", "summary": "SUSE Bug 1232876", "url": "https://bugzilla.suse.com/1232876" }, { "category": "self", "summary": "SUSE Bug 1232877", "url": "https://bugzilla.suse.com/1232877" }, { "category": "self", "summary": "SUSE Bug 1232878", "url": "https://bugzilla.suse.com/1232878" }, { "category": "self", "summary": "SUSE Bug 1232880", "url": "https://bugzilla.suse.com/1232880" }, { "category": "self", "summary": "SUSE Bug 1232881", "url": "https://bugzilla.suse.com/1232881" }, { "category": "self", "summary": "SUSE Bug 1232884", "url": "https://bugzilla.suse.com/1232884" }, { "category": "self", "summary": "SUSE Bug 1232885", "url": "https://bugzilla.suse.com/1232885" }, { "category": "self", "summary": "SUSE Bug 1232887", "url": "https://bugzilla.suse.com/1232887" }, { "category": "self", "summary": "SUSE Bug 1232888", "url": "https://bugzilla.suse.com/1232888" }, { "category": "self", "summary": "SUSE Bug 1232890", "url": "https://bugzilla.suse.com/1232890" }, { "category": "self", "summary": "SUSE Bug 1232892", "url": "https://bugzilla.suse.com/1232892" }, { "category": "self", "summary": "SUSE Bug 1232894", "url": "https://bugzilla.suse.com/1232894" }, { "category": "self", "summary": "SUSE Bug 1232896", "url": "https://bugzilla.suse.com/1232896" }, { "category": "self", "summary": "SUSE Bug 1232897", "url": "https://bugzilla.suse.com/1232897" }, { "category": "self", "summary": "SUSE Bug 1232905", "url": "https://bugzilla.suse.com/1232905" }, { "category": "self", "summary": "SUSE Bug 1232907", "url": "https://bugzilla.suse.com/1232907" }, { "category": "self", "summary": "SUSE Bug 1232914", "url": "https://bugzilla.suse.com/1232914" }, { "category": "self", "summary": "SUSE Bug 1232919", "url": "https://bugzilla.suse.com/1232919" }, { "category": "self", "summary": "SUSE Bug 1232925", "url": "https://bugzilla.suse.com/1232925" }, { "category": "self", "summary": "SUSE Bug 1232926", "url": "https://bugzilla.suse.com/1232926" }, { "category": "self", "summary": "SUSE Bug 1232928", "url": "https://bugzilla.suse.com/1232928" }, { "category": "self", "summary": "SUSE Bug 1232935", "url": "https://bugzilla.suse.com/1232935" }, { "category": "self", "summary": "SUSE Bug 1233029", "url": "https://bugzilla.suse.com/1233029" }, { "category": "self", "summary": "SUSE Bug 1233032", "url": "https://bugzilla.suse.com/1233032" }, { "category": "self", "summary": "SUSE Bug 1233035", "url": "https://bugzilla.suse.com/1233035" }, { "category": "self", "summary": "SUSE Bug 1233036", "url": "https://bugzilla.suse.com/1233036" }, { "category": "self", "summary": "SUSE Bug 1233041", "url": "https://bugzilla.suse.com/1233041" }, { "category": "self", "summary": "SUSE Bug 1233044", "url": "https://bugzilla.suse.com/1233044" }, { "category": "self", "summary": "SUSE Bug 1233049", "url": "https://bugzilla.suse.com/1233049" }, { "category": "self", "summary": "SUSE Bug 1233050", "url": "https://bugzilla.suse.com/1233050" }, { "category": "self", "summary": "SUSE Bug 1233051", "url": "https://bugzilla.suse.com/1233051" }, { "category": "self", "summary": "SUSE Bug 1233056", "url": "https://bugzilla.suse.com/1233056" }, { "category": "self", "summary": "SUSE Bug 1233057", "url": "https://bugzilla.suse.com/1233057" }, { "category": "self", "summary": "SUSE Bug 1233061", "url": "https://bugzilla.suse.com/1233061" }, { "category": "self", "summary": "SUSE Bug 1233062", "url": "https://bugzilla.suse.com/1233062" }, { "category": "self", "summary": "SUSE Bug 1233063", "url": "https://bugzilla.suse.com/1233063" }, { "category": "self", "summary": "SUSE Bug 1233065", "url": "https://bugzilla.suse.com/1233065" }, { "category": "self", "summary": "SUSE Bug 1233067", "url": "https://bugzilla.suse.com/1233067" }, { "category": "self", "summary": "SUSE Bug 1233070", "url": "https://bugzilla.suse.com/1233070" }, { "category": "self", "summary": "SUSE Bug 1233073", "url": "https://bugzilla.suse.com/1233073" }, { "category": "self", "summary": "SUSE Bug 1233074", "url": "https://bugzilla.suse.com/1233074" }, { "category": "self", "summary": "SUSE Bug 1233088", "url": "https://bugzilla.suse.com/1233088" }, { "category": "self", "summary": "SUSE Bug 1233091", "url": "https://bugzilla.suse.com/1233091" }, { "category": "self", "summary": "SUSE Bug 1233092", "url": "https://bugzilla.suse.com/1233092" }, { "category": "self", "summary": "SUSE Bug 1233097", "url": "https://bugzilla.suse.com/1233097" }, { "category": "self", "summary": "SUSE Bug 1233100", "url": "https://bugzilla.suse.com/1233100" }, { "category": "self", "summary": "SUSE Bug 1233103", "url": "https://bugzilla.suse.com/1233103" }, { "category": "self", "summary": "SUSE Bug 1233104", "url": "https://bugzilla.suse.com/1233104" }, { "category": "self", "summary": "SUSE Bug 1233105", "url": "https://bugzilla.suse.com/1233105" }, { "category": "self", "summary": "SUSE Bug 1233106", "url": "https://bugzilla.suse.com/1233106" }, { "category": "self", "summary": "SUSE Bug 1233107", "url": "https://bugzilla.suse.com/1233107" }, { "category": "self", "summary": "SUSE Bug 1233108", "url": "https://bugzilla.suse.com/1233108" }, { "category": "self", "summary": "SUSE Bug 1233110", "url": "https://bugzilla.suse.com/1233110" }, { "category": "self", "summary": "SUSE Bug 1233111", "url": "https://bugzilla.suse.com/1233111" }, { "category": "self", "summary": "SUSE Bug 1233113", "url": "https://bugzilla.suse.com/1233113" }, { "category": "self", "summary": "SUSE Bug 1233114", "url": "https://bugzilla.suse.com/1233114" }, { "category": "self", "summary": "SUSE Bug 1233115", "url": "https://bugzilla.suse.com/1233115" }, { "category": "self", "summary": "SUSE Bug 1233117", "url": "https://bugzilla.suse.com/1233117" }, { "category": "self", "summary": "SUSE Bug 1233119", "url": "https://bugzilla.suse.com/1233119" }, { "category": "self", "summary": "SUSE Bug 1233123", "url": "https://bugzilla.suse.com/1233123" }, { "category": "self", "summary": "SUSE Bug 1233125", "url": "https://bugzilla.suse.com/1233125" }, { "category": "self", "summary": "SUSE Bug 1233127", "url": "https://bugzilla.suse.com/1233127" }, { "category": "self", "summary": "SUSE Bug 1233129", "url": "https://bugzilla.suse.com/1233129" }, { "category": "self", "summary": "SUSE Bug 1233130", "url": "https://bugzilla.suse.com/1233130" }, { "category": "self", "summary": "SUSE Bug 1233132", "url": "https://bugzilla.suse.com/1233132" }, { "category": "self", "summary": "SUSE Bug 1233135", "url": "https://bugzilla.suse.com/1233135" }, { "category": "self", "summary": "SUSE Bug 1233176", "url": "https://bugzilla.suse.com/1233176" }, { "category": "self", "summary": "SUSE Bug 1233179", "url": "https://bugzilla.suse.com/1233179" }, { "category": "self", "summary": "SUSE Bug 1233185", "url": "https://bugzilla.suse.com/1233185" }, { "category": "self", "summary": "SUSE Bug 1233188", "url": "https://bugzilla.suse.com/1233188" }, { "category": "self", "summary": "SUSE Bug 1233189", "url": "https://bugzilla.suse.com/1233189" }, { "category": "self", "summary": "SUSE Bug 1233191", "url": "https://bugzilla.suse.com/1233191" }, { "category": "self", "summary": "SUSE Bug 1233193", "url": "https://bugzilla.suse.com/1233193" }, { "category": "self", "summary": "SUSE Bug 1233197", "url": "https://bugzilla.suse.com/1233197" }, { "category": "self", "summary": "SUSE Bug 1233201", "url": "https://bugzilla.suse.com/1233201" }, { "category": "self", "summary": "SUSE Bug 1233203", "url": "https://bugzilla.suse.com/1233203" }, { "category": "self", "summary": "SUSE Bug 1233204", "url": "https://bugzilla.suse.com/1233204" }, { "category": "self", "summary": "SUSE Bug 1233205", "url": "https://bugzilla.suse.com/1233205" }, { "category": "self", "summary": "SUSE Bug 1233206", "url": "https://bugzilla.suse.com/1233206" }, { "category": "self", "summary": "SUSE Bug 1233207", "url": "https://bugzilla.suse.com/1233207" }, { "category": "self", "summary": "SUSE Bug 1233208", "url": "https://bugzilla.suse.com/1233208" }, { "category": "self", "summary": "SUSE Bug 1233209", "url": "https://bugzilla.suse.com/1233209" }, { "category": "self", "summary": "SUSE Bug 1233210", "url": "https://bugzilla.suse.com/1233210" }, { "category": "self", "summary": "SUSE Bug 1233211", "url": "https://bugzilla.suse.com/1233211" }, { "category": "self", "summary": "SUSE Bug 1233212", "url": "https://bugzilla.suse.com/1233212" }, { "category": "self", "summary": "SUSE Bug 1233216", "url": "https://bugzilla.suse.com/1233216" }, { "category": "self", "summary": "SUSE Bug 1233217", "url": "https://bugzilla.suse.com/1233217" }, { "category": "self", "summary": "SUSE Bug 1233219", "url": "https://bugzilla.suse.com/1233219" }, { "category": "self", "summary": "SUSE Bug 1233226", "url": "https://bugzilla.suse.com/1233226" }, { "category": "self", "summary": "SUSE Bug 1233238", "url": "https://bugzilla.suse.com/1233238" }, { "category": "self", "summary": "SUSE Bug 1233241", "url": "https://bugzilla.suse.com/1233241" }, { "category": "self", "summary": "SUSE Bug 1233244", "url": "https://bugzilla.suse.com/1233244" }, { "category": "self", "summary": "SUSE Bug 1233253", "url": "https://bugzilla.suse.com/1233253" }, { "category": "self", "summary": "SUSE Bug 1233255", "url": "https://bugzilla.suse.com/1233255" }, { "category": "self", "summary": "SUSE Bug 1233293", "url": "https://bugzilla.suse.com/1233293" }, { "category": "self", "summary": "SUSE Bug 1233298", "url": "https://bugzilla.suse.com/1233298" }, { "category": "self", "summary": "SUSE Bug 1233305", "url": "https://bugzilla.suse.com/1233305" }, { "category": "self", "summary": "SUSE Bug 1233320", "url": "https://bugzilla.suse.com/1233320" }, { "category": "self", "summary": "SUSE Bug 1233350", "url": "https://bugzilla.suse.com/1233350" }, { "category": "self", "summary": "SUSE Bug 1233443", "url": "https://bugzilla.suse.com/1233443" }, { "category": "self", "summary": "SUSE Bug 1233452", "url": "https://bugzilla.suse.com/1233452" }, { "category": "self", "summary": "SUSE Bug 1233453", "url": "https://bugzilla.suse.com/1233453" }, { "category": "self", "summary": "SUSE Bug 1233454", "url": "https://bugzilla.suse.com/1233454" }, { "category": "self", "summary": "SUSE Bug 1233456", "url": "https://bugzilla.suse.com/1233456" }, { "category": "self", "summary": "SUSE Bug 1233457", "url": "https://bugzilla.suse.com/1233457" }, { "category": "self", "summary": "SUSE Bug 1233458", "url": "https://bugzilla.suse.com/1233458" }, { "category": "self", "summary": "SUSE Bug 1233460", "url": "https://bugzilla.suse.com/1233460" }, { "category": "self", "summary": "SUSE Bug 1233462", "url": "https://bugzilla.suse.com/1233462" }, { "category": "self", "summary": "SUSE Bug 1233463", "url": "https://bugzilla.suse.com/1233463" }, { "category": "self", "summary": "SUSE Bug 1233464", "url": "https://bugzilla.suse.com/1233464" }, { "category": "self", "summary": "SUSE Bug 1233465", "url": "https://bugzilla.suse.com/1233465" }, { "category": "self", "summary": "SUSE Bug 1233468", "url": "https://bugzilla.suse.com/1233468" }, { "category": "self", "summary": "SUSE Bug 1233471", "url": "https://bugzilla.suse.com/1233471" }, { "category": "self", "summary": "SUSE Bug 1233476", "url": "https://bugzilla.suse.com/1233476" }, { "category": "self", "summary": "SUSE Bug 1233478", "url": "https://bugzilla.suse.com/1233478" }, { "category": "self", "summary": "SUSE Bug 1233479", "url": "https://bugzilla.suse.com/1233479" }, { "category": "self", "summary": "SUSE Bug 1233481", "url": "https://bugzilla.suse.com/1233481" }, { "category": "self", "summary": "SUSE Bug 1233484", "url": "https://bugzilla.suse.com/1233484" }, { "category": "self", "summary": "SUSE Bug 1233485", "url": "https://bugzilla.suse.com/1233485" }, { "category": "self", "summary": "SUSE Bug 1233487", "url": "https://bugzilla.suse.com/1233487" }, { "category": "self", "summary": "SUSE Bug 1233490", "url": "https://bugzilla.suse.com/1233490" }, { "category": "self", "summary": "SUSE Bug 1233491", "url": "https://bugzilla.suse.com/1233491" }, { "category": "self", "summary": "SUSE Bug 1233523", "url": "https://bugzilla.suse.com/1233523" }, { "category": "self", "summary": "SUSE Bug 1233524", "url": "https://bugzilla.suse.com/1233524" }, { "category": "self", "summary": "SUSE Bug 1233540", "url": "https://bugzilla.suse.com/1233540" }, { "category": "self", "summary": "SUSE Bug 1233547", "url": "https://bugzilla.suse.com/1233547" }, { "category": "self", "summary": "SUSE Bug 1233548", "url": "https://bugzilla.suse.com/1233548" }, { "category": "self", "summary": "SUSE Bug 1233550", "url": "https://bugzilla.suse.com/1233550" }, { "category": "self", "summary": "SUSE Bug 1233552", "url": "https://bugzilla.suse.com/1233552" }, { "category": "self", "summary": "SUSE Bug 1233553", "url": "https://bugzilla.suse.com/1233553" }, { "category": "self", "summary": "SUSE Bug 1233554", "url": "https://bugzilla.suse.com/1233554" }, { "category": "self", "summary": "SUSE Bug 1233555", "url": "https://bugzilla.suse.com/1233555" }, { "category": "self", "summary": "SUSE Bug 1233557", "url": "https://bugzilla.suse.com/1233557" }, { "category": "self", "summary": "SUSE Bug 1233560", "url": "https://bugzilla.suse.com/1233560" }, { "category": "self", "summary": "SUSE Bug 1233561", "url": "https://bugzilla.suse.com/1233561" }, { "category": "self", "summary": "SUSE Bug 1233564", "url": "https://bugzilla.suse.com/1233564" }, { "category": "self", "summary": "SUSE Bug 1233566", "url": "https://bugzilla.suse.com/1233566" }, { "category": "self", "summary": "SUSE Bug 1233567", "url": "https://bugzilla.suse.com/1233567" }, { "category": "self", "summary": "SUSE Bug 1233568", "url": "https://bugzilla.suse.com/1233568" }, { "category": "self", "summary": "SUSE Bug 1233570", "url": "https://bugzilla.suse.com/1233570" }, { "category": "self", "summary": "SUSE Bug 1233572", "url": "https://bugzilla.suse.com/1233572" }, { "category": "self", "summary": "SUSE Bug 1233573", "url": "https://bugzilla.suse.com/1233573" }, { "category": "self", "summary": "SUSE Bug 1233577", "url": "https://bugzilla.suse.com/1233577" }, { "category": "self", "summary": "SUSE Bug 1233580", "url": "https://bugzilla.suse.com/1233580" }, { "category": "self", "summary": "SUSE Bug 1233640", "url": "https://bugzilla.suse.com/1233640" }, { "category": "self", "summary": "SUSE Bug 1233641", "url": "https://bugzilla.suse.com/1233641" }, { "category": "self", "summary": "SUSE Bug 1233642", "url": "https://bugzilla.suse.com/1233642" }, { "category": "self", "summary": "SUSE Bug 1233721", "url": "https://bugzilla.suse.com/1233721" }, { "category": "self", "summary": "SUSE Bug 1233754", "url": "https://bugzilla.suse.com/1233754" }, { "category": "self", "summary": "SUSE Bug 1233756", "url": "https://bugzilla.suse.com/1233756" }, { "category": "self", "summary": "SUSE Bug 1233769", "url": "https://bugzilla.suse.com/1233769" }, { "category": "self", "summary": "SUSE Bug 1233771", "url": "https://bugzilla.suse.com/1233771" }, { "category": "self", "summary": "SUSE Bug 1233977", "url": "https://bugzilla.suse.com/1233977" }, { "category": "self", "summary": "SUSE Bug 1234009", "url": "https://bugzilla.suse.com/1234009" }, { "category": "self", "summary": "SUSE Bug 1234011", "url": "https://bugzilla.suse.com/1234011" }, { "category": "self", "summary": "SUSE Bug 1234012", "url": "https://bugzilla.suse.com/1234012" }, { "category": "self", "summary": "SUSE Bug 1234025", "url": "https://bugzilla.suse.com/1234025" }, { "category": "self", "summary": "SUSE Bug 1234039", "url": "https://bugzilla.suse.com/1234039" }, { "category": "self", "summary": "SUSE Bug 1234040", "url": "https://bugzilla.suse.com/1234040" }, { "category": "self", "summary": "SUSE Bug 1234041", "url": "https://bugzilla.suse.com/1234041" }, { "category": "self", "summary": "SUSE Bug 1234042", "url": "https://bugzilla.suse.com/1234042" }, { "category": "self", "summary": "SUSE Bug 1234043", "url": "https://bugzilla.suse.com/1234043" }, { "category": "self", "summary": "SUSE Bug 1234044", "url": "https://bugzilla.suse.com/1234044" }, { "category": "self", "summary": "SUSE Bug 1234045", "url": "https://bugzilla.suse.com/1234045" }, { "category": "self", "summary": "SUSE Bug 1234046", "url": "https://bugzilla.suse.com/1234046" }, { "category": "self", "summary": "SUSE Bug 1234072", "url": "https://bugzilla.suse.com/1234072" }, { "category": "self", "summary": "SUSE Bug 1234078", "url": "https://bugzilla.suse.com/1234078" }, { "category": "self", "summary": "SUSE Bug 1234081", "url": "https://bugzilla.suse.com/1234081" }, { "category": "self", "summary": "SUSE Bug 1234083", "url": "https://bugzilla.suse.com/1234083" }, { "category": "self", "summary": "SUSE Bug 1234085", "url": "https://bugzilla.suse.com/1234085" }, { "category": "self", "summary": "SUSE Bug 1234087", "url": "https://bugzilla.suse.com/1234087" }, { "category": "self", "summary": "SUSE Bug 1234093", "url": "https://bugzilla.suse.com/1234093" }, { "category": "self", "summary": "SUSE Bug 1234098", "url": "https://bugzilla.suse.com/1234098" }, { "category": "self", "summary": "SUSE Bug 1234108", "url": "https://bugzilla.suse.com/1234108" }, { "category": "self", "summary": "SUSE Bug 1234121", "url": "https://bugzilla.suse.com/1234121" }, { "category": "self", "summary": "SUSE Bug 1234223", "url": "https://bugzilla.suse.com/1234223" }, { "category": "self", "summary": "SUSE CVE CVE-2023-52778 page", "url": "https://www.suse.com/security/cve/CVE-2023-52778/" }, { "category": "self", "summary": "SUSE CVE CVE-2023-52920 page", "url": "https://www.suse.com/security/cve/CVE-2023-52920/" }, { "category": "self", "summary": "SUSE CVE CVE-2023-52921 page", "url": "https://www.suse.com/security/cve/CVE-2023-52921/" }, { "category": "self", "summary": "SUSE CVE CVE-2023-52922 page", "url": "https://www.suse.com/security/cve/CVE-2023-52922/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-26596 page", "url": "https://www.suse.com/security/cve/CVE-2024-26596/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-26703 page", "url": "https://www.suse.com/security/cve/CVE-2024-26703/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-26741 page", "url": "https://www.suse.com/security/cve/CVE-2024-26741/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-26782 page", "url": "https://www.suse.com/security/cve/CVE-2024-26782/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-26864 page", "url": "https://www.suse.com/security/cve/CVE-2024-26864/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-26953 page", "url": "https://www.suse.com/security/cve/CVE-2024-26953/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-27017 page", "url": "https://www.suse.com/security/cve/CVE-2024-27017/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-27407 page", "url": "https://www.suse.com/security/cve/CVE-2024-27407/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-35888 page", "url": "https://www.suse.com/security/cve/CVE-2024-35888/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36000 page", "url": "https://www.suse.com/security/cve/CVE-2024-36000/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36031 page", "url": "https://www.suse.com/security/cve/CVE-2024-36031/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36484 page", "url": "https://www.suse.com/security/cve/CVE-2024-36484/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36883 page", "url": "https://www.suse.com/security/cve/CVE-2024-36883/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36886 page", "url": "https://www.suse.com/security/cve/CVE-2024-36886/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36905 page", "url": "https://www.suse.com/security/cve/CVE-2024-36905/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36920 page", "url": "https://www.suse.com/security/cve/CVE-2024-36920/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36927 page", "url": "https://www.suse.com/security/cve/CVE-2024-36927/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36954 page", "url": "https://www.suse.com/security/cve/CVE-2024-36954/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36968 page", "url": "https://www.suse.com/security/cve/CVE-2024-36968/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-38589 page", "url": "https://www.suse.com/security/cve/CVE-2024-38589/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-40914 page", "url": "https://www.suse.com/security/cve/CVE-2024-40914/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-41023 page", "url": "https://www.suse.com/security/cve/CVE-2024-41023/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-42102 page", "url": "https://www.suse.com/security/cve/CVE-2024-42102/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-44995 page", "url": "https://www.suse.com/security/cve/CVE-2024-44995/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-46680 page", "url": "https://www.suse.com/security/cve/CVE-2024-46680/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-46681 page", "url": "https://www.suse.com/security/cve/CVE-2024-46681/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-46765 page", "url": "https://www.suse.com/security/cve/CVE-2024-46765/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-46788 page", "url": "https://www.suse.com/security/cve/CVE-2024-46788/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-46800 page", "url": "https://www.suse.com/security/cve/CVE-2024-46800/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-46828 page", "url": "https://www.suse.com/security/cve/CVE-2024-46828/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-46845 page", "url": "https://www.suse.com/security/cve/CVE-2024-46845/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-47666 page", "url": "https://www.suse.com/security/cve/CVE-2024-47666/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-47679 page", "url": "https://www.suse.com/security/cve/CVE-2024-47679/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-47701 page", "url": "https://www.suse.com/security/cve/CVE-2024-47701/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-47703 page", "url": "https://www.suse.com/security/cve/CVE-2024-47703/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49868 page", "url": "https://www.suse.com/security/cve/CVE-2024-49868/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49884 page", "url": "https://www.suse.com/security/cve/CVE-2024-49884/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49888 page", "url": "https://www.suse.com/security/cve/CVE-2024-49888/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49899 page", "url": "https://www.suse.com/security/cve/CVE-2024-49899/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49905 page", "url": "https://www.suse.com/security/cve/CVE-2024-49905/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49908 page", "url": "https://www.suse.com/security/cve/CVE-2024-49908/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49911 page", "url": "https://www.suse.com/security/cve/CVE-2024-49911/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49912 page", "url": "https://www.suse.com/security/cve/CVE-2024-49912/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49921 page", "url": "https://www.suse.com/security/cve/CVE-2024-49921/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49922 page", "url": "https://www.suse.com/security/cve/CVE-2024-49922/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49923 page", "url": "https://www.suse.com/security/cve/CVE-2024-49923/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49925 page", "url": "https://www.suse.com/security/cve/CVE-2024-49925/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49933 page", "url": "https://www.suse.com/security/cve/CVE-2024-49933/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49934 page", "url": "https://www.suse.com/security/cve/CVE-2024-49934/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49944 page", "url": "https://www.suse.com/security/cve/CVE-2024-49944/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49945 page", "url": "https://www.suse.com/security/cve/CVE-2024-49945/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49952 page", "url": "https://www.suse.com/security/cve/CVE-2024-49952/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49968 page", "url": "https://www.suse.com/security/cve/CVE-2024-49968/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49975 page", "url": "https://www.suse.com/security/cve/CVE-2024-49975/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49976 page", "url": "https://www.suse.com/security/cve/CVE-2024-49976/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49983 page", "url": "https://www.suse.com/security/cve/CVE-2024-49983/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49987 page", "url": "https://www.suse.com/security/cve/CVE-2024-49987/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49989 page", "url": "https://www.suse.com/security/cve/CVE-2024-49989/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50003 page", "url": "https://www.suse.com/security/cve/CVE-2024-50003/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50004 page", "url": "https://www.suse.com/security/cve/CVE-2024-50004/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50006 page", "url": "https://www.suse.com/security/cve/CVE-2024-50006/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50009 page", "url": "https://www.suse.com/security/cve/CVE-2024-50009/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50012 page", "url": "https://www.suse.com/security/cve/CVE-2024-50012/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50014 page", "url": "https://www.suse.com/security/cve/CVE-2024-50014/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50026 page", "url": "https://www.suse.com/security/cve/CVE-2024-50026/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50067 page", "url": "https://www.suse.com/security/cve/CVE-2024-50067/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50082 page", "url": "https://www.suse.com/security/cve/CVE-2024-50082/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50084 page", "url": "https://www.suse.com/security/cve/CVE-2024-50084/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50087 page", "url": "https://www.suse.com/security/cve/CVE-2024-50087/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50088 page", "url": "https://www.suse.com/security/cve/CVE-2024-50088/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50089 page", "url": "https://www.suse.com/security/cve/CVE-2024-50089/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50093 page", "url": "https://www.suse.com/security/cve/CVE-2024-50093/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50095 page", "url": "https://www.suse.com/security/cve/CVE-2024-50095/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50096 page", "url": "https://www.suse.com/security/cve/CVE-2024-50096/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50098 page", "url": "https://www.suse.com/security/cve/CVE-2024-50098/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50099 page", "url": "https://www.suse.com/security/cve/CVE-2024-50099/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50100 page", "url": "https://www.suse.com/security/cve/CVE-2024-50100/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50101 page", "url": "https://www.suse.com/security/cve/CVE-2024-50101/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50102 page", "url": "https://www.suse.com/security/cve/CVE-2024-50102/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50103 page", "url": "https://www.suse.com/security/cve/CVE-2024-50103/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50108 page", "url": "https://www.suse.com/security/cve/CVE-2024-50108/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50110 page", "url": "https://www.suse.com/security/cve/CVE-2024-50110/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50115 page", "url": "https://www.suse.com/security/cve/CVE-2024-50115/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50116 page", "url": "https://www.suse.com/security/cve/CVE-2024-50116/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50117 page", "url": "https://www.suse.com/security/cve/CVE-2024-50117/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50121 page", "url": "https://www.suse.com/security/cve/CVE-2024-50121/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50124 page", "url": "https://www.suse.com/security/cve/CVE-2024-50124/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50125 page", "url": "https://www.suse.com/security/cve/CVE-2024-50125/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50127 page", "url": "https://www.suse.com/security/cve/CVE-2024-50127/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50128 page", "url": "https://www.suse.com/security/cve/CVE-2024-50128/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50130 page", "url": "https://www.suse.com/security/cve/CVE-2024-50130/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50131 page", "url": "https://www.suse.com/security/cve/CVE-2024-50131/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50134 page", "url": "https://www.suse.com/security/cve/CVE-2024-50134/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50135 page", "url": "https://www.suse.com/security/cve/CVE-2024-50135/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50136 page", "url": "https://www.suse.com/security/cve/CVE-2024-50136/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50138 page", "url": "https://www.suse.com/security/cve/CVE-2024-50138/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50139 page", "url": "https://www.suse.com/security/cve/CVE-2024-50139/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50141 page", "url": "https://www.suse.com/security/cve/CVE-2024-50141/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50145 page", "url": "https://www.suse.com/security/cve/CVE-2024-50145/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50146 page", "url": "https://www.suse.com/security/cve/CVE-2024-50146/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50147 page", "url": "https://www.suse.com/security/cve/CVE-2024-50147/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50148 page", "url": "https://www.suse.com/security/cve/CVE-2024-50148/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50150 page", "url": "https://www.suse.com/security/cve/CVE-2024-50150/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50153 page", "url": "https://www.suse.com/security/cve/CVE-2024-50153/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50154 page", "url": "https://www.suse.com/security/cve/CVE-2024-50154/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50155 page", "url": "https://www.suse.com/security/cve/CVE-2024-50155/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50156 page", "url": "https://www.suse.com/security/cve/CVE-2024-50156/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50157 page", "url": "https://www.suse.com/security/cve/CVE-2024-50157/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50158 page", "url": "https://www.suse.com/security/cve/CVE-2024-50158/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50159 page", "url": "https://www.suse.com/security/cve/CVE-2024-50159/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50160 page", "url": "https://www.suse.com/security/cve/CVE-2024-50160/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50166 page", "url": "https://www.suse.com/security/cve/CVE-2024-50166/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50167 page", "url": "https://www.suse.com/security/cve/CVE-2024-50167/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50169 page", "url": "https://www.suse.com/security/cve/CVE-2024-50169/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50171 page", "url": "https://www.suse.com/security/cve/CVE-2024-50171/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50172 page", "url": "https://www.suse.com/security/cve/CVE-2024-50172/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50175 page", "url": "https://www.suse.com/security/cve/CVE-2024-50175/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50176 page", "url": "https://www.suse.com/security/cve/CVE-2024-50176/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50177 page", "url": "https://www.suse.com/security/cve/CVE-2024-50177/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50179 page", "url": "https://www.suse.com/security/cve/CVE-2024-50179/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50180 page", "url": "https://www.suse.com/security/cve/CVE-2024-50180/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50181 page", "url": "https://www.suse.com/security/cve/CVE-2024-50181/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50182 page", "url": "https://www.suse.com/security/cve/CVE-2024-50182/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50183 page", "url": "https://www.suse.com/security/cve/CVE-2024-50183/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50184 page", "url": "https://www.suse.com/security/cve/CVE-2024-50184/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50186 page", "url": "https://www.suse.com/security/cve/CVE-2024-50186/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50187 page", "url": "https://www.suse.com/security/cve/CVE-2024-50187/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50188 page", "url": "https://www.suse.com/security/cve/CVE-2024-50188/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50189 page", "url": "https://www.suse.com/security/cve/CVE-2024-50189/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50192 page", "url": "https://www.suse.com/security/cve/CVE-2024-50192/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50194 page", "url": "https://www.suse.com/security/cve/CVE-2024-50194/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50195 page", "url": "https://www.suse.com/security/cve/CVE-2024-50195/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50196 page", "url": "https://www.suse.com/security/cve/CVE-2024-50196/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50198 page", "url": "https://www.suse.com/security/cve/CVE-2024-50198/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50200 page", "url": "https://www.suse.com/security/cve/CVE-2024-50200/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50201 page", "url": "https://www.suse.com/security/cve/CVE-2024-50201/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50205 page", "url": "https://www.suse.com/security/cve/CVE-2024-50205/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50208 page", "url": "https://www.suse.com/security/cve/CVE-2024-50208/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50209 page", "url": "https://www.suse.com/security/cve/CVE-2024-50209/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50210 page", "url": "https://www.suse.com/security/cve/CVE-2024-50210/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50215 page", "url": "https://www.suse.com/security/cve/CVE-2024-50215/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50216 page", "url": "https://www.suse.com/security/cve/CVE-2024-50216/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50218 page", "url": "https://www.suse.com/security/cve/CVE-2024-50218/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50221 page", "url": "https://www.suse.com/security/cve/CVE-2024-50221/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50224 page", "url": "https://www.suse.com/security/cve/CVE-2024-50224/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50225 page", "url": "https://www.suse.com/security/cve/CVE-2024-50225/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50228 page", "url": "https://www.suse.com/security/cve/CVE-2024-50228/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50229 page", "url": "https://www.suse.com/security/cve/CVE-2024-50229/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50230 page", "url": "https://www.suse.com/security/cve/CVE-2024-50230/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50231 page", "url": "https://www.suse.com/security/cve/CVE-2024-50231/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50232 page", "url": "https://www.suse.com/security/cve/CVE-2024-50232/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50233 page", "url": "https://www.suse.com/security/cve/CVE-2024-50233/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50234 page", "url": "https://www.suse.com/security/cve/CVE-2024-50234/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50235 page", "url": "https://www.suse.com/security/cve/CVE-2024-50235/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50236 page", "url": "https://www.suse.com/security/cve/CVE-2024-50236/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50237 page", "url": "https://www.suse.com/security/cve/CVE-2024-50237/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50240 page", "url": "https://www.suse.com/security/cve/CVE-2024-50240/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50245 page", "url": "https://www.suse.com/security/cve/CVE-2024-50245/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50246 page", "url": "https://www.suse.com/security/cve/CVE-2024-50246/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50248 page", "url": "https://www.suse.com/security/cve/CVE-2024-50248/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50249 page", "url": "https://www.suse.com/security/cve/CVE-2024-50249/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50250 page", "url": "https://www.suse.com/security/cve/CVE-2024-50250/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50252 page", "url": "https://www.suse.com/security/cve/CVE-2024-50252/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50255 page", "url": "https://www.suse.com/security/cve/CVE-2024-50255/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50257 page", "url": "https://www.suse.com/security/cve/CVE-2024-50257/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50261 page", "url": "https://www.suse.com/security/cve/CVE-2024-50261/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50264 page", "url": "https://www.suse.com/security/cve/CVE-2024-50264/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50265 page", "url": "https://www.suse.com/security/cve/CVE-2024-50265/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50267 page", "url": "https://www.suse.com/security/cve/CVE-2024-50267/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50268 page", "url": "https://www.suse.com/security/cve/CVE-2024-50268/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50269 page", "url": "https://www.suse.com/security/cve/CVE-2024-50269/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50271 page", "url": "https://www.suse.com/security/cve/CVE-2024-50271/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50273 page", "url": "https://www.suse.com/security/cve/CVE-2024-50273/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50274 page", "url": "https://www.suse.com/security/cve/CVE-2024-50274/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50275 page", "url": "https://www.suse.com/security/cve/CVE-2024-50275/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50276 page", "url": "https://www.suse.com/security/cve/CVE-2024-50276/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50279 page", "url": "https://www.suse.com/security/cve/CVE-2024-50279/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50282 page", "url": "https://www.suse.com/security/cve/CVE-2024-50282/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50287 page", "url": "https://www.suse.com/security/cve/CVE-2024-50287/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50289 page", "url": "https://www.suse.com/security/cve/CVE-2024-50289/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50290 page", "url": "https://www.suse.com/security/cve/CVE-2024-50290/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50292 page", "url": "https://www.suse.com/security/cve/CVE-2024-50292/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50295 page", "url": "https://www.suse.com/security/cve/CVE-2024-50295/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50296 page", "url": "https://www.suse.com/security/cve/CVE-2024-50296/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50298 page", "url": "https://www.suse.com/security/cve/CVE-2024-50298/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50301 page", "url": "https://www.suse.com/security/cve/CVE-2024-50301/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50302 page", "url": "https://www.suse.com/security/cve/CVE-2024-50302/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53042 page", "url": "https://www.suse.com/security/cve/CVE-2024-53042/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53043 page", "url": "https://www.suse.com/security/cve/CVE-2024-53043/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53045 page", "url": "https://www.suse.com/security/cve/CVE-2024-53045/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53048 page", "url": "https://www.suse.com/security/cve/CVE-2024-53048/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53051 page", "url": "https://www.suse.com/security/cve/CVE-2024-53051/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53052 page", "url": "https://www.suse.com/security/cve/CVE-2024-53052/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53055 page", "url": "https://www.suse.com/security/cve/CVE-2024-53055/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53056 page", "url": "https://www.suse.com/security/cve/CVE-2024-53056/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53058 page", "url": "https://www.suse.com/security/cve/CVE-2024-53058/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53059 page", "url": "https://www.suse.com/security/cve/CVE-2024-53059/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53060 page", "url": "https://www.suse.com/security/cve/CVE-2024-53060/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53061 page", "url": "https://www.suse.com/security/cve/CVE-2024-53061/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53063 page", "url": "https://www.suse.com/security/cve/CVE-2024-53063/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53066 page", "url": "https://www.suse.com/security/cve/CVE-2024-53066/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53068 page", "url": "https://www.suse.com/security/cve/CVE-2024-53068/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53072 page", "url": "https://www.suse.com/security/cve/CVE-2024-53072/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53074 page", "url": "https://www.suse.com/security/cve/CVE-2024-53074/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53076 page", "url": "https://www.suse.com/security/cve/CVE-2024-53076/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53079 page", "url": "https://www.suse.com/security/cve/CVE-2024-53079/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53081 page", "url": "https://www.suse.com/security/cve/CVE-2024-53081/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53082 page", "url": "https://www.suse.com/security/cve/CVE-2024-53082/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53085 page", "url": "https://www.suse.com/security/cve/CVE-2024-53085/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53088 page", "url": "https://www.suse.com/security/cve/CVE-2024-53088/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53093 page", "url": "https://www.suse.com/security/cve/CVE-2024-53093/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53094 page", "url": "https://www.suse.com/security/cve/CVE-2024-53094/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53095 page", "url": "https://www.suse.com/security/cve/CVE-2024-53095/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53096 page", "url": "https://www.suse.com/security/cve/CVE-2024-53096/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53100 page", "url": "https://www.suse.com/security/cve/CVE-2024-53100/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53101 page", "url": "https://www.suse.com/security/cve/CVE-2024-53101/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53104 page", "url": "https://www.suse.com/security/cve/CVE-2024-53104/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53106 page", "url": "https://www.suse.com/security/cve/CVE-2024-53106/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53108 page", "url": "https://www.suse.com/security/cve/CVE-2024-53108/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53110 page", "url": "https://www.suse.com/security/cve/CVE-2024-53110/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53112 page", "url": "https://www.suse.com/security/cve/CVE-2024-53112/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53114 page", "url": "https://www.suse.com/security/cve/CVE-2024-53114/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53121 page", "url": "https://www.suse.com/security/cve/CVE-2024-53121/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53138 page", "url": "https://www.suse.com/security/cve/CVE-2024-53138/" } ], "title": "Security update for the Linux Kernel", "tracking": { "current_release_date": "2024-12-13T15:24:02Z", "generator": { "date": "2024-12-13T15:24:02Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2024:4316-1", "initial_release_date": "2024-12-13T15:24:02Z", "revision_history": [ { "date": "2024-12-13T15:24:02Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product": { "name": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product_id": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product": { "name": "dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product_id": "dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product": { "name": "gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product_id": "gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "kernel-azure-6.4.0-150600.8.20.1.aarch64", "product": { "name": "kernel-azure-6.4.0-150600.8.20.1.aarch64", "product_id": "kernel-azure-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "product": { "name": "kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "product_id": "kernel-azure-devel-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "product": { "name": "kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "product_id": "kernel-azure-extra-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "product": { "name": "kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "product_id": "kernel-azure-optional-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "product": { "name": "kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "product_id": "kernel-syms-azure-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product": { "name": "kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product_id": "kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product": { "name": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product_id": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64" } }, { "category": "product_version", "name": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product": { "name": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "product_id": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "product": { "name": "kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "product_id": "kernel-devel-azure-6.4.0-150600.8.20.1.noarch" } }, { "category": "product_version", "name": "kernel-source-azure-6.4.0-150600.8.20.1.noarch", "product": { "name": "kernel-source-azure-6.4.0-150600.8.20.1.noarch", "product_id": "kernel-source-azure-6.4.0-150600.8.20.1.noarch" } } ], "category": "architecture", "name": "noarch" }, { "branches": [ { "category": "product_version", "name": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product": { "name": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product_id": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product": { "name": "dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product_id": "dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product": { "name": "gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product_id": "gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-6.4.0-150600.8.20.1.x86_64", "product": { "name": "kernel-azure-6.4.0-150600.8.20.1.x86_64", "product_id": "kernel-azure-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "product": { "name": "kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "product_id": "kernel-azure-devel-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "product": { "name": "kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "product_id": "kernel-azure-extra-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "product": { "name": "kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "product_id": "kernel-azure-optional-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "product": { "name": "kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "product_id": "kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "product": { "name": "kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "product_id": "kernel-syms-azure-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product": { "name": "kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product_id": "kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product": { "name": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product_id": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64" } }, { "category": "product_version", "name": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product": { "name": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64", "product_id": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product": { "name": "SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_identification_helper": { "cpe": "cpe:/o:suse:sle-module-public-cloud:15:sp6" } } }, { "category": "product_name", "name": "openSUSE Leap 15.6", "product": { "name": "openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6", "product_identification_helper": { "cpe": "cpe:/o:opensuse:leap:15.6" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-6.4.0-150600.8.20.1.aarch64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "kernel-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-6.4.0-150600.8.20.1.x86_64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kernel-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-devel-6.4.0-150600.8.20.1.aarch64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-devel-6.4.0-150600.8.20.1.x86_64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-devel-azure-6.4.0-150600.8.20.1.noarch as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch" }, "product_reference": "kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-source-azure-6.4.0-150600.8.20.1.noarch as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch" }, "product_reference": "kernel-source-azure-6.4.0-150600.8.20.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-syms-azure-6.4.0-150600.8.20.1.aarch64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-syms-azure-6.4.0-150600.8.20.1.x86_64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "kernel-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kernel-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-devel-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-devel-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-extra-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-extra-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-optional-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-optional-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-devel-azure-6.4.0-150600.8.20.1.noarch as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch" }, "product_reference": "kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-source-azure-6.4.0-150600.8.20.1.noarch as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch" }, "product_reference": "kernel-source-azure-6.4.0-150600.8.20.1.noarch", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-syms-azure-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-syms-azure-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64" }, "product_reference": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" }, "product_reference": "reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" } ] }, "vulnerabilities": [ { "cve": "CVE-2023-52778", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2023-52778" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: deal with large GSO size\n\nAfter the blamed commit below, the TCP sockets (and the MPTCP subflows)\ncan build egress packets larger than 64K. That exceeds the maximum DSS\ndata size, the length being misrepresent on the wire and the stream being\ncorrupted, as later observed on the receiver:\n\n WARNING: CPU: 0 PID: 9696 at net/mptcp/protocol.c:705 __mptcp_move_skbs_from_subflow+0x2604/0x26e0\n CPU: 0 PID: 9696 Comm: syz-executor.7 Not tainted 6.6.0-rc5-gcd8bdf563d46 #45\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014\n netlink: 8 bytes leftover after parsing attributes in process `syz-executor.4\u0027.\n RIP: 0010:__mptcp_move_skbs_from_subflow+0x2604/0x26e0 net/mptcp/protocol.c:705\n RSP: 0018:ffffc90000006e80 EFLAGS: 00010246\n RAX: ffffffff83e9f674 RBX: ffff88802f45d870 RCX: ffff888102ad0000\n netlink: 8 bytes leftover after parsing attributes in process `syz-executor.4\u0027.\n RDX: 0000000080000303 RSI: 0000000000013908 RDI: 0000000000003908\n RBP: ffffc90000007110 R08: ffffffff83e9e078 R09: 1ffff1100e548c8a\n R10: dffffc0000000000 R11: ffffed100e548c8b R12: 0000000000013908\n R13: dffffc0000000000 R14: 0000000000003908 R15: 000000000031cf29\n FS: 00007f239c47e700(0000) GS:ffff88811b200000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f239c45cd78 CR3: 000000006a66c006 CR4: 0000000000770ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000600\n PKRU: 55555554\n Call Trace:\n \u003cIRQ\u003e\n mptcp_data_ready+0x263/0xac0 net/mptcp/protocol.c:819\n subflow_data_ready+0x268/0x6d0 net/mptcp/subflow.c:1409\n tcp_data_queue+0x21a1/0x7a60 net/ipv4/tcp_input.c:5151\n tcp_rcv_established+0x950/0x1d90 net/ipv4/tcp_input.c:6098\n tcp_v6_do_rcv+0x554/0x12f0 net/ipv6/tcp_ipv6.c:1483\n tcp_v6_rcv+0x2e26/0x3810 net/ipv6/tcp_ipv6.c:1749\n ip6_protocol_deliver_rcu+0xd6b/0x1ae0 net/ipv6/ip6_input.c:438\n ip6_input+0x1c5/0x470 net/ipv6/ip6_input.c:483\n ipv6_rcv+0xef/0x2c0 include/linux/netfilter.h:304\n __netif_receive_skb+0x1ea/0x6a0 net/core/dev.c:5532\n process_backlog+0x353/0x660 net/core/dev.c:5974\n __napi_poll+0xc6/0x5a0 net/core/dev.c:6536\n net_rx_action+0x6a0/0xfd0 net/core/dev.c:6603\n __do_softirq+0x184/0x524 kernel/softirq.c:553\n do_softirq+0xdd/0x130 kernel/softirq.c:454\n\nAddress the issue explicitly bounding the maximum GSO size to what MPTCP\nactually allows.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2023-52778", "url": "https://www.suse.com/security/cve/CVE-2023-52778" }, { "category": "external", "summary": "SUSE Bug 1224948 for CVE-2023-52778", "url": "https://bugzilla.suse.com/1224948" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2023-52778" }, { "cve": "CVE-2023-52920", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2023-52920" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: support non-r10 register spill/fill to/from stack in precision tracking\n\nUse instruction (jump) history to record instructions that performed\nregister spill/fill to/from stack, regardless if this was done through\nread-only r10 register, or any other register after copying r10 into it\n*and* potentially adjusting offset.\n\nTo make this work reliably, we push extra per-instruction flags into\ninstruction history, encoding stack slot index (spi) and stack frame\nnumber in extra 10 bit flags we take away from prev_idx in instruction\nhistory. We don\u0027t touch idx field for maximum performance, as it\u0027s\nchecked most frequently during backtracking.\n\nThis change removes basically the last remaining practical limitation of\nprecision backtracking logic in BPF verifier. It fixes known\ndeficiencies, but also opens up new opportunities to reduce number of\nverified states, explored in the subsequent patches.\n\nThere are only three differences in selftests\u0027 BPF object files\naccording to veristat, all in the positive direction (less states).\n\nFile Program Insns (A) Insns (B) Insns (DIFF) States (A) States (B) States (DIFF)\n-------------------------------------- ------------- --------- --------- ------------- ---------- ---------- -------------\ntest_cls_redirect_dynptr.bpf.linked3.o cls_redirect 2987 2864 -123 (-4.12%) 240 231 -9 (-3.75%)\nxdp_synproxy_kern.bpf.linked3.o syncookie_tc 82848 82661 -187 (-0.23%) 5107 5073 -34 (-0.67%)\nxdp_synproxy_kern.bpf.linked3.o syncookie_xdp 85116 84964 -152 (-0.18%) 5162 5130 -32 (-0.62%)\n\nNote, I avoided renaming jmp_history to more generic insn_hist to\nminimize number of lines changed and potential merge conflicts between\nbpf and bpf-next trees.\n\nNotice also cur_hist_entry pointer reset to NULL at the beginning of\ninstruction verification loop. This pointer avoids the problem of\nrelying on last jump history entry\u0027s insn_idx to determine whether we\nalready have entry for current instruction or not. It can happen that we\nadded jump history entry because current instruction is_jmp_point(), but\nalso we need to add instruction flags for stack access. In this case, we\ndon\u0027t want to entries, so we need to reuse last added entry, if it is\npresent.\n\nRelying on insn_idx comparison has the same ambiguity problem as the one\nthat was fixed recently in [0], so we avoid that.\n\n [0] https://patchwork.kernel.org/project/netdevbpf/patch/20231110002638.4168352-3-andrii@kernel.org/", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2023-52920", "url": "https://www.suse.com/security/cve/CVE-2023-52920" }, { "category": "external", "summary": "SUSE Bug 1232823 for CVE-2023-52920", "url": "https://bugzilla.suse.com/1232823" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2023-52920" }, { "cve": "CVE-2023-52921", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2023-52921" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix possible UAF in amdgpu_cs_pass1()\n\nSince the gang_size check is outside of chunk parsing\nloop, we need to reset i before we free the chunk data.\n\nSuggested by Ye Zhang (@VAR10CK) of Baidu Security.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2023-52921", "url": "https://www.suse.com/security/cve/CVE-2023-52921" }, { "category": "external", "summary": "SUSE Bug 1233452 for CVE-2023-52921", "url": "https://bugzilla.suse.com/1233452" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2023-52921" }, { "cve": "CVE-2023-52922", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2023-52922" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: Fix UAF in bcm_proc_show()\n\nBUG: KASAN: slab-use-after-free in bcm_proc_show+0x969/0xa80\nRead of size 8 at addr ffff888155846230 by task cat/7862\n\nCPU: 1 PID: 7862 Comm: cat Not tainted 6.5.0-rc1-00153-gc8746099c197 #230\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0xd5/0x150\n print_report+0xc1/0x5e0\n kasan_report+0xba/0xf0\n bcm_proc_show+0x969/0xa80\n seq_read_iter+0x4f6/0x1260\n seq_read+0x165/0x210\n proc_reg_read+0x227/0x300\n vfs_read+0x1d5/0x8d0\n ksys_read+0x11e/0x240\n do_syscall_64+0x35/0xb0\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nAllocated by task 7846:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n __kasan_kmalloc+0x9e/0xa0\n bcm_sendmsg+0x264b/0x44e0\n sock_sendmsg+0xda/0x180\n ____sys_sendmsg+0x735/0x920\n ___sys_sendmsg+0x11d/0x1b0\n __sys_sendmsg+0xfa/0x1d0\n do_syscall_64+0x35/0xb0\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nFreed by task 7846:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_save_free_info+0x27/0x40\n ____kasan_slab_free+0x161/0x1c0\n slab_free_freelist_hook+0x119/0x220\n __kmem_cache_free+0xb4/0x2e0\n rcu_core+0x809/0x1bd0\n\nbcm_op is freed before procfs entry be removed in bcm_release(),\nthis lead to bcm_proc_show() may read the freed bcm_op.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2023-52922", "url": "https://www.suse.com/security/cve/CVE-2023-52922" }, { "category": "external", "summary": "SUSE Bug 1233977 for CVE-2023-52922", "url": "https://bugzilla.suse.com/1233977" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2023-52922" }, { "cve": "CVE-2024-26596", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-26596" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: fix netdev_priv() dereference before check on non-DSA netdevice events\n\nAfter the blamed commit, we started doing this dereference for every\nNETDEV_CHANGEUPPER and NETDEV_PRECHANGEUPPER event in the system.\n\nstatic inline struct dsa_port *dsa_user_to_port(const struct net_device *dev)\n{\n\tstruct dsa_user_priv *p = netdev_priv(dev);\n\n\treturn p-\u003edp;\n}\n\nWhich is obviously bogus, because not all net_devices have a netdev_priv()\nof type struct dsa_user_priv. But struct dsa_user_priv is fairly small,\nand p-\u003edp means dereferencing 8 bytes starting with offset 16. Most\ndrivers allocate that much private memory anyway, making our access not\nfault, and we discard the bogus data quickly afterwards, so this wasn\u0027t\ncaught.\n\nBut the dummy interface is somewhat special in that it calls\nalloc_netdev() with a priv size of 0. So every netdev_priv() dereference\nis invalid, and we get this when we emit a NETDEV_PRECHANGEUPPER event\nwith a VLAN as its new upper:\n\n$ ip link add dummy1 type dummy\n$ ip link add link dummy1 name dummy1.100 type vlan id 100\n[ 43.309174] ==================================================================\n[ 43.316456] BUG: KASAN: slab-out-of-bounds in dsa_user_prechangeupper+0x30/0xe8\n[ 43.323835] Read of size 8 at addr ffff3f86481d2990 by task ip/374\n[ 43.330058]\n[ 43.342436] Call trace:\n[ 43.366542] dsa_user_prechangeupper+0x30/0xe8\n[ 43.371024] dsa_user_netdevice_event+0xb38/0xee8\n[ 43.375768] notifier_call_chain+0xa4/0x210\n[ 43.379985] raw_notifier_call_chain+0x24/0x38\n[ 43.384464] __netdev_upper_dev_link+0x3ec/0x5d8\n[ 43.389120] netdev_upper_dev_link+0x70/0xa8\n[ 43.393424] register_vlan_dev+0x1bc/0x310\n[ 43.397554] vlan_newlink+0x210/0x248\n[ 43.401247] rtnl_newlink+0x9fc/0xe30\n[ 43.404942] rtnetlink_rcv_msg+0x378/0x580\n\nAvoid the kernel oops by dereferencing after the type check, as customary.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-26596", "url": "https://www.suse.com/security/cve/CVE-2024-26596" }, { "category": "external", "summary": "SUSE Bug 1220355 for CVE-2024-26596", "url": "https://bugzilla.suse.com/1220355" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-26596" }, { "cve": "CVE-2024-26703", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-26703" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Move hrtimer_init to timerlat_fd open()\n\nCurrently, the timerlat\u0027s hrtimer is initialized at the first read of\ntimerlat_fd, and destroyed at close(). It works, but it causes an error\nif the user program open() and close() the file without reading.\n\nHere\u0027s an example:\n\n # echo NO_OSNOISE_WORKLOAD \u003e /sys/kernel/debug/tracing/osnoise/options\n # echo timerlat \u003e /sys/kernel/debug/tracing/current_tracer\n\n # cat \u003c\u003cEOF \u003e ./timerlat_load.py\n # !/usr/bin/env python3\n\n timerlat_fd = open(\"/sys/kernel/tracing/osnoise/per_cpu/cpu0/timerlat_fd\", \u0027r\u0027)\n timerlat_fd.close();\n EOF\n\n # ./taskset -c 0 ./timerlat_load.py\n\u003cBOOM\u003e\n\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 1 PID: 2673 Comm: python3 Not tainted 6.6.13-200.fc39.x86_64 #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-1.fc39 04/01/2014\n RIP: 0010:hrtimer_active+0xd/0x50\n Code: 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 48 8b 57 30 \u003c8b\u003e 42 10 a8 01 74 09 f3 90 8b 42 10 a8 01 75 f7 80 7f 38 00 75 1d\n RSP: 0018:ffffb031009b7e10 EFLAGS: 00010286\n RAX: 000000000002db00 RBX: ffff9118f786db08 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: ffff9117a0e64400 RDI: ffff9118f786db08\n RBP: ffff9118f786db80 R08: ffff9117a0ddd420 R09: ffff9117804d4f70\n R10: 0000000000000000 R11: 0000000000000000 R12: ffff9118f786db08\n R13: ffff91178fdd5e20 R14: ffff9117840978c0 R15: 0000000000000000\n FS: 00007f2ffbab1740(0000) GS:ffff9118f7840000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000010 CR3: 00000001b402e000 CR4: 0000000000750ee0\n PKRU: 55555554\n Call Trace:\n \u003cTASK\u003e\n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? srso_alias_return_thunk+0x5/0x7f\n ? avc_has_extended_perms+0x237/0x520\n ? exc_page_fault+0x7f/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? hrtimer_active+0xd/0x50\n hrtimer_cancel+0x15/0x40\n timerlat_fd_release+0x48/0xe0\n __fput+0xf5/0x290\n __x64_sys_close+0x3d/0x80\n do_syscall_64+0x60/0x90\n ? srso_alias_return_thunk+0x5/0x7f\n ? __x64_sys_ioctl+0x72/0xd0\n ? srso_alias_return_thunk+0x5/0x7f\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_syscall_64+0x6c/0x90\n ? srso_alias_return_thunk+0x5/0x7f\n ? exit_to_user_mode_prepare+0x142/0x1f0\n ? srso_alias_return_thunk+0x5/0x7f\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_syscall_64+0x6c/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n RIP: 0033:0x7f2ffb321594\n Code: 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 80 3d d5 cd 0d 00 00 74 13 b8 03 00 00 00 0f 05 \u003c48\u003e 3d 00 f0 ff ff 77 3c c3 0f 1f 00 55 48 89 e5 48 83 ec 10 89 7d\n RSP: 002b:00007ffe8d8eef18 EFLAGS: 00000202 ORIG_RAX: 0000000000000003\n RAX: ffffffffffffffda RBX: 00007f2ffba4e668 RCX: 00007f2ffb321594\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\n RBP: 00007ffe8d8eef40 R08: 0000000000000000 R09: 0000000000000000\n R10: 55c926e3167eae79 R11: 0000000000000202 R12: 0000000000000003\n R13: 00007ffe8d8ef030 R14: 0000000000000000 R15: 00007f2ffba4e668\n \u003c/TASK\u003e\n CR2: 0000000000000010\n ---[ end trace 0000000000000000 ]---\n\nMove hrtimer_init to timerlat_fd open() to avoid this problem.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-26703", "url": "https://www.suse.com/security/cve/CVE-2024-26703" }, { "category": "external", "summary": "SUSE Bug 1222423 for CVE-2024-26703", "url": "https://bugzilla.suse.com/1222423" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-26703" }, { "cve": "CVE-2024-26741", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-26741" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished().\n\nsyzkaller reported a warning [0] in inet_csk_destroy_sock() with no\nrepro.\n\n WARN_ON(inet_sk(sk)-\u003einet_num \u0026\u0026 !inet_csk(sk)-\u003eicsk_bind_hash);\n\nHowever, the syzkaller\u0027s log hinted that connect() failed just before\nthe warning due to FAULT_INJECTION. [1]\n\nWhen connect() is called for an unbound socket, we search for an\navailable ephemeral port. If a bhash bucket exists for the port, we\ncall __inet_check_established() or __inet6_check_established() to check\nif the bucket is reusable.\n\nIf reusable, we add the socket into ehash and set inet_sk(sk)-\u003einet_num.\n\nLater, we look up the corresponding bhash2 bucket and try to allocate\nit if it does not exist.\n\nAlthough it rarely occurs in real use, if the allocation fails, we must\nrevert the changes by check_established(). Otherwise, an unconnected\nsocket could illegally occupy an ehash entry.\n\nNote that we do not put tw back into ehash because sk might have\nalready responded to a packet for tw and it would be better to free\ntw earlier under such memory presure.\n\n[0]:\nWARNING: CPU: 0 PID: 350830 at net/ipv4/inet_connection_sock.c:1193 inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)\nModules linked in:\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nRIP: 0010:inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)\nCode: 41 5c 41 5d 41 5e e9 2d 4a 3d fd e8 28 4a 3d fd 48 89 ef e8 f0 cd 7d ff 5b 5d 41 5c 41 5d 41 5e e9 13 4a 3d fd e8 0e 4a 3d fd \u003c0f\u003e 0b e9 61 fe ff ff e8 02 4a 3d fd 4c 89 e7 be 03 00 00 00 e8 05\nRSP: 0018:ffffc9000b21fd38 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: 0000000000009e78 RCX: ffffffff840bae40\nRDX: ffff88806e46c600 RSI: ffffffff840bb012 RDI: ffff88811755cca8\nRBP: ffff88811755c880 R08: 0000000000000003 R09: 0000000000000000\nR10: 0000000000009e78 R11: 0000000000000000 R12: ffff88811755c8e0\nR13: ffff88811755c892 R14: ffff88811755c918 R15: 0000000000000000\nFS: 00007f03e5243800(0000) GS:ffff88811ae00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000001b32f21000 CR3: 0000000112ffe001 CR4: 0000000000770ef0\nPKRU: 55555554\nCall Trace:\n \u003cTASK\u003e\n ? inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)\n dccp_close (net/dccp/proto.c:1078)\n inet_release (net/ipv4/af_inet.c:434)\n __sock_release (net/socket.c:660)\n sock_close (net/socket.c:1423)\n __fput (fs/file_table.c:377)\n __fput_sync (fs/file_table.c:462)\n __x64_sys_close (fs/open.c:1557 fs/open.c:1539 fs/open.c:1539)\n do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129)\nRIP: 0033:0x7f03e53852bb\nCode: 03 00 00 00 0f 05 48 3d 00 f0 ff ff 77 41 c3 48 83 ec 18 89 7c 24 0c e8 43 c9 f5 ff 8b 7c 24 0c 41 89 c0 b8 03 00 00 00 0f 05 \u003c48\u003e 3d 00 f0 ff ff 77 35 44 89 c7 89 44 24 0c e8 a1 c9 f5 ff 8b 44\nRSP: 002b:00000000005dfba0 EFLAGS: 00000293 ORIG_RAX: 0000000000000003\nRAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007f03e53852bb\nRDX: 0000000000000002 RSI: 0000000000000002 RDI: 0000000000000003\nRBP: 0000000000000000 R08: 0000000000000000 R09: 000000000000167c\nR10: 0000000008a79680 R11: 0000000000000293 R12: 00007f03e4e43000\nR13: 00007f03e4e43170 R14: 00007f03e4e43178 R15: 00007f03e4e43170\n \u003c/TASK\u003e\n\n[1]:\nFAULT_INJECTION: forcing a failure.\nname failslab, interval 1, probability 0, space 0, times 0\nCPU: 0 PID: 350833 Comm: syz-executor.1 Not tainted 6.7.0-12272-g2121c43f88f5 #9\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl (lib/dump_stack.c:107 (discriminator 1))\n should_fail_ex (lib/fault-inject.c:52 lib/fault-inject.c:153)\n should_failslab (mm/slub.c:3748)\n kmem_cache_alloc (mm/slub.c:3763 mm/slub.c:3842 mm/slub.c:3867)\n inet_bind2_bucket_create \n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-26741", "url": "https://www.suse.com/security/cve/CVE-2024-26741" }, { "category": "external", "summary": "SUSE Bug 1222587 for CVE-2024-26741", "url": "https://bugzilla.suse.com/1222587" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-26741" }, { "cve": "CVE-2024-26782", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-26782" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix double-free on socket dismantle\n\nwhen MPTCP server accepts an incoming connection, it clones its listener\nsocket. However, the pointer to \u0027inet_opt\u0027 for the new socket has the same\nvalue as the original one: as a consequence, on program exit it\u0027s possible\nto observe the following splat:\n\n BUG: KASAN: double-free in inet_sock_destruct+0x54f/0x8b0\n Free of addr ffff888485950880 by task swapper/25/0\n\n CPU: 25 PID: 0 Comm: swapper/25 Kdump: loaded Not tainted 6.8.0-rc1+ #609\n Hardware name: Supermicro SYS-6027R-72RF/X9DRH-7TF/7F/iTF/iF, BIOS 3.0 07/26/2013\n Call Trace:\n \u003cIRQ\u003e\n dump_stack_lvl+0x32/0x50\n print_report+0xca/0x620\n kasan_report_invalid_free+0x64/0x90\n __kasan_slab_free+0x1aa/0x1f0\n kfree+0xed/0x2e0\n inet_sock_destruct+0x54f/0x8b0\n __sk_destruct+0x48/0x5b0\n rcu_do_batch+0x34e/0xd90\n rcu_core+0x559/0xac0\n __do_softirq+0x183/0x5a4\n irq_exit_rcu+0x12d/0x170\n sysvec_apic_timer_interrupt+0x6b/0x80\n \u003c/IRQ\u003e\n \u003cTASK\u003e\n asm_sysvec_apic_timer_interrupt+0x16/0x20\n RIP: 0010:cpuidle_enter_state+0x175/0x300\n Code: 30 00 0f 84 1f 01 00 00 83 e8 01 83 f8 ff 75 e5 48 83 c4 18 44 89 e8 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc fb 45 85 ed \u003c0f\u003e 89 60 ff ff ff 48 c1 e5 06 48 c7 43 18 00 00 00 00 48 83 44 2b\n RSP: 0018:ffff888481cf7d90 EFLAGS: 00000202\n RAX: 0000000000000000 RBX: ffff88887facddc8 RCX: 0000000000000000\n RDX: 1ffff1110ff588b1 RSI: 0000000000000019 RDI: ffff88887fac4588\n RBP: 0000000000000004 R08: 0000000000000002 R09: 0000000000043080\n R10: 0009b02ea273363f R11: ffff88887fabf42b R12: ffffffff932592e0\n R13: 0000000000000004 R14: 0000000000000000 R15: 00000022c880ec80\n cpuidle_enter+0x4a/0xa0\n do_idle+0x310/0x410\n cpu_startup_entry+0x51/0x60\n start_secondary+0x211/0x270\n secondary_startup_64_no_verify+0x184/0x18b\n \u003c/TASK\u003e\n\n Allocated by task 6853:\n kasan_save_stack+0x1c/0x40\n kasan_save_track+0x10/0x30\n __kasan_kmalloc+0xa6/0xb0\n __kmalloc+0x1eb/0x450\n cipso_v4_sock_setattr+0x96/0x360\n netlbl_sock_setattr+0x132/0x1f0\n selinux_netlbl_socket_post_create+0x6c/0x110\n selinux_socket_post_create+0x37b/0x7f0\n security_socket_post_create+0x63/0xb0\n __sock_create+0x305/0x450\n __sys_socket_create.part.23+0xbd/0x130\n __sys_socket+0x37/0xb0\n __x64_sys_socket+0x6f/0xb0\n do_syscall_64+0x83/0x160\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\n Freed by task 6858:\n kasan_save_stack+0x1c/0x40\n kasan_save_track+0x10/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x12c/0x1f0\n kfree+0xed/0x2e0\n inet_sock_destruct+0x54f/0x8b0\n __sk_destruct+0x48/0x5b0\n subflow_ulp_release+0x1f0/0x250\n tcp_cleanup_ulp+0x6e/0x110\n tcp_v4_destroy_sock+0x5a/0x3a0\n inet_csk_destroy_sock+0x135/0x390\n tcp_fin+0x416/0x5c0\n tcp_data_queue+0x1bc8/0x4310\n tcp_rcv_state_process+0x15a3/0x47b0\n tcp_v4_do_rcv+0x2c1/0x990\n tcp_v4_rcv+0x41fb/0x5ed0\n ip_protocol_deliver_rcu+0x6d/0x9f0\n ip_local_deliver_finish+0x278/0x360\n ip_local_deliver+0x182/0x2c0\n ip_rcv+0xb5/0x1c0\n __netif_receive_skb_one_core+0x16e/0x1b0\n process_backlog+0x1e3/0x650\n __napi_poll+0xa6/0x500\n net_rx_action+0x740/0xbb0\n __do_softirq+0x183/0x5a4\n\n The buggy address belongs to the object at ffff888485950880\n which belongs to the cache kmalloc-64 of size 64\n The buggy address is located 0 bytes inside of\n 64-byte region [ffff888485950880, ffff8884859508c0)\n\n The buggy address belongs to the physical page:\n page:0000000056d1e95e refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888485950700 pfn:0x485950\n flags: 0x57ffffc0000800(slab|node=1|zone=2|lastcpupid=0x1fffff)\n page_type: 0xffffffff()\n raw: 0057ffffc0000800 ffff88810004c640 ffffea00121b8ac0 dead000000000006\n raw: ffff888485950700 0000000000200019 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff888485950780: fa fb fb\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-26782", "url": "https://www.suse.com/security/cve/CVE-2024-26782" }, { "category": "external", "summary": "SUSE Bug 1222590 for CVE-2024-26782", "url": "https://bugzilla.suse.com/1222590" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-26782" }, { "cve": "CVE-2024-26864", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-26864" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Fix refcnt handling in __inet_hash_connect().\n\nsyzbot reported a warning in sk_nulls_del_node_init_rcu().\n\nThe commit 66b60b0c8c4a (\"dccp/tcp: Unhash sk from ehash for tb2 alloc\nfailure after check_estalblished().\") tried to fix an issue that an\nunconnected socket occupies an ehash entry when bhash2 allocation fails.\n\nIn such a case, we need to revert changes done by check_established(),\nwhich does not hold refcnt when inserting socket into ehash.\n\nSo, to revert the change, we need to __sk_nulls_add_node_rcu() instead\nof sk_nulls_add_node_rcu().\n\nOtherwise, sock_put() will cause refcnt underflow and leak the socket.\n\n[0]:\nWARNING: CPU: 0 PID: 23948 at include/net/sock.h:799 sk_nulls_del_node_init_rcu+0x166/0x1a0 include/net/sock.h:799\nModules linked in:\nCPU: 0 PID: 23948 Comm: syz-executor.2 Not tainted 6.8.0-rc6-syzkaller-00159-gc055fc00c07b #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nRIP: 0010:sk_nulls_del_node_init_rcu+0x166/0x1a0 include/net/sock.h:799\nCode: e8 7f 71 c6 f7 83 fb 02 7c 25 e8 35 6d c6 f7 4d 85 f6 0f 95 c0 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc e8 1b 6d c6 f7 90 \u003c0f\u003e 0b 90 eb b2 e8 10 6d c6 f7 4c 89 e7 be 04 00 00 00 e8 63 e7 d2\nRSP: 0018:ffffc900032d7848 EFLAGS: 00010246\nRAX: ffffffff89cd0035 RBX: 0000000000000001 RCX: 0000000000040000\nRDX: ffffc90004de1000 RSI: 000000000003ffff RDI: 0000000000040000\nRBP: 1ffff1100439ac26 R08: ffffffff89ccffe3 R09: 1ffff1100439ac28\nR10: dffffc0000000000 R11: ffffed100439ac29 R12: ffff888021cd6140\nR13: dffffc0000000000 R14: ffff88802a9bf5c0 R15: ffff888021cd6130\nFS: 00007f3b823f16c0(0000) GS:ffff8880b9400000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f3b823f0ff8 CR3: 000000004674a000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \u003cTASK\u003e\n __inet_hash_connect+0x140f/0x20b0 net/ipv4/inet_hashtables.c:1139\n dccp_v6_connect+0xcb9/0x1480 net/dccp/ipv6.c:956\n __inet_stream_connect+0x262/0xf30 net/ipv4/af_inet.c:678\n inet_stream_connect+0x65/0xa0 net/ipv4/af_inet.c:749\n __sys_connect_file net/socket.c:2048 [inline]\n __sys_connect+0x2df/0x310 net/socket.c:2065\n __do_sys_connect net/socket.c:2075 [inline]\n __se_sys_connect net/socket.c:2072 [inline]\n __x64_sys_connect+0x7a/0x90 net/socket.c:2072\n do_syscall_64+0xf9/0x240\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\nRIP: 0033:0x7f3b8167dda9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 e1 20 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f3b823f10c8 EFLAGS: 00000246 ORIG_RAX: 000000000000002a\nRAX: ffffffffffffffda RBX: 00007f3b817abf80 RCX: 00007f3b8167dda9\nRDX: 000000000000001c RSI: 0000000020000040 RDI: 0000000000000003\nRBP: 00007f3b823f1120 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001\nR13: 000000000000000b R14: 00007f3b817abf80 R15: 00007ffd3beb57b8\n \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-26864", "url": "https://www.suse.com/security/cve/CVE-2024-26864" }, { "category": "external", "summary": "SUSE Bug 1223112 for CVE-2024-26864", "url": "https://bugzilla.suse.com/1223112" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-26864" }, { "cve": "CVE-2024-26953", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-26953" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: esp: fix bad handling of pages from page_pool\n\nWhen the skb is reorganized during esp_output (!esp-\u003einline), the pages\ncoming from the original skb fragments are supposed to be released back\nto the system through put_page. But if the skb fragment pages are\noriginating from a page_pool, calling put_page on them will trigger a\npage_pool leak which will eventually result in a crash.\n\nThis leak can be easily observed when using CONFIG_DEBUG_VM and doing\nipsec + gre (non offloaded) forwarding:\n\n BUG: Bad page state in process ksoftirqd/16 pfn:1451b6\n page:00000000de2b8d32 refcount:0 mapcount:0 mapping:0000000000000000 index:0x1451b6000 pfn:0x1451b6\n flags: 0x200000000000000(node=0|zone=2)\n page_type: 0xffffffff()\n raw: 0200000000000000 dead000000000040 ffff88810d23c000 0000000000000000\n raw: 00000001451b6000 0000000000000001 00000000ffffffff 0000000000000000\n page dumped because: page_pool leak\n Modules linked in: ip_gre gre mlx5_ib mlx5_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink iptable_nat nf_nat xt_addrtype br_netfilter rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm ib_uverbs ib_core overlay zram zsmalloc fuse [last unloaded: mlx5_core]\n CPU: 16 PID: 96 Comm: ksoftirqd/16 Not tainted 6.8.0-rc4+ #22\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x36/0x50\n bad_page+0x70/0xf0\n free_unref_page_prepare+0x27a/0x460\n free_unref_page+0x38/0x120\n esp_ssg_unref.isra.0+0x15f/0x200\n esp_output_tail+0x66d/0x780\n esp_xmit+0x2c5/0x360\n validate_xmit_xfrm+0x313/0x370\n ? validate_xmit_skb+0x1d/0x330\n validate_xmit_skb_list+0x4c/0x70\n sch_direct_xmit+0x23e/0x350\n __dev_queue_xmit+0x337/0xba0\n ? nf_hook_slow+0x3f/0xd0\n ip_finish_output2+0x25e/0x580\n iptunnel_xmit+0x19b/0x240\n ip_tunnel_xmit+0x5fb/0xb60\n ipgre_xmit+0x14d/0x280 [ip_gre]\n dev_hard_start_xmit+0xc3/0x1c0\n __dev_queue_xmit+0x208/0xba0\n ? nf_hook_slow+0x3f/0xd0\n ip_finish_output2+0x1ca/0x580\n ip_sublist_rcv_finish+0x32/0x40\n ip_sublist_rcv+0x1b2/0x1f0\n ? ip_rcv_finish_core.constprop.0+0x460/0x460\n ip_list_rcv+0x103/0x130\n __netif_receive_skb_list_core+0x181/0x1e0\n netif_receive_skb_list_internal+0x1b3/0x2c0\n napi_gro_receive+0xc8/0x200\n gro_cell_poll+0x52/0x90\n __napi_poll+0x25/0x1a0\n net_rx_action+0x28e/0x300\n __do_softirq+0xc3/0x276\n ? sort_range+0x20/0x20\n run_ksoftirqd+0x1e/0x30\n smpboot_thread_fn+0xa6/0x130\n kthread+0xcd/0x100\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x31/0x50\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork_asm+0x11/0x20\n \u003c/TASK\u003e\n\nThe suggested fix is to introduce a new wrapper (skb_page_unref) that\ncovers page refcounting for page_pool pages as well.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-26953", "url": "https://www.suse.com/security/cve/CVE-2024-26953" }, { "category": "external", "summary": "SUSE Bug 1223656 for CVE-2024-26953", "url": "https://bugzilla.suse.com/1223656" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-26953" }, { "cve": "CVE-2024-27017", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-27017" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: walk over current view on netlink dump\n\nThe generation mask can be updated while netlink dump is in progress.\nThe pipapo set backend walk iterator cannot rely on it to infer what\nview of the datastructure is to be used. Add notation to specify if user\nwants to read/update the set.\n\nBased on patch from Florian Westphal.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-27017", "url": "https://www.suse.com/security/cve/CVE-2024-27017" }, { "category": "external", "summary": "SUSE Bug 1223733 for CVE-2024-27017", "url": "https://bugzilla.suse.com/1223733" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-27017" }, { "cve": "CVE-2024-27407", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-27407" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Fixed overflow check in mi_enum_attr()", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-27407", "url": "https://www.suse.com/security/cve/CVE-2024-27407" }, { "category": "external", "summary": "SUSE Bug 1224429 for CVE-2024-27407", "url": "https://bugzilla.suse.com/1224429" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-27407" }, { "cve": "CVE-2024-35888", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-35888" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nerspan: make sure erspan_base_hdr is present in skb-\u003ehead\n\nsyzbot reported a problem in ip6erspan_rcv() [1]\n\nIssue is that ip6erspan_rcv() (and erspan_rcv()) no longer make\nsure erspan_base_hdr is present in skb linear part (skb-\u003ehead)\nbefore getting @ver field from it.\n\nAdd the missing pskb_may_pull() calls.\n\nv2: Reload iph pointer in erspan_rcv() after pskb_may_pull()\n because skb-\u003ehead might have changed.\n\n[1]\n\n BUG: KMSAN: uninit-value in pskb_may_pull_reason include/linux/skbuff.h:2742 [inline]\n BUG: KMSAN: uninit-value in pskb_may_pull include/linux/skbuff.h:2756 [inline]\n BUG: KMSAN: uninit-value in ip6erspan_rcv net/ipv6/ip6_gre.c:541 [inline]\n BUG: KMSAN: uninit-value in gre_rcv+0x11f8/0x1930 net/ipv6/ip6_gre.c:610\n pskb_may_pull_reason include/linux/skbuff.h:2742 [inline]\n pskb_may_pull include/linux/skbuff.h:2756 [inline]\n ip6erspan_rcv net/ipv6/ip6_gre.c:541 [inline]\n gre_rcv+0x11f8/0x1930 net/ipv6/ip6_gre.c:610\n ip6_protocol_deliver_rcu+0x1d4c/0x2ca0 net/ipv6/ip6_input.c:438\n ip6_input_finish net/ipv6/ip6_input.c:483 [inline]\n NF_HOOK include/linux/netfilter.h:314 [inline]\n ip6_input+0x15d/0x430 net/ipv6/ip6_input.c:492\n ip6_mc_input+0xa7e/0xc80 net/ipv6/ip6_input.c:586\n dst_input include/net/dst.h:460 [inline]\n ip6_rcv_finish+0x955/0x970 net/ipv6/ip6_input.c:79\n NF_HOOK include/linux/netfilter.h:314 [inline]\n ipv6_rcv+0xde/0x390 net/ipv6/ip6_input.c:310\n __netif_receive_skb_one_core net/core/dev.c:5538 [inline]\n __netif_receive_skb+0x1da/0xa00 net/core/dev.c:5652\n netif_receive_skb_internal net/core/dev.c:5738 [inline]\n netif_receive_skb+0x58/0x660 net/core/dev.c:5798\n tun_rx_batched+0x3ee/0x980 drivers/net/tun.c:1549\n tun_get_user+0x5566/0x69e0 drivers/net/tun.c:2002\n tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\n call_write_iter include/linux/fs.h:2108 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0xb63/0x1520 fs/read_write.c:590\n ksys_write+0x20f/0x4c0 fs/read_write.c:643\n __do_sys_write fs/read_write.c:655 [inline]\n __se_sys_write fs/read_write.c:652 [inline]\n __x64_sys_write+0x93/0xe0 fs/read_write.c:652\n do_syscall_64+0xd5/0x1f0\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:3804 [inline]\n slab_alloc_node mm/slub.c:3845 [inline]\n kmem_cache_alloc_node+0x613/0xc50 mm/slub.c:3888\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:577\n __alloc_skb+0x35b/0x7a0 net/core/skbuff.c:668\n alloc_skb include/linux/skbuff.h:1318 [inline]\n alloc_skb_with_frags+0xc8/0xbf0 net/core/skbuff.c:6504\n sock_alloc_send_pskb+0xa81/0xbf0 net/core/sock.c:2795\n tun_alloc_skb drivers/net/tun.c:1525 [inline]\n tun_get_user+0x209a/0x69e0 drivers/net/tun.c:1846\n tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048\n call_write_iter include/linux/fs.h:2108 [inline]\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0xb63/0x1520 fs/read_write.c:590\n ksys_write+0x20f/0x4c0 fs/read_write.c:643\n __do_sys_write fs/read_write.c:655 [inline]\n __se_sys_write fs/read_write.c:652 [inline]\n __x64_sys_write+0x93/0xe0 fs/read_write.c:652\n do_syscall_64+0xd5/0x1f0\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\n\nCPU: 1 PID: 5045 Comm: syz-executor114 Not tainted 6.9.0-rc1-syzkaller-00021-g962490525cff #0", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-35888", "url": "https://www.suse.com/security/cve/CVE-2024-35888" }, { "category": "external", "summary": "SUSE Bug 1224518 for CVE-2024-35888", "url": "https://bugzilla.suse.com/1224518" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-35888" }, { "cve": "CVE-2024-36000", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36000" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix missing hugetlb_lock for resv uncharge\n\nThere is a recent report on UFFDIO_COPY over hugetlb:\n\nhttps://lore.kernel.org/all/000000000000ee06de0616177560@google.com/\n\n350:\tlockdep_assert_held(\u0026hugetlb_lock);\n\nShould be an issue in hugetlb but triggered in an userfault context, where\nit goes into the unlikely path where two threads modifying the resv map\ntogether. Mike has a fix in that path for resv uncharge but it looks like\nthe locking criteria was overlooked: hugetlb_cgroup_uncharge_folio_rsvd()\nwill update the cgroup pointer, so it requires to be called with the lock\nheld.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36000", "url": "https://www.suse.com/security/cve/CVE-2024-36000" }, { "category": "external", "summary": "SUSE Bug 1224548 for CVE-2024-36000", "url": "https://bugzilla.suse.com/1224548" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36000" }, { "cve": "CVE-2024-36031", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36031" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: Fix overwrite of key expiration on instantiation\n\nThe expiry time of a key is unconditionally overwritten during\ninstantiation, defaulting to turn it permanent. This causes a problem\nfor DNS resolution as the expiration set by user-space is overwritten to\nTIME64_MAX, disabling further DNS updates. Fix this by restoring the\ncondition that key_set_expiry is only called when the pre-parser sets a\nspecific expiry.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36031", "url": "https://www.suse.com/security/cve/CVE-2024-36031" }, { "category": "external", "summary": "SUSE Bug 1225713 for CVE-2024-36031", "url": "https://bugzilla.suse.com/1225713" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36031" }, { "cve": "CVE-2024-36484", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36484" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: relax socket state check at accept time.\n\nChristoph reported the following splat:\n\nWARNING: CPU: 1 PID: 772 at net/ipv4/af_inet.c:761 __inet_accept+0x1f4/0x4a0\nModules linked in:\nCPU: 1 PID: 772 Comm: syz-executor510 Not tainted 6.9.0-rc7-g7da7119fe22b #56\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014\nRIP: 0010:__inet_accept+0x1f4/0x4a0 net/ipv4/af_inet.c:759\nCode: 04 38 84 c0 0f 85 87 00 00 00 41 c7 04 24 03 00 00 00 48 83 c4 10 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc e8 ec b7 da fd \u003c0f\u003e 0b e9 7f fe ff ff e8 e0 b7 da fd 0f 0b e9 fe fe ff ff 89 d9 80\nRSP: 0018:ffffc90000c2fc58 EFLAGS: 00010293\nRAX: ffffffff836bdd14 RBX: 0000000000000000 RCX: ffff888104668000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: dffffc0000000000 R08: ffffffff836bdb89 R09: fffff52000185f64\nR10: dffffc0000000000 R11: fffff52000185f64 R12: dffffc0000000000\nR13: 1ffff92000185f98 R14: ffff88810754d880 R15: ffff8881007b7800\nFS: 000000001c772880(0000) GS:ffff88811b280000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fb9fcf2e178 CR3: 00000001045d2002 CR4: 0000000000770ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \u003cTASK\u003e\n inet_accept+0x138/0x1d0 net/ipv4/af_inet.c:786\n do_accept+0x435/0x620 net/socket.c:1929\n __sys_accept4_file net/socket.c:1969 [inline]\n __sys_accept4+0x9b/0x110 net/socket.c:1999\n __do_sys_accept net/socket.c:2016 [inline]\n __se_sys_accept net/socket.c:2013 [inline]\n __x64_sys_accept+0x7d/0x90 net/socket.c:2013\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x58/0x100 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x4315f9\nCode: fd ff 48 81 c4 80 00 00 00 e9 f1 fe ff ff 0f 1f 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 0f 83 ab b4 fd ff c3 66 2e 0f 1f 84 00 00 00 00\nRSP: 002b:00007ffdb26d9c78 EFLAGS: 00000246 ORIG_RAX: 000000000000002b\nRAX: ffffffffffffffda RBX: 0000000000400300 RCX: 00000000004315f9\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000004\nRBP: 00000000006e1018 R08: 0000000000400300 R09: 0000000000400300\nR10: 0000000000400300 R11: 0000000000000246 R12: 0000000000000000\nR13: 000000000040cdf0 R14: 000000000040ce80 R15: 0000000000000055\n \u003c/TASK\u003e\n\nThe reproducer invokes shutdown() before entering the listener status.\nAfter commit 94062790aedb (\"tcp: defer shutdown(SEND_SHUTDOWN) for\nTCP_SYN_RECV sockets\"), the above causes the child to reach the accept\nsyscall in FIN_WAIT1 status.\n\nEric noted we can relax the existing assertion in __inet_accept()", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36484", "url": "https://www.suse.com/security/cve/CVE-2024-36484" }, { "category": "external", "summary": "SUSE Bug 1226872 for CVE-2024-36484", "url": "https://bugzilla.suse.com/1226872" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36484" }, { "cve": "CVE-2024-36883", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36883" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix out-of-bounds access in ops_init\n\nnet_alloc_generic is called by net_alloc, which is called without any\nlocking. It reads max_gen_ptrs, which is changed under pernet_ops_rwsem. It\nis read twice, first to allocate an array, then to set s.len, which is\nlater used to limit the bounds of the array access.\n\nIt is possible that the array is allocated and another thread is\nregistering a new pernet ops, increments max_gen_ptrs, which is then used\nto set s.len with a larger than allocated length for the variable array.\n\nFix it by reading max_gen_ptrs only once in net_alloc_generic. If\nmax_gen_ptrs is later incremented, it will be caught in net_assign_generic.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36883", "url": "https://www.suse.com/security/cve/CVE-2024-36883" }, { "category": "external", "summary": "SUSE Bug 1225725 for CVE-2024-36883", "url": "https://bugzilla.suse.com/1225725" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36883" }, { "cve": "CVE-2024-36886", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36886" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix UAF in error path\n\nSam Page (sam4k) working with Trend Micro Zero Day Initiative reported\na UAF in the tipc_buf_append() error path:\n\nBUG: KASAN: slab-use-after-free in kfree_skb_list_reason+0x47e/0x4c0\nlinux/net/core/skbuff.c:1183\nRead of size 8 at addr ffff88804d2a7c80 by task poc/8034\n\nCPU: 1 PID: 8034 Comm: poc Not tainted 6.8.2 #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.0-debian-1.16.0-5 04/01/2014\nCall Trace:\n \u003cIRQ\u003e\n __dump_stack linux/lib/dump_stack.c:88\n dump_stack_lvl+0xd9/0x1b0 linux/lib/dump_stack.c:106\n print_address_description linux/mm/kasan/report.c:377\n print_report+0xc4/0x620 linux/mm/kasan/report.c:488\n kasan_report+0xda/0x110 linux/mm/kasan/report.c:601\n kfree_skb_list_reason+0x47e/0x4c0 linux/net/core/skbuff.c:1183\n skb_release_data+0x5af/0x880 linux/net/core/skbuff.c:1026\n skb_release_all linux/net/core/skbuff.c:1094\n __kfree_skb linux/net/core/skbuff.c:1108\n kfree_skb_reason+0x12d/0x210 linux/net/core/skbuff.c:1144\n kfree_skb linux/./include/linux/skbuff.h:1244\n tipc_buf_append+0x425/0xb50 linux/net/tipc/msg.c:186\n tipc_link_input+0x224/0x7c0 linux/net/tipc/link.c:1324\n tipc_link_rcv+0x76e/0x2d70 linux/net/tipc/link.c:1824\n tipc_rcv+0x45f/0x10f0 linux/net/tipc/node.c:2159\n tipc_udp_recv+0x73b/0x8f0 linux/net/tipc/udp_media.c:390\n udp_queue_rcv_one_skb+0xad2/0x1850 linux/net/ipv4/udp.c:2108\n udp_queue_rcv_skb+0x131/0xb00 linux/net/ipv4/udp.c:2186\n udp_unicast_rcv_skb+0x165/0x3b0 linux/net/ipv4/udp.c:2346\n __udp4_lib_rcv+0x2594/0x3400 linux/net/ipv4/udp.c:2422\n ip_protocol_deliver_rcu+0x30c/0x4e0 linux/net/ipv4/ip_input.c:205\n ip_local_deliver_finish+0x2e4/0x520 linux/net/ipv4/ip_input.c:233\n NF_HOOK linux/./include/linux/netfilter.h:314\n NF_HOOK linux/./include/linux/netfilter.h:308\n ip_local_deliver+0x18e/0x1f0 linux/net/ipv4/ip_input.c:254\n dst_input linux/./include/net/dst.h:461\n ip_rcv_finish linux/net/ipv4/ip_input.c:449\n NF_HOOK linux/./include/linux/netfilter.h:314\n NF_HOOK linux/./include/linux/netfilter.h:308\n ip_rcv+0x2c5/0x5d0 linux/net/ipv4/ip_input.c:569\n __netif_receive_skb_one_core+0x199/0x1e0 linux/net/core/dev.c:5534\n __netif_receive_skb+0x1f/0x1c0 linux/net/core/dev.c:5648\n process_backlog+0x101/0x6b0 linux/net/core/dev.c:5976\n __napi_poll.constprop.0+0xba/0x550 linux/net/core/dev.c:6576\n napi_poll linux/net/core/dev.c:6645\n net_rx_action+0x95a/0xe90 linux/net/core/dev.c:6781\n __do_softirq+0x21f/0x8e7 linux/kernel/softirq.c:553\n do_softirq linux/kernel/softirq.c:454\n do_softirq+0xb2/0xf0 linux/kernel/softirq.c:441\n \u003c/IRQ\u003e\n \u003cTASK\u003e\n __local_bh_enable_ip+0x100/0x120 linux/kernel/softirq.c:381\n local_bh_enable linux/./include/linux/bottom_half.h:33\n rcu_read_unlock_bh linux/./include/linux/rcupdate.h:851\n __dev_queue_xmit+0x871/0x3ee0 linux/net/core/dev.c:4378\n dev_queue_xmit linux/./include/linux/netdevice.h:3169\n neigh_hh_output linux/./include/net/neighbour.h:526\n neigh_output linux/./include/net/neighbour.h:540\n ip_finish_output2+0x169f/0x2550 linux/net/ipv4/ip_output.c:235\n __ip_finish_output linux/net/ipv4/ip_output.c:313\n __ip_finish_output+0x49e/0x950 linux/net/ipv4/ip_output.c:295\n ip_finish_output+0x31/0x310 linux/net/ipv4/ip_output.c:323\n NF_HOOK_COND linux/./include/linux/netfilter.h:303\n ip_output+0x13b/0x2a0 linux/net/ipv4/ip_output.c:433\n dst_output linux/./include/net/dst.h:451\n ip_local_out linux/net/ipv4/ip_output.c:129\n ip_send_skb+0x3e5/0x560 linux/net/ipv4/ip_output.c:1492\n udp_send_skb+0x73f/0x1530 linux/net/ipv4/udp.c:963\n udp_sendmsg+0x1a36/0x2b40 linux/net/ipv4/udp.c:1250\n inet_sendmsg+0x105/0x140 linux/net/ipv4/af_inet.c:850\n sock_sendmsg_nosec linux/net/socket.c:730\n __sock_sendmsg linux/net/socket.c:745\n __sys_sendto+0x42c/0x4e0 linux/net/socket.c:2191\n __do_sys_sendto linux/net/socket.c:2203\n __se_sys_sendto linux/net/socket.c:2199\n __x64_sys_sendto+0xe0/0x1c0 linux/net/socket.c:2199\n do_syscall_x64 linux/arch/x86/entry/common.c:52\n do_syscall_\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36886", "url": "https://www.suse.com/security/cve/CVE-2024-36886" }, { "category": "external", "summary": "SUSE Bug 1225730 for CVE-2024-36886", "url": "https://bugzilla.suse.com/1225730" }, { "category": "external", "summary": "SUSE Bug 1225742 for CVE-2024-36886", "url": "https://bugzilla.suse.com/1225742" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36886" }, { "cve": "CVE-2024-36905", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36905" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets\n\nTCP_SYN_RECV state is really special, it is only used by\ncross-syn connections, mostly used by fuzzers.\n\nIn the following crash [1], syzbot managed to trigger a divide\nby zero in tcp_rcv_space_adjust()\n\nA socket makes the following state transitions,\nwithout ever calling tcp_init_transfer(),\nmeaning tcp_init_buffer_space() is also not called.\n\n TCP_CLOSE\nconnect()\n TCP_SYN_SENT\n TCP_SYN_RECV\nshutdown() -\u003e tcp_shutdown(sk, SEND_SHUTDOWN)\n TCP_FIN_WAIT1\n\nTo fix this issue, change tcp_shutdown() to not\nperform a TCP_SYN_RECV -\u003e TCP_FIN_WAIT1 transition,\nwhich makes no sense anyway.\n\nWhen tcp_rcv_state_process() later changes socket state\nfrom TCP_SYN_RECV to TCP_ESTABLISH, then look at\nsk-\u003esk_shutdown to finally enter TCP_FIN_WAIT1 state,\nand send a FIN packet from a sane socket state.\n\nThis means tcp_send_fin() can now be called from BH\ncontext, and must use GFP_ATOMIC allocations.\n\n[1]\ndivide error: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 1 PID: 5084 Comm: syz-executor358 Not tainted 6.9.0-rc6-syzkaller-00022-g98369dccd2f8 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\n RIP: 0010:tcp_rcv_space_adjust+0x2df/0x890 net/ipv4/tcp_input.c:767\nCode: e3 04 4c 01 eb 48 8b 44 24 38 0f b6 04 10 84 c0 49 89 d5 0f 85 a5 03 00 00 41 8b 8e c8 09 00 00 89 e8 29 c8 48 0f af c3 31 d2 \u003c48\u003e f7 f1 48 8d 1c 43 49 8d 96 76 08 00 00 48 89 d0 48 c1 e8 03 48\nRSP: 0018:ffffc900031ef3f0 EFLAGS: 00010246\nRAX: 0c677a10441f8f42 RBX: 000000004fb95e7e RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: 0000000027d4b11f R08: ffffffff89e535a4 R09: 1ffffffff25e6ab7\nR10: dffffc0000000000 R11: ffffffff8135e920 R12: ffff88802a9f8d30\nR13: dffffc0000000000 R14: ffff88802a9f8d00 R15: 1ffff1100553f2da\nFS: 00005555775c0380(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f1155bf2304 CR3: 000000002b9f2000 CR4: 0000000000350ef0\nCall Trace:\n \u003cTASK\u003e\n tcp_recvmsg_locked+0x106d/0x25a0 net/ipv4/tcp.c:2513\n tcp_recvmsg+0x25d/0x920 net/ipv4/tcp.c:2578\n inet6_recvmsg+0x16a/0x730 net/ipv6/af_inet6.c:680\n sock_recvmsg_nosec net/socket.c:1046 [inline]\n sock_recvmsg+0x109/0x280 net/socket.c:1068\n ____sys_recvmsg+0x1db/0x470 net/socket.c:2803\n ___sys_recvmsg net/socket.c:2845 [inline]\n do_recvmmsg+0x474/0xae0 net/socket.c:2939\n __sys_recvmmsg net/socket.c:3018 [inline]\n __do_sys_recvmmsg net/socket.c:3041 [inline]\n __se_sys_recvmmsg net/socket.c:3034 [inline]\n __x64_sys_recvmmsg+0x199/0x250 net/socket.c:3034\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7faeb6363db9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffcc1997168 EFLAGS: 00000246 ORIG_RAX: 000000000000012b\nRAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007faeb6363db9\nRDX: 0000000000000001 RSI: 0000000020000bc0 RDI: 0000000000000005\nRBP: 0000000000000000 R08: 0000000000000000 R09: 000000000000001c\nR10: 0000000000000122 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000001", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36905", "url": "https://www.suse.com/security/cve/CVE-2024-36905" }, { "category": "external", "summary": "SUSE Bug 1225742 for CVE-2024-36905", "url": "https://bugzilla.suse.com/1225742" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36905" }, { "cve": "CVE-2024-36920", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36920" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpi3mr: Avoid memcpy field-spanning write WARNING\n\nWhen the \"storcli2 show\" command is executed for eHBA-9600, mpi3mr driver\nprints this WARNING message:\n\n memcpy: detected field-spanning write (size 128) of single field \"bsg_reply_buf-\u003ereply_buf\" at drivers/scsi/mpi3mr/mpi3mr_app.c:1658 (size 1)\n WARNING: CPU: 0 PID: 12760 at drivers/scsi/mpi3mr/mpi3mr_app.c:1658 mpi3mr_bsg_request+0x6b12/0x7f10 [mpi3mr]\n\nThe cause of the WARN is 128 bytes memcpy to the 1 byte size array \"__u8\nreplay_buf[1]\" in the struct mpi3mr_bsg_in_reply_buf. The array is intended\nto be a flexible length array, so the WARN is a false positive.\n\nTo suppress the WARN, remove the constant number \u00271\u0027 from the array\ndeclaration and clarify that it has flexible length. Also, adjust the\nmemory allocation size to match the change.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36920", "url": "https://www.suse.com/security/cve/CVE-2024-36920" }, { "category": "external", "summary": "SUSE Bug 1225768 for CVE-2024-36920", "url": "https://bugzilla.suse.com/1225768" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36920" }, { "cve": "CVE-2024-36927", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36927" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: Fix uninit-value access in __ip_make_skb()\n\nKMSAN reported uninit-value access in __ip_make_skb() [1]. __ip_make_skb()\ntests HDRINCL to know if the skb has icmphdr. However, HDRINCL can cause a\nrace condition. If calling setsockopt(2) with IP_HDRINCL changes HDRINCL\nwhile __ip_make_skb() is running, the function will access icmphdr in the\nskb even if it is not included. This causes the issue reported by KMSAN.\n\nCheck FLOWI_FLAG_KNOWN_NH on fl4-\u003eflowi4_flags instead of testing HDRINCL\non the socket.\n\nAlso, fl4-\u003efl4_icmp_type and fl4-\u003efl4_icmp_code are not initialized. These\nare union in struct flowi4 and are implicitly initialized by\nflowi4_init_output(), but we should not rely on specific union layout.\n\nInitialize these explicitly in raw_sendmsg().\n\n[1]\nBUG: KMSAN: uninit-value in __ip_make_skb+0x2b74/0x2d20 net/ipv4/ip_output.c:1481\n __ip_make_skb+0x2b74/0x2d20 net/ipv4/ip_output.c:1481\n ip_finish_skb include/net/ip.h:243 [inline]\n ip_push_pending_frames+0x4c/0x5c0 net/ipv4/ip_output.c:1508\n raw_sendmsg+0x2381/0x2690 net/ipv4/raw.c:654\n inet_sendmsg+0x27b/0x2a0 net/ipv4/af_inet.c:851\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x274/0x3c0 net/socket.c:745\n __sys_sendto+0x62c/0x7b0 net/socket.c:2191\n __do_sys_sendto net/socket.c:2203 [inline]\n __se_sys_sendto net/socket.c:2199 [inline]\n __x64_sys_sendto+0x130/0x200 net/socket.c:2199\n do_syscall_64+0xd8/0x1f0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:3804 [inline]\n slab_alloc_node mm/slub.c:3845 [inline]\n kmem_cache_alloc_node+0x5f6/0xc50 mm/slub.c:3888\n kmalloc_reserve+0x13c/0x4a0 net/core/skbuff.c:577\n __alloc_skb+0x35a/0x7c0 net/core/skbuff.c:668\n alloc_skb include/linux/skbuff.h:1318 [inline]\n __ip_append_data+0x49ab/0x68c0 net/ipv4/ip_output.c:1128\n ip_append_data+0x1e7/0x260 net/ipv4/ip_output.c:1365\n raw_sendmsg+0x22b1/0x2690 net/ipv4/raw.c:648\n inet_sendmsg+0x27b/0x2a0 net/ipv4/af_inet.c:851\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x274/0x3c0 net/socket.c:745\n __sys_sendto+0x62c/0x7b0 net/socket.c:2191\n __do_sys_sendto net/socket.c:2203 [inline]\n __se_sys_sendto net/socket.c:2199 [inline]\n __x64_sys_sendto+0x130/0x200 net/socket.c:2199\n do_syscall_64+0xd8/0x1f0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\n\nCPU: 1 PID: 15709 Comm: syz-executor.7 Not tainted 6.8.0-11567-gb3603fcb79b1 #25\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-1.fc39 04/01/2014", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36927", "url": "https://www.suse.com/security/cve/CVE-2024-36927" }, { "category": "external", "summary": "SUSE Bug 1225813 for CVE-2024-36927", "url": "https://bugzilla.suse.com/1225813" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36927" }, { "cve": "CVE-2024-36954", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36954" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix a possible memleak in tipc_buf_append\n\n__skb_linearize() doesn\u0027t free the skb when it fails, so move\n\u0027*buf = NULL\u0027 after __skb_linearize(), so that the skb can be\nfreed on the err path.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36954", "url": "https://www.suse.com/security/cve/CVE-2024-36954" }, { "category": "external", "summary": "SUSE Bug 1225764 for CVE-2024-36954", "url": "https://bugzilla.suse.com/1225764" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36954" }, { "cve": "CVE-2024-36968", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36968" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init()\n\nl2cap_le_flowctl_init() can cause both div-by-zero and an integer\noverflow since hdev-\u003ele_mtu may not fall in the valid range.\n\nMove MTU from hci_dev to hci_conn to validate MTU and stop the connection\nprocess earlier if MTU is invalid.\nAlso, add a missing validation in read_buffer_size() and make it return\nan error value if the validation fails.\nNow hci_conn_add() returns ERR_PTR() as it can fail due to the both a\nkzalloc failure and invalid MTU value.\n\ndivide error: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 0 PID: 67 Comm: kworker/u5:0 Tainted: G W 6.9.0-rc5+ #20\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nWorkqueue: hci0 hci_rx_work\nRIP: 0010:l2cap_le_flowctl_init+0x19e/0x3f0 net/bluetooth/l2cap_core.c:547\nCode: e8 17 17 0c 00 66 41 89 9f 84 00 00 00 bf 01 00 00 00 41 b8 02 00 00 00 4c\n89 fe 4c 89 e2 89 d9 e8 27 17 0c 00 44 89 f0 31 d2 \u003c66\u003e f7 f3 89 c3 ff c3 4d 8d\nb7 88 00 00 00 4c 89 f0 48 c1 e8 03 42\nRSP: 0018:ffff88810bc0f858 EFLAGS: 00010246\nRAX: 00000000000002a0 RBX: 0000000000000000 RCX: dffffc0000000000\nRDX: 0000000000000000 RSI: ffff88810bc0f7c0 RDI: ffffc90002dcb66f\nRBP: ffff88810bc0f880 R08: aa69db2dda70ff01 R09: 0000ffaaaaaaaaaa\nR10: 0084000000ffaaaa R11: 0000000000000000 R12: ffff88810d65a084\nR13: dffffc0000000000 R14: 00000000000002a0 R15: ffff88810d65a000\nFS: 0000000000000000(0000) GS:ffff88811ac00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000020000100 CR3: 0000000103268003 CR4: 0000000000770ef0\nPKRU: 55555554\nCall Trace:\n \u003cTASK\u003e\n l2cap_le_connect_req net/bluetooth/l2cap_core.c:4902 [inline]\n l2cap_le_sig_cmd net/bluetooth/l2cap_core.c:5420 [inline]\n l2cap_le_sig_channel net/bluetooth/l2cap_core.c:5486 [inline]\n l2cap_recv_frame+0xe59d/0x11710 net/bluetooth/l2cap_core.c:6809\n l2cap_recv_acldata+0x544/0x10a0 net/bluetooth/l2cap_core.c:7506\n hci_acldata_packet net/bluetooth/hci_core.c:3939 [inline]\n hci_rx_work+0x5e5/0xb20 net/bluetooth/hci_core.c:4176\n process_one_work kernel/workqueue.c:3254 [inline]\n process_scheduled_works+0x90f/0x1530 kernel/workqueue.c:3335\n worker_thread+0x926/0xe70 kernel/workqueue.c:3416\n kthread+0x2e3/0x380 kernel/kthread.c:388\n ret_from_fork+0x5c/0x90 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \u003c/TASK\u003e\nModules linked in:\n---[ end trace 0000000000000000 ]---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36968", "url": "https://www.suse.com/security/cve/CVE-2024-36968" }, { "category": "external", "summary": "SUSE Bug 1226130 for CVE-2024-36968", "url": "https://bugzilla.suse.com/1226130" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-36968" }, { "cve": "CVE-2024-38589", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-38589" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetrom: fix possible dead-lock in nr_rt_ioctl()\n\nsyzbot loves netrom, and found a possible deadlock in nr_rt_ioctl [1]\n\nMake sure we always acquire nr_node_list_lock before nr_node_lock(nr_node)\n\n[1]\nWARNING: possible circular locking dependency detected\n6.9.0-rc7-syzkaller-02147-g654de42f3fc6 #0 Not tainted\n------------------------------------------------------\nsyz-executor350/5129 is trying to acquire lock:\n ffff8880186e2070 (\u0026nr_node-\u003enode_lock){+...}-{2:2}, at: spin_lock_bh include/linux/spinlock.h:356 [inline]\n ffff8880186e2070 (\u0026nr_node-\u003enode_lock){+...}-{2:2}, at: nr_node_lock include/net/netrom.h:152 [inline]\n ffff8880186e2070 (\u0026nr_node-\u003enode_lock){+...}-{2:2}, at: nr_dec_obs net/netrom/nr_route.c:464 [inline]\n ffff8880186e2070 (\u0026nr_node-\u003enode_lock){+...}-{2:2}, at: nr_rt_ioctl+0x1bb/0x1090 net/netrom/nr_route.c:697\n\nbut task is already holding lock:\n ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: spin_lock_bh include/linux/spinlock.h:356 [inline]\n ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: nr_dec_obs net/netrom/nr_route.c:462 [inline]\n ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: nr_rt_ioctl+0x10a/0x1090 net/netrom/nr_route.c:697\n\nwhich lock already depends on the new lock.\n\nthe existing dependency chain (in reverse order) is:\n\n-\u003e #1 (nr_node_list_lock){+...}-{2:2}:\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5754\n __raw_spin_lock_bh include/linux/spinlock_api_smp.h:126 [inline]\n _raw_spin_lock_bh+0x35/0x50 kernel/locking/spinlock.c:178\n spin_lock_bh include/linux/spinlock.h:356 [inline]\n nr_remove_node net/netrom/nr_route.c:299 [inline]\n nr_del_node+0x4b4/0x820 net/netrom/nr_route.c:355\n nr_rt_ioctl+0xa95/0x1090 net/netrom/nr_route.c:683\n sock_do_ioctl+0x158/0x460 net/socket.c:1222\n sock_ioctl+0x629/0x8e0 net/socket.c:1341\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:904 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:890\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n-\u003e #0 (\u0026nr_node-\u003enode_lock){+...}-{2:2}:\n check_prev_add kernel/locking/lockdep.c:3134 [inline]\n check_prevs_add kernel/locking/lockdep.c:3253 [inline]\n validate_chain+0x18cb/0x58e0 kernel/locking/lockdep.c:3869\n __lock_acquire+0x1346/0x1fd0 kernel/locking/lockdep.c:5137\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5754\n __raw_spin_lock_bh include/linux/spinlock_api_smp.h:126 [inline]\n _raw_spin_lock_bh+0x35/0x50 kernel/locking/spinlock.c:178\n spin_lock_bh include/linux/spinlock.h:356 [inline]\n nr_node_lock include/net/netrom.h:152 [inline]\n nr_dec_obs net/netrom/nr_route.c:464 [inline]\n nr_rt_ioctl+0x1bb/0x1090 net/netrom/nr_route.c:697\n sock_do_ioctl+0x158/0x460 net/socket.c:1222\n sock_ioctl+0x629/0x8e0 net/socket.c:1341\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:904 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:890\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nother info that might help us debug this:\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(nr_node_list_lock);\n lock(\u0026nr_node-\u003enode_lock);\n lock(nr_node_list_lock);\n lock(\u0026nr_node-\u003enode_lock);\n\n *** DEADLOCK ***\n\n1 lock held by syz-executor350/5129:\n #0: ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: spin_lock_bh include/linux/spinlock.h:356 [inline]\n #0: ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: nr_dec_obs net/netrom/nr_route.c:462 [inline]\n #0: ffffffff8f70\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-38589", "url": "https://www.suse.com/security/cve/CVE-2024-38589" }, { "category": "external", "summary": "SUSE Bug 1226748 for CVE-2024-38589", "url": "https://bugzilla.suse.com/1226748" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-38589" }, { "cve": "CVE-2024-40914", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-40914" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: don\u0027t unpoison huge_zero_folio\n\nWhen I did memory failure tests recently, below panic occurs:\n\n kernel BUG at include/linux/mm.h:1135!\n invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 9 PID: 137 Comm: kswapd1 Not tainted 6.9.0-rc4-00491-gd5ce28f156fe-dirty #14\n RIP: 0010:shrink_huge_zero_page_scan+0x168/0x1a0\n RSP: 0018:ffff9933c6c57bd0 EFLAGS: 00000246\n RAX: 000000000000003e RBX: 0000000000000000 RCX: ffff88f61fc5c9c8\n RDX: 0000000000000000 RSI: 0000000000000027 RDI: ffff88f61fc5c9c0\n RBP: ffffcd7c446b0000 R08: ffffffff9a9405f0 R09: 0000000000005492\n R10: 00000000000030ea R11: ffffffff9a9405f0 R12: 0000000000000000\n R13: 0000000000000000 R14: 0000000000000000 R15: ffff88e703c4ac00\n FS: 0000000000000000(0000) GS:ffff88f61fc40000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000055f4da6e9878 CR3: 0000000c71048000 CR4: 00000000000006f0\n Call Trace:\n \u003cTASK\u003e\n do_shrink_slab+0x14f/0x6a0\n shrink_slab+0xca/0x8c0\n shrink_node+0x2d0/0x7d0\n balance_pgdat+0x33a/0x720\n kswapd+0x1f3/0x410\n kthread+0xd5/0x100\n ret_from_fork+0x2f/0x50\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e\n Modules linked in: mce_inject hwpoison_inject\n ---[ end trace 0000000000000000 ]---\n RIP: 0010:shrink_huge_zero_page_scan+0x168/0x1a0\n RSP: 0018:ffff9933c6c57bd0 EFLAGS: 00000246\n RAX: 000000000000003e RBX: 0000000000000000 RCX: ffff88f61fc5c9c8\n RDX: 0000000000000000 RSI: 0000000000000027 RDI: ffff88f61fc5c9c0\n RBP: ffffcd7c446b0000 R08: ffffffff9a9405f0 R09: 0000000000005492\n R10: 00000000000030ea R11: ffffffff9a9405f0 R12: 0000000000000000\n R13: 0000000000000000 R14: 0000000000000000 R15: ffff88e703c4ac00\n FS: 0000000000000000(0000) GS:ffff88f61fc40000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000055f4da6e9878 CR3: 0000000c71048000 CR4: 00000000000006f0\n\nThe root cause is that HWPoison flag will be set for huge_zero_folio\nwithout increasing the folio refcnt. But then unpoison_memory() will\ndecrease the folio refcnt unexpectedly as it appears like a successfully\nhwpoisoned folio leading to VM_BUG_ON_PAGE(page_ref_count(page) == 0) when\nreleasing huge_zero_folio.\n\nSkip unpoisoning huge_zero_folio in unpoison_memory() to fix this issue. \nWe\u0027re not prepared to unpoison huge_zero_folio yet.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-40914", "url": "https://www.suse.com/security/cve/CVE-2024-40914" }, { "category": "external", "summary": "SUSE Bug 1227842 for CVE-2024-40914", "url": "https://bugzilla.suse.com/1227842" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-40914" }, { "cve": "CVE-2024-41023", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-41023" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/deadline: Fix task_struct reference leak\n\nDuring the execution of the following stress test with linux-rt:\n\nstress-ng --cyclic 30 --timeout 30 --minimize --quiet\n\nkmemleak frequently reported a memory leak concerning the task_struct:\n\nunreferenced object 0xffff8881305b8000 (size 16136):\n comm \"stress-ng\", pid 614, jiffies 4294883961 (age 286.412s)\n object hex dump (first 32 bytes):\n 02 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 .@..............\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n debug hex dump (first 16 bytes):\n 53 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 S...............\n backtrace:\n [\u003c00000000046b6790\u003e] dup_task_struct+0x30/0x540\n [\u003c00000000c5ca0f0b\u003e] copy_process+0x3d9/0x50e0\n [\u003c00000000ced59777\u003e] kernel_clone+0xb0/0x770\n [\u003c00000000a50befdc\u003e] __do_sys_clone+0xb6/0xf0\n [\u003c000000001dbf2008\u003e] do_syscall_64+0x5d/0xf0\n [\u003c00000000552900ff\u003e] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nThe issue occurs in start_dl_timer(), which increments the task_struct\nreference count and sets a timer. The timer callback, dl_task_timer,\nis supposed to decrement the reference count upon expiration. However,\nif enqueue_task_dl() is called before the timer expires and cancels it,\nthe reference count is not decremented, leading to the leak.\n\nThis patch fixes the reference leak by ensuring the task_struct\nreference count is properly decremented when the timer is canceled.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-41023", "url": "https://www.suse.com/security/cve/CVE-2024-41023" }, { "category": "external", "summary": "SUSE Bug 1228430 for CVE-2024-41023", "url": "https://bugzilla.suse.com/1228430" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-41023" }, { "cve": "CVE-2024-42102", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-42102" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again\"\n\nPatch series \"mm: Avoid possible overflows in dirty throttling\".\n\nDirty throttling logic assumes dirty limits in page units fit into\n32-bits. This patch series makes sure this is true (see patch 2/2 for\nmore details).\n\n\nThis patch (of 2):\n\nThis reverts commit 9319b647902cbd5cc884ac08a8a6d54ce111fc78.\n\nThe commit is broken in several ways. Firstly, the removed (u64) cast\nfrom the multiplication will introduce a multiplication overflow on 32-bit\narchs if wb_thresh * bg_thresh \u003e= 1\u003c\u003c32 (which is actually common - the\ndefault settings with 4GB of RAM will trigger this). Secondly, the\ndiv64_u64() is unnecessarily expensive on 32-bit archs. We have\ndiv64_ul() in case we want to be safe \u0026 cheap. Thirdly, if dirty\nthresholds are larger than 1\u003c\u003c32 pages, then dirty balancing is going to\nblow up in many other spectacular ways anyway so trying to fix one\npossible overflow is just moot.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-42102", "url": "https://www.suse.com/security/cve/CVE-2024-42102" }, { "category": "external", "summary": "SUSE Bug 1222364 for CVE-2024-42102", "url": "https://bugzilla.suse.com/1222364" }, { "category": "external", "summary": "SUSE Bug 1233132 for CVE-2024-42102", "url": "https://bugzilla.suse.com/1233132" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-42102" }, { "cve": "CVE-2024-44995", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-44995" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix a deadlock problem when config TC during resetting\n\nWhen config TC during the reset process, may cause a deadlock, the flow is\nas below:\n pf reset start\n |\n \u25bc\n ......\nsetup tc |\n | \u25bc\n \u25bc DOWN: napi_disable()\nnapi_disable()(skip) |\n | |\n \u25bc \u25bc\n ...... ......\n | |\n \u25bc |\nnapi_enable() |\n \u25bc\n UINIT: netif_napi_del()\n |\n \u25bc\n ......\n |\n \u25bc\n INIT: netif_napi_add()\n |\n \u25bc\n ...... global reset start\n | |\n \u25bc \u25bc\n UP: napi_enable()(skip) ......\n | |\n \u25bc \u25bc\n ...... napi_disable()\n\nIn reset process, the driver will DOWN the port and then UINIT, in this\ncase, the setup tc process will UP the port before UINIT, so cause the\nproblem. Adds a DOWN process in UINIT to fix it.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-44995", "url": "https://www.suse.com/security/cve/CVE-2024-44995" }, { "category": "external", "summary": "SUSE Bug 1230231 for CVE-2024-44995", "url": "https://bugzilla.suse.com/1230231" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-44995" }, { "cve": "CVE-2024-46680", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-46680" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix random crash seen while removing driver\n\nThis fixes the random kernel crash seen while removing the driver, when\nrunning the load/unload test over multiple iterations.\n\n1) modprobe btnxpuart\n2) hciconfig hci0 reset\n3) hciconfig (check hci0 interface up with valid BD address)\n4) modprobe -r btnxpuart\nRepeat steps 1 to 4\n\nThe ps_wakeup() call in btnxpuart_close() schedules the psdata-\u003ework(),\nwhich gets scheduled after module is removed, causing a kernel crash.\n\nThis hidden issue got highlighted after enabling Power Save by default\nin 4183a7be7700 (Bluetooth: btnxpuart: Enable Power Save feature on\nstartup)\n\nThe new ps_cleanup() deasserts UART break immediately while closing\nserdev device, cancels any scheduled ps_work and destroys the ps_lock\nmutex.\n\n[ 85.884604] Unable to handle kernel paging request at virtual address ffffd4a61638f258\n[ 85.884624] Mem abort info:\n[ 85.884625] ESR = 0x0000000086000007\n[ 85.884628] EC = 0x21: IABT (current EL), IL = 32 bits\n[ 85.884633] SET = 0, FnV = 0\n[ 85.884636] EA = 0, S1PTW = 0\n[ 85.884638] FSC = 0x07: level 3 translation fault\n[ 85.884642] swapper pgtable: 4k pages, 48-bit VAs, pgdp=0000000041dd0000\n[ 85.884646] [ffffd4a61638f258] pgd=1000000095fff003, p4d=1000000095fff003, pud=100000004823d003, pmd=100000004823e003, pte=0000000000000000\n[ 85.884662] Internal error: Oops: 0000000086000007 [#1] PREEMPT SMP\n[ 85.890932] Modules linked in: algif_hash algif_skcipher af_alg overlay fsl_jr_uio caam_jr caamkeyblob_desc caamhash_desc caamalg_desc crypto_engine authenc libdes crct10dif_ce polyval_ce polyval_generic snd_soc_imx_spdif snd_soc_imx_card snd_soc_ak5558 snd_soc_ak4458 caam secvio error snd_soc_fsl_spdif snd_soc_fsl_micfil snd_soc_fsl_sai snd_soc_fsl_utils gpio_ir_recv rc_core fuse [last unloaded: btnxpuart(O)]\n[ 85.927297] CPU: 1 PID: 67 Comm: kworker/1:3 Tainted: G O 6.1.36+g937b1be4345a #1\n[ 85.936176] Hardware name: FSL i.MX8MM EVK board (DT)\n[ 85.936182] Workqueue: events 0xffffd4a61638f380\n[ 85.936198] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 85.952817] pc : 0xffffd4a61638f258\n[ 85.952823] lr : 0xffffd4a61638f258\n[ 85.952827] sp : ffff8000084fbd70\n[ 85.952829] x29: ffff8000084fbd70 x28: 0000000000000000 x27: 0000000000000000\n[ 85.963112] x26: ffffd4a69133f000 x25: ffff4bf1c8540990 x24: ffff4bf215b87305\n[ 85.963119] x23: ffff4bf215b87300 x22: ffff4bf1c85409d0 x21: ffff4bf1c8540970\n[ 85.977382] x20: 0000000000000000 x19: ffff4bf1c8540880 x18: 0000000000000000\n[ 85.977391] x17: 0000000000000000 x16: 0000000000000133 x15: 0000ffffe2217090\n[ 85.977399] x14: 0000000000000001 x13: 0000000000000133 x12: 0000000000000139\n[ 85.977407] x11: 0000000000000001 x10: 0000000000000a60 x9 : ffff8000084fbc50\n[ 85.977417] x8 : ffff4bf215b7d000 x7 : ffff4bf215b83b40 x6 : 00000000000003e8\n[ 85.977424] x5 : 00000000410fd030 x4 : 0000000000000000 x3 : 0000000000000000\n[ 85.977432] x2 : 0000000000000000 x1 : ffff4bf1c4265880 x0 : 0000000000000000\n[ 85.977443] Call trace:\n[ 85.977446] 0xffffd4a61638f258\n[ 85.977451] 0xffffd4a61638f3e8\n[ 85.977455] process_one_work+0x1d4/0x330\n[ 85.977464] worker_thread+0x6c/0x430\n[ 85.977471] kthread+0x108/0x10c\n[ 85.977476] ret_from_fork+0x10/0x20\n[ 85.977488] Code: bad PC value\n[ 85.977491] ---[ end trace 0000000000000000 ]---\n\nPreset since v6.9.11", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-46680", "url": "https://www.suse.com/security/cve/CVE-2024-46680" }, { "category": "external", "summary": "SUSE Bug 1230557 for CVE-2024-46680", "url": "https://bugzilla.suse.com/1230557" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-46680" }, { "cve": "CVE-2024-46681", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-46681" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\npktgen: use cpus_read_lock() in pg_net_init()\n\nI have seen the WARN_ON(smp_processor_id() != cpu) firing\nin pktgen_thread_worker() during tests.\n\nWe must use cpus_read_lock()/cpus_read_unlock()\naround the for_each_online_cpu(cpu) loop.\n\nWhile we are at it use WARN_ON_ONCE() to avoid a possible syslog flood.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-46681", "url": "https://www.suse.com/security/cve/CVE-2024-46681" }, { "category": "external", "summary": "SUSE Bug 1230558 for CVE-2024-46681", "url": "https://bugzilla.suse.com/1230558" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 2.5, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-46681" }, { "cve": "CVE-2024-46765", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-46765" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: protect XDP configuration with a mutex\n\nThe main threat to data consistency in ice_xdp() is a possible asynchronous\nPF reset. It can be triggered by a user or by TX timeout handler.\n\nXDP setup and PF reset code access the same resources in the following\nsections:\n* ice_vsi_close() in ice_prepare_for_reset() - already rtnl-locked\n* ice_vsi_rebuild() for the PF VSI - not protected\n* ice_vsi_open() - already rtnl-locked\n\nWith an unfortunate timing, such accesses can result in a crash such as the\none below:\n\n[ +1.999878] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 14\n[ +2.002992] ice 0000:b1:00.0: Registered XDP mem model MEM_TYPE_XSK_BUFF_POOL on Rx ring 18\n[Mar15 18:17] ice 0000:b1:00.0 ens801f0np0: NETDEV WATCHDOG: CPU: 38: transmit queue 14 timed out 80692736 ms\n[ +0.000093] ice 0000:b1:00.0 ens801f0np0: tx_timeout: VSI_num: 6, Q 14, NTC: 0x0, HW_HEAD: 0x0, NTU: 0x0, INT: 0x4000001\n[ +0.000012] ice 0000:b1:00.0 ens801f0np0: tx_timeout recovery level 1, txqueue 14\n[ +0.394718] ice 0000:b1:00.0: PTP reset successful\n[ +0.006184] BUG: kernel NULL pointer dereference, address: 0000000000000098\n[ +0.000045] #PF: supervisor read access in kernel mode\n[ +0.000023] #PF: error_code(0x0000) - not-present page\n[ +0.000023] PGD 0 P4D 0\n[ +0.000018] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ +0.000023] CPU: 38 PID: 7540 Comm: kworker/38:1 Not tainted 6.8.0-rc7 #1\n[ +0.000031] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0014.082620210524 08/26/2021\n[ +0.000036] Workqueue: ice ice_service_task [ice]\n[ +0.000183] RIP: 0010:ice_clean_tx_ring+0xa/0xd0 [ice]\n[...]\n[ +0.000013] Call Trace:\n[ +0.000016] \u003cTASK\u003e\n[ +0.000014] ? __die+0x1f/0x70\n[ +0.000029] ? page_fault_oops+0x171/0x4f0\n[ +0.000029] ? schedule+0x3b/0xd0\n[ +0.000027] ? exc_page_fault+0x7b/0x180\n[ +0.000022] ? asm_exc_page_fault+0x22/0x30\n[ +0.000031] ? ice_clean_tx_ring+0xa/0xd0 [ice]\n[ +0.000194] ice_free_tx_ring+0xe/0x60 [ice]\n[ +0.000186] ice_destroy_xdp_rings+0x157/0x310 [ice]\n[ +0.000151] ice_vsi_decfg+0x53/0xe0 [ice]\n[ +0.000180] ice_vsi_rebuild+0x239/0x540 [ice]\n[ +0.000186] ice_vsi_rebuild_by_type+0x76/0x180 [ice]\n[ +0.000145] ice_rebuild+0x18c/0x840 [ice]\n[ +0.000145] ? delay_tsc+0x4a/0xc0\n[ +0.000022] ? delay_tsc+0x92/0xc0\n[ +0.000020] ice_do_reset+0x140/0x180 [ice]\n[ +0.000886] ice_service_task+0x404/0x1030 [ice]\n[ +0.000824] process_one_work+0x171/0x340\n[ +0.000685] worker_thread+0x277/0x3a0\n[ +0.000675] ? preempt_count_add+0x6a/0xa0\n[ +0.000677] ? _raw_spin_lock_irqsave+0x23/0x50\n[ +0.000679] ? __pfx_worker_thread+0x10/0x10\n[ +0.000653] kthread+0xf0/0x120\n[ +0.000635] ? __pfx_kthread+0x10/0x10\n[ +0.000616] ret_from_fork+0x2d/0x50\n[ +0.000612] ? __pfx_kthread+0x10/0x10\n[ +0.000604] ret_from_fork_asm+0x1b/0x30\n[ +0.000604] \u003c/TASK\u003e\n\nThe previous way of handling this through returning -EBUSY is not viable,\nparticularly when destroying AF_XDP socket, because the kernel proceeds\nwith removal anyway.\n\nThere is plenty of code between those calls and there is no need to create\na large critical section that covers all of them, same as there is no need\nto protect ice_vsi_rebuild() with rtnl_lock().\n\nAdd xdp_state_lock mutex to protect ice_vsi_rebuild() and ice_xdp().\n\nLeaving unprotected sections in between would result in two states that\nhave to be considered:\n1. when the VSI is closed, but not yet rebuild\n2. when VSI is already rebuild, but not yet open\n\nThe latter case is actually already handled through !netif_running() case,\nwe just need to adjust flag checking a little. The former one is not as\ntrivial, because between ice_vsi_close() and ice_vsi_rebuild(), a lot of\nhardware interaction happens, this can make adding/deleting rings exit\nwith an error. Luckily, VSI rebuild is pending and can apply new\nconfiguration for us in a managed fashion.\n\nTherefore, add an additional VSI state flag ICE_VSI_REBUILD_PENDING to\nindicate that ice_x\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-46765", "url": "https://www.suse.com/security/cve/CVE-2024-46765" }, { "category": "external", "summary": "SUSE Bug 1230807 for CVE-2024-46765", "url": "https://bugzilla.suse.com/1230807" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-46765" }, { "cve": "CVE-2024-46788", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-46788" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/osnoise: Use a cpumask to know what threads are kthreads\n\nThe start_kthread() and stop_thread() code was not always called with the\ninterface_lock held. This means that the kthread variable could be\nunexpectedly changed causing the kthread_stop() to be called on it when it\nshould not have been, leading to:\n\n while true; do\n rtla timerlat top -u -q \u0026 PID=$!;\n sleep 5;\n kill -INT $PID;\n sleep 0.001;\n kill -TERM $PID;\n wait $PID;\n done\n\nCausing the following OOPS:\n\n Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN PTI\n KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n CPU: 5 UID: 0 PID: 885 Comm: timerlatu/5 Not tainted 6.11.0-rc4-test-00002-gbc754cc76d1b-dirty #125 a533010b71dab205ad2f507188ce8c82203b0254\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n RIP: 0010:hrtimer_active+0x58/0x300\n Code: 48 c1 ee 03 41 54 48 01 d1 48 01 d6 55 53 48 83 ec 20 80 39 00 0f 85 30 02 00 00 49 8b 6f 30 4c 8d 75 10 4c 89 f0 48 c1 e8 03 \u003c0f\u003e b6 3c 10 4c 89 f0 83 e0 07 83 c0 03 40 38 f8 7c 09 40 84 ff 0f\n RSP: 0018:ffff88811d97f940 EFLAGS: 00010202\n RAX: 0000000000000002 RBX: ffff88823c6b5b28 RCX: ffffed10478d6b6b\n RDX: dffffc0000000000 RSI: ffffed10478d6b6c RDI: ffff88823c6b5b28\n RBP: 0000000000000000 R08: ffff88823c6b5b58 R09: ffff88823c6b5b60\n R10: ffff88811d97f957 R11: 0000000000000010 R12: 00000000000a801d\n R13: ffff88810d8b35d8 R14: 0000000000000010 R15: ffff88823c6b5b28\n FS: 0000000000000000(0000) GS:ffff88823c680000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000561858ad7258 CR3: 000000007729e001 CR4: 0000000000170ef0\n Call Trace:\n \u003cTASK\u003e\n ? die_addr+0x40/0xa0\n ? exc_general_protection+0x154/0x230\n ? asm_exc_general_protection+0x26/0x30\n ? hrtimer_active+0x58/0x300\n ? __pfx_mutex_lock+0x10/0x10\n ? __pfx_locks_remove_file+0x10/0x10\n hrtimer_cancel+0x15/0x40\n timerlat_fd_release+0x8e/0x1f0\n ? security_file_release+0x43/0x80\n __fput+0x372/0xb10\n task_work_run+0x11e/0x1f0\n ? _raw_spin_lock+0x85/0xe0\n ? __pfx_task_work_run+0x10/0x10\n ? poison_slab_object+0x109/0x170\n ? do_exit+0x7a0/0x24b0\n do_exit+0x7bd/0x24b0\n ? __pfx_migrate_enable+0x10/0x10\n ? __pfx_do_exit+0x10/0x10\n ? __pfx_read_tsc+0x10/0x10\n ? ktime_get+0x64/0x140\n ? _raw_spin_lock_irq+0x86/0xe0\n do_group_exit+0xb0/0x220\n get_signal+0x17ba/0x1b50\n ? vfs_read+0x179/0xa40\n ? timerlat_fd_read+0x30b/0x9d0\n ? __pfx_get_signal+0x10/0x10\n ? __pfx_timerlat_fd_read+0x10/0x10\n arch_do_signal_or_restart+0x8c/0x570\n ? __pfx_arch_do_signal_or_restart+0x10/0x10\n ? vfs_read+0x179/0xa40\n ? ksys_read+0xfe/0x1d0\n ? __pfx_ksys_read+0x10/0x10\n syscall_exit_to_user_mode+0xbc/0x130\n do_syscall_64+0x74/0x110\n ? __pfx___rseq_handle_notify_resume+0x10/0x10\n ? __pfx_ksys_read+0x10/0x10\n ? fpregs_restore_userregs+0xdb/0x1e0\n ? fpregs_restore_userregs+0xdb/0x1e0\n ? syscall_exit_to_user_mode+0x116/0x130\n ? do_syscall_64+0x74/0x110\n ? do_syscall_64+0x74/0x110\n ? do_syscall_64+0x74/0x110\n entry_SYSCALL_64_after_hwframe+0x71/0x79\n RIP: 0033:0x7ff0070eca9c\n Code: Unable to access opcode bytes at 0x7ff0070eca72.\n RSP: 002b:00007ff006dff8c0 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\n RAX: 0000000000000000 RBX: 0000000000000005 RCX: 00007ff0070eca9c\n RDX: 0000000000000400 RSI: 00007ff006dff9a0 RDI: 0000000000000003\n RBP: 00007ff006dffde0 R08: 0000000000000000 R09: 00007ff000000ba0\n R10: 00007ff007004b08 R11: 0000000000000246 R12: 0000000000000003\n R13: 00007ff006dff9a0 R14: 0000000000000007 R15: 0000000000000008\n \u003c/TASK\u003e\n Modules linked in: snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec snd_hwdep snd_hda_core\n ---[ end trace 0000000000000000 ]---\n\nThis is because it would mistakenly call kthread_stop() on a user space\nthread making it \"exit\" before it actually exits.\n\nSince kthread\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-46788", "url": "https://www.suse.com/security/cve/CVE-2024-46788" }, { "category": "external", "summary": "SUSE Bug 1230817 for CVE-2024-46788", "url": "https://bugzilla.suse.com/1230817" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-46788" }, { "cve": "CVE-2024-46800", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-46800" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsch/netem: fix use after free in netem_dequeue\n\nIf netem_dequeue() enqueues packet to inner qdisc and that qdisc\nreturns __NET_XMIT_STOLEN. The packet is dropped but\nqdisc_tree_reduce_backlog() is not called to update the parent\u0027s\nq.qlen, leading to the similar use-after-free as Commit\ne04991a48dbaf382 (\"netem: fix return value if duplicate enqueue\nfails\")\n\nCommands to trigger KASAN UaF:\n\nip link add type dummy\nip link set lo up\nip link set dummy0 up\ntc qdisc add dev lo parent root handle 1: drr\ntc filter add dev lo parent 1: basic classid 1:1\ntc class add dev lo classid 1:1 drr\ntc qdisc add dev lo parent 1:1 handle 2: netem\ntc qdisc add dev lo parent 2: handle 3: drr\ntc filter add dev lo parent 3: basic classid 3:1 action mirred egress\nredirect dev dummy0\ntc class add dev lo classid 3:1 drr\nping -c1 -W0.01 localhost # Trigger bug\ntc class del dev lo classid 1:1\ntc class add dev lo classid 1:1 drr\nping -c1 -W0.01 localhost # UaF", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-46800", "url": "https://www.suse.com/security/cve/CVE-2024-46800" }, { "category": "external", "summary": "SUSE Bug 1230827 for CVE-2024-46800", "url": "https://bugzilla.suse.com/1230827" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-46800" }, { "cve": "CVE-2024-46828", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-46828" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched: sch_cake: fix bulk flow accounting logic for host fairness\n\nIn sch_cake, we keep track of the count of active bulk flows per host,\nwhen running in dst/src host fairness mode, which is used as the\nround-robin weight when iterating through flows. The count of active\nbulk flows is updated whenever a flow changes state.\n\nThis has a peculiar interaction with the hash collision handling: when a\nhash collision occurs (after the set-associative hashing), the state of\nthe hash bucket is simply updated to match the new packet that collided,\nand if host fairness is enabled, that also means assigning new per-host\nstate to the flow. For this reason, the bulk flow counters of the\nhost(s) assigned to the flow are decremented, before new state is\nassigned (and the counters, which may not belong to the same host\nanymore, are incremented again).\n\nBack when this code was introduced, the host fairness mode was always\nenabled, so the decrement was unconditional. When the configuration\nflags were introduced the *increment* was made conditional, but\nthe *decrement* was not. Which of course can lead to a spurious\ndecrement (and associated wrap-around to U16_MAX).\n\nAFAICT, when host fairness is disabled, the decrement and wrap-around\nhappens as soon as a hash collision occurs (which is not that common in\nitself, due to the set-associative hashing). However, in most cases this\nis harmless, as the value is only used when host fairness mode is\nenabled. So in order to trigger an array overflow, sch_cake has to first\nbe configured with host fairness disabled, and while running in this\nmode, a hash collision has to occur to cause the overflow. Then, the\nqdisc has to be reconfigured to enable host fairness, which leads to the\narray out-of-bounds because the wrapped-around value is retained and\nused as an array index. It seems that syzbot managed to trigger this,\nwhich is quite impressive in its own right.\n\nThis patch fixes the issue by introducing the same conditional check on\ndecrement as is used on increment.\n\nThe original bug predates the upstreaming of cake, but the commit listed\nin the Fixes tag touched that code, meaning that this patch won\u0027t apply\nbefore that.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-46828", "url": "https://www.suse.com/security/cve/CVE-2024-46828" }, { "category": "external", "summary": "SUSE Bug 1231114 for CVE-2024-46828", "url": "https://bugzilla.suse.com/1231114" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-46828" }, { "cve": "CVE-2024-46845", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-46845" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Only clear timer if a kthread exists\n\nThe timerlat tracer can use user space threads to check for osnoise and\ntimer latency. If the program using this is killed via a SIGTERM, the\nthreads are shutdown one at a time and another tracing instance can start\nup resetting the threads before they are fully closed. That causes the\nhrtimer assigned to the kthread to be shutdown and freed twice when the\ndying thread finally closes the file descriptors, causing a use-after-free\nbug.\n\nOnly cancel the hrtimer if the associated thread is still around. Also add\nthe interface_lock around the resetting of the tlat_var-\u003ekthread.\n\nNote, this is just a quick fix that can be backported to stable. A real\nfix is to have a better synchronization between the shutdown of old\nthreads and the starting of new ones.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-46845", "url": "https://www.suse.com/security/cve/CVE-2024-46845" }, { "category": "external", "summary": "SUSE Bug 1231076 for CVE-2024-46845", "url": "https://bugzilla.suse.com/1231076" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-46845" }, { "cve": "CVE-2024-47666", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-47666" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: pm80xx: Set phy-\u003eenable_completion only when we wait for it\n\npm8001_phy_control() populates the enable_completion pointer with a stack\naddress, sends a PHY_LINK_RESET / PHY_HARD_RESET, waits 300 ms, and\nreturns. The problem arises when a phy control response comes late. After\n300 ms the pm8001_phy_control() function returns and the passed\nenable_completion stack address is no longer valid. Late phy control\nresponse invokes complete() on a dangling enable_completion pointer which\nleads to a kernel crash.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-47666", "url": "https://www.suse.com/security/cve/CVE-2024-47666" }, { "category": "external", "summary": "SUSE Bug 1231453 for CVE-2024-47666", "url": "https://bugzilla.suse.com/1231453" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-47666" }, { "cve": "CVE-2024-47679", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-47679" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfs: fix race between evice_inodes() and find_inode()\u0026iput()\n\nHi, all\n\nRecently I noticed a bug[1] in btrfs, after digged it into\nand I believe it\u0027a race in vfs.\n\nLet\u0027s assume there\u0027s a inode (ie ino 261) with i_count 1 is\ncalled by iput(), and there\u0027s a concurrent thread calling\ngeneric_shutdown_super().\n\ncpu0: cpu1:\niput() // i_count is 1\n -\u003espin_lock(inode)\n -\u003edec i_count to 0\n -\u003eiput_final() generic_shutdown_super()\n -\u003e__inode_add_lru() -\u003eevict_inodes()\n // cause some reason[2] -\u003eif (atomic_read(inode-\u003ei_count)) continue;\n // return before // inode 261 passed the above check\n // list_lru_add_obj() // and then schedule out\n -\u003espin_unlock()\n// note here: the inode 261\n// was still at sb list and hash list,\n// and I_FREEING|I_WILL_FREE was not been set\n\nbtrfs_iget()\n // after some function calls\n -\u003efind_inode()\n // found the above inode 261\n -\u003espin_lock(inode)\n // check I_FREEING|I_WILL_FREE\n // and passed\n -\u003e__iget()\n -\u003espin_unlock(inode) // schedule back\n -\u003espin_lock(inode)\n // check (I_NEW|I_FREEING|I_WILL_FREE) flags,\n // passed and set I_FREEING\niput() -\u003espin_unlock(inode)\n -\u003espin_lock(inode)\t\t\t -\u003eevict()\n // dec i_count to 0\n -\u003eiput_final()\n -\u003espin_unlock()\n -\u003eevict()\n\nNow, we have two threads simultaneously evicting\nthe same inode, which may trigger the BUG(inode-\u003ei_state \u0026 I_CLEAR)\nstatement both within clear_inode() and iput().\n\nTo fix the bug, recheck the inode-\u003ei_count after holding i_lock.\nBecause in the most scenarios, the first check is valid, and\nthe overhead of spin_lock() can be reduced.\n\nIf there is any misunderstanding, please let me know, thanks.\n\n[1]: https://lore.kernel.org/linux-btrfs/000000000000eabe1d0619c48986@google.com/\n[2]: The reason might be 1. SB_ACTIVE was removed or 2. mapping_shrinkable()\nreturn false when I reproduced the bug.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-47679", "url": "https://www.suse.com/security/cve/CVE-2024-47679" }, { "category": "external", "summary": "SUSE Bug 1231930 for CVE-2024-47679", "url": "https://bugzilla.suse.com/1231930" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-47679" }, { "cve": "CVE-2024-47701", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-47701" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid OOB when system.data xattr changes underneath the filesystem\n\nWhen looking up for an entry in an inlined directory, if e_value_offs is\nchanged underneath the filesystem by some change in the block device, it\nwill lead to an out-of-bounds access that KASAN detects as an UAF.\n\nEXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 r/w without journal. Quota mode: none.\nloop0: detected capacity change from 2048 to 2047\n==================================================================\nBUG: KASAN: use-after-free in ext4_search_dir+0xf2/0x1c0 fs/ext4/namei.c:1500\nRead of size 1 at addr ffff88803e91130f by task syz-executor269/5103\n\nCPU: 0 UID: 0 PID: 5103 Comm: syz-executor269 Not tainted 6.11.0-rc4-syzkaller #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n ext4_search_dir+0xf2/0x1c0 fs/ext4/namei.c:1500\n ext4_find_inline_entry+0x4be/0x5e0 fs/ext4/inline.c:1697\n __ext4_find_entry+0x2b4/0x1b30 fs/ext4/namei.c:1573\n ext4_lookup_entry fs/ext4/namei.c:1727 [inline]\n ext4_lookup+0x15f/0x750 fs/ext4/namei.c:1795\n lookup_one_qstr_excl+0x11f/0x260 fs/namei.c:1633\n filename_create+0x297/0x540 fs/namei.c:3980\n do_symlinkat+0xf9/0x3a0 fs/namei.c:4587\n __do_sys_symlinkat fs/namei.c:4610 [inline]\n __se_sys_symlinkat fs/namei.c:4607 [inline]\n __x64_sys_symlinkat+0x95/0xb0 fs/namei.c:4607\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f3e73ced469\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 21 18 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fff4d40c258 EFLAGS: 00000246 ORIG_RAX: 000000000000010a\nRAX: ffffffffffffffda RBX: 0032656c69662f2e RCX: 00007f3e73ced469\nRDX: 0000000020000200 RSI: 00000000ffffff9c RDI: 00000000200001c0\nRBP: 0000000000000000 R08: 00007fff4d40c290 R09: 00007fff4d40c290\nR10: 0023706f6f6c2f76 R11: 0000000000000246 R12: 00007fff4d40c27c\nR13: 0000000000000003 R14: 431bde82d7b634db R15: 00007fff4d40c2b0\n \u003c/TASK\u003e\n\nCalling ext4_xattr_ibody_find right after reading the inode with\next4_get_inode_loc will lead to a check of the validity of the xattrs,\navoiding this problem.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-47701", "url": "https://www.suse.com/security/cve/CVE-2024-47701" }, { "category": "external", "summary": "SUSE Bug 1225742 for CVE-2024-47701", "url": "https://bugzilla.suse.com/1225742" }, { "category": "external", "summary": "SUSE Bug 1231920 for CVE-2024-47701", "url": "https://bugzilla.suse.com/1231920" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-47701" }, { "cve": "CVE-2024-47703", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-47703" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, lsm: Add check for BPF LSM return value\n\nA bpf prog returning a positive number attached to file_alloc_security\nhook makes kernel panic.\n\nThis happens because file system can not filter out the positive number\nreturned by the LSM prog using IS_ERR, and misinterprets this positive\nnumber as a file pointer.\n\nGiven that hook file_alloc_security never returned positive number\nbefore the introduction of BPF LSM, and other BPF LSM hooks may\nencounter similar issues, this patch adds LSM return value check\nin verifier, to ensure no unexpected value is returned.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-47703", "url": "https://www.suse.com/security/cve/CVE-2024-47703" }, { "category": "external", "summary": "SUSE Bug 1231946 for CVE-2024-47703", "url": "https://bugzilla.suse.com/1231946" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-47703" }, { "cve": "CVE-2024-49868", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49868" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix a NULL pointer dereference when failed to start a new trasacntion\n\n[BUG]\nSyzbot reported a NULL pointer dereference with the following crash:\n\n FAULT_INJECTION: forcing a failure.\n start_transaction+0x830/0x1670 fs/btrfs/transaction.c:676\n prepare_to_relocate+0x31f/0x4c0 fs/btrfs/relocation.c:3642\n relocate_block_group+0x169/0xd20 fs/btrfs/relocation.c:3678\n ...\n BTRFS info (device loop0): balance: ended with status: -12\n Oops: general protection fault, probably for non-canonical address 0xdffffc00000000cc: 0000 [#1] PREEMPT SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000660-0x0000000000000667]\n RIP: 0010:btrfs_update_reloc_root+0x362/0xa80 fs/btrfs/relocation.c:926\n Call Trace:\n \u003cTASK\u003e\n commit_fs_roots+0x2ee/0x720 fs/btrfs/transaction.c:1496\n btrfs_commit_transaction+0xfaf/0x3740 fs/btrfs/transaction.c:2430\n del_balance_item fs/btrfs/volumes.c:3678 [inline]\n reset_balance_state+0x25e/0x3c0 fs/btrfs/volumes.c:3742\n btrfs_balance+0xead/0x10c0 fs/btrfs/volumes.c:4574\n btrfs_ioctl_balance+0x493/0x7c0 fs/btrfs/ioctl.c:3673\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:907 [inline]\n __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n[CAUSE]\nThe allocation failure happens at the start_transaction() inside\nprepare_to_relocate(), and during the error handling we call\nunset_reloc_control(), which makes fs_info-\u003ebalance_ctl to be NULL.\n\nThen we continue the error path cleanup in btrfs_balance() by calling\nreset_balance_state() which will call del_balance_item() to fully delete\nthe balance item in the root tree.\n\nHowever during the small window between set_reloc_contrl() and\nunset_reloc_control(), we can have a subvolume tree update and created a\nreloc_root for that subvolume.\n\nThen we go into the final btrfs_commit_transaction() of\ndel_balance_item(), and into btrfs_update_reloc_root() inside\ncommit_fs_roots().\n\nThat function checks if fs_info-\u003ereloc_ctl is in the merge_reloc_tree\nstage, but since fs_info-\u003ereloc_ctl is NULL, it results a NULL pointer\ndereference.\n\n[FIX]\nJust add extra check on fs_info-\u003ereloc_ctl inside\nbtrfs_update_reloc_root(), before checking\nfs_info-\u003ereloc_ctl-\u003emerge_reloc_tree.\n\nThat DEAD_RELOC_TREE handling is to prevent further modification to the\nreloc tree during merge stage, but since there is no reloc_ctl at all,\nwe do not need to bother that.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49868", "url": "https://www.suse.com/security/cve/CVE-2024-49868" }, { "category": "external", "summary": "SUSE Bug 1232272 for CVE-2024-49868", "url": "https://bugzilla.suse.com/1232272" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49868" }, { "cve": "CVE-2024-49884", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49884" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix slab-use-after-free in ext4_split_extent_at()\n\nWe hit the following use-after-free:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in ext4_split_extent_at+0xba8/0xcc0\nRead of size 2 at addr ffff88810548ed08 by task kworker/u20:0/40\nCPU: 0 PID: 40 Comm: kworker/u20:0 Not tainted 6.9.0-dirty #724\nCall Trace:\n \u003cTASK\u003e\n kasan_report+0x93/0xc0\n ext4_split_extent_at+0xba8/0xcc0\n ext4_split_extent.isra.0+0x18f/0x500\n ext4_split_convert_extents+0x275/0x750\n ext4_ext_handle_unwritten_extents+0x73e/0x1580\n ext4_ext_map_blocks+0xe20/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n\nAllocated by task 40:\n __kmalloc_noprof+0x1ac/0x480\n ext4_find_extent+0xf3b/0x1e70\n ext4_ext_map_blocks+0x188/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n\nFreed by task 40:\n kfree+0xf1/0x2b0\n ext4_find_extent+0xa71/0x1e70\n ext4_ext_insert_extent+0xa22/0x3260\n ext4_split_extent_at+0x3ef/0xcc0\n ext4_split_extent.isra.0+0x18f/0x500\n ext4_split_convert_extents+0x275/0x750\n ext4_ext_handle_unwritten_extents+0x73e/0x1580\n ext4_ext_map_blocks+0xe20/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n==================================================================\n\nThe flow of issue triggering is as follows:\n\next4_split_extent_at\n path = *ppath\n ext4_ext_insert_extent(ppath)\n ext4_ext_create_new_leaf(ppath)\n ext4_find_extent(orig_path)\n path = *orig_path\n read_extent_tree_block\n // return -ENOMEM or -EIO\n ext4_free_ext_path(path)\n kfree(path)\n *orig_path = NULL\n a. If err is -ENOMEM:\n ext4_ext_dirty(path + path-\u003ep_depth)\n // path use-after-free !!!\n b. If err is -EIO and we have EXT_DEBUG defined:\n ext4_ext_show_leaf(path)\n eh = path[depth].p_hdr\n // path also use-after-free !!!\n\nSo when trying to zeroout or fix the extent length, call ext4_find_extent()\nto update the path.\n\nIn addition we use *ppath directly as an ext4_ext_show_leaf() input to\navoid possible use-after-free when EXT_DEBUG is defined, and to avoid\nunnecessary path updates.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49884", "url": "https://www.suse.com/security/cve/CVE-2024-49884" }, { "category": "external", "summary": "SUSE Bug 1225742 for CVE-2024-49884", "url": "https://bugzilla.suse.com/1225742" }, { "category": "external", "summary": "SUSE Bug 1232198 for CVE-2024-49884", "url": "https://bugzilla.suse.com/1232198" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49884" }, { "cve": "CVE-2024-49888", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49888" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a sdiv overflow issue\n\nZac Ecob reported a problem where a bpf program may cause kernel crash due\nto the following error:\n Oops: divide error: 0000 [#1] PREEMPT SMP KASAN PTI\n\nThe failure is due to the below signed divide:\n LLONG_MIN/-1 where LLONG_MIN equals to -9,223,372,036,854,775,808.\nLLONG_MIN/-1 is supposed to give a positive number 9,223,372,036,854,775,808,\nbut it is impossible since for 64-bit system, the maximum positive\nnumber is 9,223,372,036,854,775,807. On x86_64, LLONG_MIN/-1 will\ncause a kernel exception. On arm64, the result for LLONG_MIN/-1 is\nLLONG_MIN.\n\nFurther investigation found all the following sdiv/smod cases may trigger\nan exception when bpf program is running on x86_64 platform:\n - LLONG_MIN/-1 for 64bit operation\n - INT_MIN/-1 for 32bit operation\n - LLONG_MIN%-1 for 64bit operation\n - INT_MIN%-1 for 32bit operation\nwhere -1 can be an immediate or in a register.\n\nOn arm64, there are no exceptions:\n - LLONG_MIN/-1 = LLONG_MIN\n - INT_MIN/-1 = INT_MIN\n - LLONG_MIN%-1 = 0\n - INT_MIN%-1 = 0\nwhere -1 can be an immediate or in a register.\n\nInsn patching is needed to handle the above cases and the patched codes\nproduced results aligned with above arm64 result. The below are pseudo\ncodes to handle sdiv/smod exceptions including both divisor -1 and divisor 0\nand the divisor is stored in a register.\n\nsdiv:\n tmp = rX\n tmp += 1 /* [-1, 0] -\u003e [0, 1]\n if tmp \u003e(unsigned) 1 goto L2\n if tmp == 0 goto L1\n rY = 0\n L1:\n rY = -rY;\n goto L3\n L2:\n rY /= rX\n L3:\n\nsmod:\n tmp = rX\n tmp += 1 /* [-1, 0] -\u003e [0, 1]\n if tmp \u003e(unsigned) 1 goto L1\n if tmp == 1 (is64 ? goto L2 : goto L3)\n rY = 0;\n goto L2\n L1:\n rY %= rX\n L2:\n goto L4 // only when !is64\n L3:\n wY = wY // only when !is64\n L4:\n\n [1] https://lore.kernel.org/bpf/tPJLTEh7S_DxFEqAI2Ji5MBSoZVg7_G-Py2iaZpAaWtM961fFTWtsnlzwvTbzBzaUzwQAoNATXKUlt0LZOFgnDcIyKCswAnAGdUF3LBrhGQ=@protonmail.com/", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49888", "url": "https://www.suse.com/security/cve/CVE-2024-49888" }, { "category": "external", "summary": "SUSE Bug 1232208 for CVE-2024-49888", "url": "https://bugzilla.suse.com/1232208" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49888" }, { "cve": "CVE-2024-49899", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49899" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Initialize denominators\u0027 default to 1\n\n[WHAT \u0026 HOW]\nVariables used as denominators and maybe not assigned to other values,\nshould not be 0. Change their default to 1 so they are never 0.\n\nThis fixes 10 DIVIDE_BY_ZERO issues reported by Coverity.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49899", "url": "https://www.suse.com/security/cve/CVE-2024-49899" }, { "category": "external", "summary": "SUSE Bug 1232358 for CVE-2024-49899", "url": "https://bugzilla.suse.com/1232358" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49899" }, { "cve": "CVE-2024-49905", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49905" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for \u0027afb\u0027 in amdgpu_dm_plane_handle_cursor_update (v2)\n\nThis commit adds a null check for the \u0027afb\u0027 variable in the\namdgpu_dm_plane_handle_cursor_update function. Previously, \u0027afb\u0027 was\nassumed to be null, but was used later in the code without a null check.\nThis could potentially lead to a null pointer dereference.\n\nChanges since v1:\n- Moved the null check for \u0027afb\u0027 to the line where \u0027afb\u0027 is used. (Alex)\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_plane.c:1298 amdgpu_dm_plane_handle_cursor_update() error: we previously assumed \u0027afb\u0027 could be null (see line 1252)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49905", "url": "https://www.suse.com/security/cve/CVE-2024-49905" }, { "category": "external", "summary": "SUSE Bug 1232357 for CVE-2024-49905", "url": "https://bugzilla.suse.com/1232357" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49905" }, { "cve": "CVE-2024-49908", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49908" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for \u0027afb\u0027 in amdgpu_dm_update_cursor (v2)\n\nThis commit adds a null check for the \u0027afb\u0027 variable in the\namdgpu_dm_update_cursor function. Previously, \u0027afb\u0027 was assumed to be\nnull at line 8388, but was used later in the code without a null check.\nThis could potentially lead to a null pointer dereference.\n\nChanges since v1:\n- Moved the null check for \u0027afb\u0027 to the line where \u0027afb\u0027 is used. (Alex)\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm.c:8433 amdgpu_dm_update_cursor()\n\terror: we previously assumed \u0027afb\u0027 could be null (see line 8388)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49908", "url": "https://www.suse.com/security/cve/CVE-2024-49908" }, { "category": "external", "summary": "SUSE Bug 1232335 for CVE-2024-49908", "url": "https://bugzilla.suse.com/1232335" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49908" }, { "cve": "CVE-2024-49911", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49911" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func\n\nThis commit adds a null check for the set_output_gamma function pointer\nin the dcn20_set_output_transfer_func function. Previously,\nset_output_gamma was being checked for null at line 1030, but then it\nwas being dereferenced without any null check at line 1048. This could\npotentially lead to a null pointer dereference error if set_output_gamma\nis null.\n\nTo fix this, we now ensure that set_output_gamma is not null before\ndereferencing it. We do this by adding a null check for set_output_gamma\nbefore the call to set_output_gamma at line 1048.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49911", "url": "https://www.suse.com/security/cve/CVE-2024-49911" }, { "category": "external", "summary": "SUSE Bug 1232366 for CVE-2024-49911", "url": "https://bugzilla.suse.com/1232366" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49911" }, { "cve": "CVE-2024-49912", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49912" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Handle null \u0027stream_status\u0027 in \u0027planes_changed_for_existing_stream\u0027\n\nThis commit adds a null check for \u0027stream_status\u0027 in the function\n\u0027planes_changed_for_existing_stream\u0027. Previously, the code assumed\n\u0027stream_status\u0027 could be null, but did not handle the case where it was\nactually null. This could lead to a null pointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/core/dc_resource.c:3784 planes_changed_for_existing_stream() error: we previously assumed \u0027stream_status\u0027 could be null (see line 3774)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49912", "url": "https://www.suse.com/security/cve/CVE-2024-49912" }, { "category": "external", "summary": "SUSE Bug 1232367 for CVE-2024-49912", "url": "https://bugzilla.suse.com/1232367" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49912" }, { "cve": "CVE-2024-49921", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49921" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before used\n\n[WHAT \u0026 HOW]\nPoniters, such as dc-\u003eclk_mgr, are null checked previously in the same\nfunction, so Coverity warns \"implies that \"dc-\u003eclk_mgr\" might be null\".\nAs a result, these pointers need to be checked when used again.\n\nThis fixes 10 FORWARD_NULL issues reported by Coverity.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49921", "url": "https://www.suse.com/security/cve/CVE-2024-49921" }, { "category": "external", "summary": "SUSE Bug 1232371 for CVE-2024-49921", "url": "https://bugzilla.suse.com/1232371" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49921" }, { "cve": "CVE-2024-49922", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49922" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before using them\n\n[WHAT \u0026 HOW]\nThese pointers are null checked previously in the same function,\nindicating they might be null as reported by Coverity. As a result,\nthey need to be checked when used again.\n\nThis fixes 3 FORWARD_NULL issue reported by Coverity.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49922", "url": "https://www.suse.com/security/cve/CVE-2024-49922" }, { "category": "external", "summary": "SUSE Bug 1232374 for CVE-2024-49922", "url": "https://bugzilla.suse.com/1232374" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49922" }, { "cve": "CVE-2024-49923", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49923" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags\n\n[WHAT \u0026 HOW]\n\"dcn20_validate_apply_pipe_split_flags\" dereferences merge, and thus it\ncannot be a null pointer. Let\u0027s pass a valid pointer to avoid null\ndereference.\n\nThis fixes 2 FORWARD_NULL issues reported by Coverity.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49923", "url": "https://www.suse.com/security/cve/CVE-2024-49923" }, { "category": "external", "summary": "SUSE Bug 1232361 for CVE-2024-49923", "url": "https://bugzilla.suse.com/1232361" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49923" }, { "cve": "CVE-2024-49925", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49925" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: efifb: Register sysfs groups through driver core\n\nThe driver core can register and cleanup sysfs groups already.\nMake use of that functionality to simplify the error handling and\ncleanup.\n\nAlso avoid a UAF race during unregistering where the sysctl attributes\nwere usable after the info struct was freed.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49925", "url": "https://www.suse.com/security/cve/CVE-2024-49925" }, { "category": "external", "summary": "SUSE Bug 1232224 for CVE-2024-49925", "url": "https://bugzilla.suse.com/1232224" }, { "category": "external", "summary": "SUSE Bug 1232225 for CVE-2024-49925", "url": "https://bugzilla.suse.com/1232225" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49925" }, { "cve": "CVE-2024-49933", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49933" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk_iocost: fix more out of bound shifts\n\nRecently running UBSAN caught few out of bound shifts in the\nioc_forgive_debts() function:\n\nUBSAN: shift-out-of-bounds in block/blk-iocost.c:2142:38\nshift exponent 80 is too large for 64-bit type \u0027u64\u0027 (aka \u0027unsigned long\nlong\u0027)\n...\nUBSAN: shift-out-of-bounds in block/blk-iocost.c:2144:30\nshift exponent 80 is too large for 64-bit type \u0027u64\u0027 (aka \u0027unsigned long\nlong\u0027)\n...\nCall Trace:\n\u003cIRQ\u003e\ndump_stack_lvl+0xca/0x130\n__ubsan_handle_shift_out_of_bounds+0x22c/0x280\n? __lock_acquire+0x6441/0x7c10\nioc_timer_fn+0x6cec/0x7750\n? blk_iocost_init+0x720/0x720\n? call_timer_fn+0x5d/0x470\ncall_timer_fn+0xfa/0x470\n? blk_iocost_init+0x720/0x720\n__run_timer_base+0x519/0x700\n...\n\nActual impact of this issue was not identified but I propose to fix the\nundefined behaviour.\nThe proposed fix to prevent those out of bound shifts consist of\nprecalculating exponent before using it the shift operations by taking\nmin value from the actual exponent and maximum possible number of bits.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49933", "url": "https://www.suse.com/security/cve/CVE-2024-49933" }, { "category": "external", "summary": "SUSE Bug 1232368 for CVE-2024-49933", "url": "https://bugzilla.suse.com/1232368" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49933" }, { "cve": "CVE-2024-49934", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49934" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/inode: Prevent dump_mapping() accessing invalid dentry.d_name.name\n\nIt\u0027s observed that a crash occurs during hot-remove a memory device,\nin which user is accessing the hugetlb. See calltrace as following:\n\n------------[ cut here ]------------\nWARNING: CPU: 1 PID: 14045 at arch/x86/mm/fault.c:1278 do_user_addr_fault+0x2a0/0x790\nModules linked in: kmem device_dax cxl_mem cxl_pmem cxl_port cxl_pci dax_hmem dax_pmem nd_pmem cxl_acpi nd_btt cxl_core crc32c_intel nvme virtiofs fuse nvme_core nfit libnvdimm dm_multipath scsi_dh_rdac scsi_dh_emc s\nmirror dm_region_hash dm_log dm_mod\nCPU: 1 PID: 14045 Comm: daxctl Not tainted 6.10.0-rc2-lizhijian+ #492\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\nRIP: 0010:do_user_addr_fault+0x2a0/0x790\nCode: 48 8b 00 a8 04 0f 84 b5 fe ff ff e9 1c ff ff ff 4c 89 e9 4c 89 e2 be 01 00 00 00 bf 02 00 00 00 e8 b5 ef 24 00 e9 42 fe ff ff \u003c0f\u003e 0b 48 83 c4 08 4c 89 ea 48 89 ee 4c 89 e7 5b 5d 41 5c 41 5d 41\nRSP: 0000:ffffc90000a575f0 EFLAGS: 00010046\nRAX: ffff88800c303600 RBX: 0000000000000000 RCX: 0000000000000000\nRDX: 0000000000001000 RSI: ffffffff82504162 RDI: ffffffff824b2c36\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: ffffc90000a57658\nR13: 0000000000001000 R14: ffff88800bc2e040 R15: 0000000000000000\nFS: 00007f51cb57d880(0000) GS:ffff88807fd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000001000 CR3: 00000000072e2004 CR4: 00000000001706f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \u003cTASK\u003e\n ? __warn+0x8d/0x190\n ? do_user_addr_fault+0x2a0/0x790\n ? report_bug+0x1c3/0x1d0\n ? handle_bug+0x3c/0x70\n ? exc_invalid_op+0x14/0x70\n ? asm_exc_invalid_op+0x16/0x20\n ? do_user_addr_fault+0x2a0/0x790\n ? exc_page_fault+0x31/0x200\n exc_page_fault+0x68/0x200\n\u003c...snip...\u003e\nBUG: unable to handle page fault for address: 0000000000001000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 800000000ad92067 P4D 800000000ad92067 PUD 7677067 PMD 0\n Oops: Oops: 0000 [#1] PREEMPT SMP PTI\n ---[ end trace 0000000000000000 ]---\n BUG: unable to handle page fault for address: 0000000000001000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 800000000ad92067 P4D 800000000ad92067 PUD 7677067 PMD 0\n Oops: Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 1 PID: 14045 Comm: daxctl Kdump: loaded Tainted: G W 6.10.0-rc2-lizhijian+ #492\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n RIP: 0010:dentry_name+0x1f4/0x440\n\u003c...snip...\u003e\n? dentry_name+0x2fa/0x440\nvsnprintf+0x1f3/0x4f0\nvprintk_store+0x23a/0x540\nvprintk_emit+0x6d/0x330\n_printk+0x58/0x80\ndump_mapping+0x10b/0x1a0\n? __pfx_free_object_rcu+0x10/0x10\n__dump_page+0x26b/0x3e0\n? vprintk_emit+0xe0/0x330\n? _printk+0x58/0x80\n? dump_page+0x17/0x50\ndump_page+0x17/0x50\ndo_migrate_range+0x2f7/0x7f0\n? do_migrate_range+0x42/0x7f0\n? offline_pages+0x2f4/0x8c0\noffline_pages+0x60a/0x8c0\nmemory_subsys_offline+0x9f/0x1c0\n? lockdep_hardirqs_on+0x77/0x100\n? _raw_spin_unlock_irqrestore+0x38/0x60\ndevice_offline+0xe3/0x110\nstate_store+0x6e/0xc0\nkernfs_fop_write_iter+0x143/0x200\nvfs_write+0x39f/0x560\nksys_write+0x65/0xf0\ndo_syscall_64+0x62/0x130\n\nPreviously, some sanity check have been done in dump_mapping() before\nthe print facility parsing \u0027%pd\u0027 though, it\u0027s still possible to run into\nan invalid dentry.d_name.name.\n\nSince dump_mapping() only needs to dump the filename only, retrieve it\nby itself in a safer way to prevent an unnecessary crash.\n\nNote that either retrieving the filename with \u0027%pd\u0027 or\nstrncpy_from_kernel_nofault(), the filename could be unreliable.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49934", "url": "https://www.suse.com/security/cve/CVE-2024-49934" }, { "category": "external", "summary": "SUSE Bug 1232387 for CVE-2024-49934", "url": "https://bugzilla.suse.com/1232387" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.2, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49934" }, { "cve": "CVE-2024-49944", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49944" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start\n\nIn sctp_listen_start() invoked by sctp_inet_listen(), it should set the\nsk_state back to CLOSED if sctp_autobind() fails due to whatever reason.\n\nOtherwise, next time when calling sctp_inet_listen(), if sctp_sk(sk)-\u003ereuse\nis already set via setsockopt(SCTP_REUSE_PORT), sctp_sk(sk)-\u003ebind_hash will\nbe dereferenced as sk_state is LISTENING, which causes a crash as bind_hash\nis NULL.\n\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n RIP: 0010:sctp_inet_listen+0x7f0/0xa20 net/sctp/socket.c:8617\n Call Trace:\n \u003cTASK\u003e\n __sys_listen_socket net/socket.c:1883 [inline]\n __sys_listen+0x1b7/0x230 net/socket.c:1894\n __do_sys_listen net/socket.c:1902 [inline]", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49944", "url": "https://www.suse.com/security/cve/CVE-2024-49944" }, { "category": "external", "summary": "SUSE Bug 1232166 for CVE-2024-49944", "url": "https://bugzilla.suse.com/1232166" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49944" }, { "cve": "CVE-2024-49945", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49945" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ncsi: Disable the ncsi work before freeing the associated structure\n\nThe work function can run after the ncsi device is freed, resulting\nin use-after-free bugs or kernel panic.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49945", "url": "https://www.suse.com/security/cve/CVE-2024-49945" }, { "category": "external", "summary": "SUSE Bug 1232165 for CVE-2024-49945", "url": "https://bugzilla.suse.com/1232165" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49945" }, { "cve": "CVE-2024-49952", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49952" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: prevent nf_skb_duplicated corruption\n\nsyzbot found that nf_dup_ipv4() or nf_dup_ipv6() could write\nper-cpu variable nf_skb_duplicated in an unsafe way [1].\n\nDisabling preemption as hinted by the splat is not enough,\nwe have to disable soft interrupts as well.\n\n[1]\nBUG: using __this_cpu_write() in preemptible [00000000] code: syz.4.282/6316\n caller is nf_dup_ipv4+0x651/0x8f0 net/ipv4/netfilter/nf_dup_ipv4.c:87\nCPU: 0 UID: 0 PID: 6316 Comm: syz.4.282 Not tainted 6.11.0-rc7-syzkaller-00104-g7052622fccb1 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n check_preemption_disabled+0x10e/0x120 lib/smp_processor_id.c:49\n nf_dup_ipv4+0x651/0x8f0 net/ipv4/netfilter/nf_dup_ipv4.c:87\n nft_dup_ipv4_eval+0x1db/0x300 net/ipv4/netfilter/nft_dup_ipv4.c:30\n expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]\n nft_do_chain+0x4ad/0x1da0 net/netfilter/nf_tables_core.c:288\n nft_do_chain_ipv4+0x202/0x320 net/netfilter/nft_chain_filter.c:23\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xc3/0x220 net/netfilter/core.c:626\n nf_hook+0x2c4/0x450 include/linux/netfilter.h:269\n NF_HOOK_COND include/linux/netfilter.h:302 [inline]\n ip_output+0x185/0x230 net/ipv4/ip_output.c:433\n ip_local_out net/ipv4/ip_output.c:129 [inline]\n ip_send_skb+0x74/0x100 net/ipv4/ip_output.c:1495\n udp_send_skb+0xacf/0x1650 net/ipv4/udp.c:981\n udp_sendmsg+0x1c21/0x2a60 net/ipv4/udp.c:1269\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2597\n ___sys_sendmsg net/socket.c:2651 [inline]\n __sys_sendmmsg+0x3b2/0x740 net/socket.c:2737\n __do_sys_sendmmsg net/socket.c:2766 [inline]\n __se_sys_sendmmsg net/socket.c:2763 [inline]\n __x64_sys_sendmmsg+0xa0/0xb0 net/socket.c:2763\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f4ce4f7def9\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f4ce5d4a038 EFLAGS: 00000246 ORIG_RAX: 0000000000000133\nRAX: ffffffffffffffda RBX: 00007f4ce5135f80 RCX: 00007f4ce4f7def9\nRDX: 0000000000000001 RSI: 0000000020005d40 RDI: 0000000000000006\nRBP: 00007f4ce4ff0b76 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 00007f4ce5135f80 R15: 00007ffd4cbc6d68\n \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49952", "url": "https://www.suse.com/security/cve/CVE-2024-49952" }, { "category": "external", "summary": "SUSE Bug 1232157 for CVE-2024-49952", "url": "https://bugzilla.suse.com/1232157" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49952" }, { "cve": "CVE-2024-49968", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49968" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: filesystems without casefold feature cannot be mounted with siphash\n\nWhen mounting the ext4 filesystem, if the default hash version is set to\nDX_HASH_SIPHASH but the casefold feature is not set, exit the mounting.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49968", "url": "https://www.suse.com/security/cve/CVE-2024-49968" }, { "category": "external", "summary": "SUSE Bug 1232264 for CVE-2024-49968", "url": "https://bugzilla.suse.com/1232264" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49968" }, { "cve": "CVE-2024-49975", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49975" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nuprobes: fix kernel info leak via \"[uprobes]\" vma\n\nxol_add_vma() maps the uninitialized page allocated by __create_xol_area()\ninto userspace. On some architectures (x86) this memory is readable even\nwithout VM_READ, VM_EXEC results in the same pgprot_t as VM_EXEC|VM_READ,\nalthough this doesn\u0027t really matter, debugger can read this memory anyway.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49975", "url": "https://www.suse.com/security/cve/CVE-2024-49975" }, { "category": "external", "summary": "SUSE Bug 1232104 for CVE-2024-49975", "url": "https://bugzilla.suse.com/1232104" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49975" }, { "cve": "CVE-2024-49976", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49976" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Drop interface_lock in stop_kthread()\n\nstop_kthread() is the offline callback for \"trace/osnoise:online\", since\ncommit 5bfbcd1ee57b (\"tracing/timerlat: Add interface_lock around clearing\nof kthread in stop_kthread()\"), the following ABBA deadlock scenario is\nintroduced:\n\nT1 | T2 [BP] | T3 [AP]\nosnoise_hotplug_workfn() | work_for_cpu_fn() | cpuhp_thread_fun()\n | _cpu_down() | osnoise_cpu_die()\n mutex_lock(\u0026interface_lock) | | stop_kthread()\n | cpus_write_lock() | mutex_lock(\u0026interface_lock)\n cpus_read_lock() | cpuhp_kick_ap() |\n\nAs the interface_lock here in just for protecting the \"kthread\" field of\nthe osn_var, use xchg() instead to fix this issue. Also use\nfor_each_online_cpu() back in stop_per_cpu_kthreads() as it can take\ncpu_read_lock() again.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49976", "url": "https://www.suse.com/security/cve/CVE-2024-49976" }, { "category": "external", "summary": "SUSE Bug 1232103 for CVE-2024-49976", "url": "https://bugzilla.suse.com/1232103" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49976" }, { "cve": "CVE-2024-49983", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49983" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: drop ppath from ext4_ext_replay_update_ex() to avoid double-free\n\nWhen calling ext4_force_split_extent_at() in ext4_ext_replay_update_ex(),\nthe \u0027ppath\u0027 is updated but it is the \u0027path\u0027 that is freed, thus potentially\ntriggering a double-free in the following process:\n\next4_ext_replay_update_ex\n ppath = path\n ext4_force_split_extent_at(\u0026ppath)\n ext4_split_extent_at\n ext4_ext_insert_extent\n ext4_ext_create_new_leaf\n ext4_ext_grow_indepth\n ext4_find_extent\n if (depth \u003e path[0].p_maxdepth)\n kfree(path) ---\u003e path First freed\n *orig_path = path = NULL ---\u003e null ppath\n kfree(path) ---\u003e path double-free !!!\n\nSo drop the unnecessary ppath and use path directly to avoid this problem.\nAnd use ext4_find_extent() directly to update path, avoiding unnecessary\nmemory allocation and freeing. Also, propagate the error returned by\next4_find_extent() instead of using strange error codes.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49983", "url": "https://www.suse.com/security/cve/CVE-2024-49983" }, { "category": "external", "summary": "SUSE Bug 1232096 for CVE-2024-49983", "url": "https://bugzilla.suse.com/1232096" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49983" }, { "cve": "CVE-2024-49987", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49987" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpftool: Fix undefined behavior in qsort(NULL, 0, ...)\n\nWhen netfilter has no entry to display, qsort is called with\nqsort(NULL, 0, ...). This results in undefined behavior, as UBSan\nreports:\n\nnet.c:827:2: runtime error: null pointer passed as argument 1, which is declared to never be null\n\nAlthough the C standard does not explicitly state whether calling qsort\nwith a NULL pointer when the size is 0 constitutes undefined behavior,\nSection 7.1.4 of the C standard (Use of library functions) mentions:\n\n\"Each of the following statements applies unless explicitly stated\notherwise in the detailed descriptions that follow: If an argument to a\nfunction has an invalid value (such as a value outside the domain of\nthe function, or a pointer outside the address space of the program, or\na null pointer, or a pointer to non-modifiable storage when the\ncorresponding parameter is not const-qualified) or a type (after\npromotion) not expected by a function with variable number of\narguments, the behavior is undefined.\"\n\nTo avoid this, add an early return when nf_link_info is NULL to prevent\ncalling qsort with a NULL pointer.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49987", "url": "https://www.suse.com/security/cve/CVE-2024-49987" }, { "category": "external", "summary": "SUSE Bug 1232258 for CVE-2024-49987", "url": "https://bugzilla.suse.com/1232258" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49987" }, { "cve": "CVE-2024-49989", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49989" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix double free issue during amdgpu module unload\n\nFlexible endpoints use DIGs from available inflexible endpoints,\nso only the encoders of inflexible links need to be freed.\nOtherwise, a double free issue may occur when unloading the\namdgpu module.\n\n[ 279.190523] RIP: 0010:__slab_free+0x152/0x2f0\n[ 279.190577] Call Trace:\n[ 279.190580] \u003cTASK\u003e\n[ 279.190582] ? show_regs+0x69/0x80\n[ 279.190590] ? die+0x3b/0x90\n[ 279.190595] ? do_trap+0xc8/0xe0\n[ 279.190601] ? do_error_trap+0x73/0xa0\n[ 279.190605] ? __slab_free+0x152/0x2f0\n[ 279.190609] ? exc_invalid_op+0x56/0x70\n[ 279.190616] ? __slab_free+0x152/0x2f0\n[ 279.190642] ? asm_exc_invalid_op+0x1f/0x30\n[ 279.190648] ? dcn10_link_encoder_destroy+0x19/0x30 [amdgpu]\n[ 279.191096] ? __slab_free+0x152/0x2f0\n[ 279.191102] ? dcn10_link_encoder_destroy+0x19/0x30 [amdgpu]\n[ 279.191469] kfree+0x260/0x2b0\n[ 279.191474] dcn10_link_encoder_destroy+0x19/0x30 [amdgpu]\n[ 279.191821] link_destroy+0xd7/0x130 [amdgpu]\n[ 279.192248] dc_destruct+0x90/0x270 [amdgpu]\n[ 279.192666] dc_destroy+0x19/0x40 [amdgpu]\n[ 279.193020] amdgpu_dm_fini+0x16e/0x200 [amdgpu]\n[ 279.193432] dm_hw_fini+0x26/0x40 [amdgpu]\n[ 279.193795] amdgpu_device_fini_hw+0x24c/0x400 [amdgpu]\n[ 279.194108] amdgpu_driver_unload_kms+0x4f/0x70 [amdgpu]\n[ 279.194436] amdgpu_pci_remove+0x40/0x80 [amdgpu]\n[ 279.194632] pci_device_remove+0x3a/0xa0\n[ 279.194638] device_remove+0x40/0x70\n[ 279.194642] device_release_driver_internal+0x1ad/0x210\n[ 279.194647] driver_detach+0x4e/0xa0\n[ 279.194650] bus_remove_driver+0x6f/0xf0\n[ 279.194653] driver_unregister+0x33/0x60\n[ 279.194657] pci_unregister_driver+0x44/0x90\n[ 279.194662] amdgpu_exit+0x19/0x1f0 [amdgpu]\n[ 279.194939] __do_sys_delete_module.isra.0+0x198/0x2f0\n[ 279.194946] __x64_sys_delete_module+0x16/0x20\n[ 279.194950] do_syscall_64+0x58/0x120\n[ 279.194954] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n[ 279.194980] \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49989", "url": "https://www.suse.com/security/cve/CVE-2024-49989" }, { "category": "external", "summary": "SUSE Bug 1232483 for CVE-2024-49989", "url": "https://bugzilla.suse.com/1232483" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-49989" }, { "cve": "CVE-2024-50003", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50003" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix system hang while resume with TBT monitor\n\n[Why]\nConnected with a Thunderbolt monitor and do the suspend and the system\nmay hang while resume.\n\nThe TBT monitor HPD will be triggered during the resume procedure\nand call the drm_client_modeset_probe() while\nstruct drm_connector connector-\u003edev-\u003emaster is NULL.\n\nIt will mess up the pipe topology after resume.\n\n[How]\nSkip the TBT monitor HPD during the resume procedure because we\ncurrently will probe the connectors after resume by default.\n\n(cherry picked from commit 453f86a26945207a16b8f66aaed5962dc2b95b85)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50003", "url": "https://www.suse.com/security/cve/CVE-2024-50003" }, { "category": "external", "summary": "SUSE Bug 1232385 for CVE-2024-50003", "url": "https://bugzilla.suse.com/1232385" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50003" }, { "cve": "CVE-2024-50004", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50004" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: update DML2 policy EnhancedPrefetchScheduleAccelerationFinal DCN35\n\n[WHY \u0026 HOW]\nMismatch in DCN35 DML2 cause bw validation failed to acquire unexpected DPP pipe to cause\ngrey screen and system hang. Remove EnhancedPrefetchScheduleAccelerationFinal value override\nto match HW spec.\n\n(cherry picked from commit 9dad21f910fcea2bdcff4af46159101d7f9cd8ba)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50004", "url": "https://www.suse.com/security/cve/CVE-2024-50004" }, { "category": "external", "summary": "SUSE Bug 1232396 for CVE-2024-50004", "url": "https://bugzilla.suse.com/1232396" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50004" }, { "cve": "CVE-2024-50006", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50006" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix i_data_sem unlock order in ext4_ind_migrate()\n\nFuzzing reports a possible deadlock in jbd2_log_wait_commit.\n\nThis issue is triggered when an EXT4_IOC_MIGRATE ioctl is set to require\nsynchronous updates because the file descriptor is opened with O_SYNC.\nThis can lead to the jbd2_journal_stop() function calling\njbd2_might_wait_for_commit(), potentially causing a deadlock if the\nEXT4_IOC_MIGRATE call races with a write(2) system call.\n\nThis problem only arises when CONFIG_PROVE_LOCKING is enabled. In this\ncase, the jbd2_might_wait_for_commit macro locks jbd2_handle in the\njbd2_journal_stop function while i_data_sem is locked. This triggers\nlockdep because the jbd2_journal_start function might also lock the same\njbd2_handle simultaneously.\n\nFound by Linux Verification Center (linuxtesting.org) with syzkaller.\n\nRule: add", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50006", "url": "https://www.suse.com/security/cve/CVE-2024-50006" }, { "category": "external", "summary": "SUSE Bug 1232442 for CVE-2024-50006", "url": "https://bugzilla.suse.com/1232442" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50006" }, { "cve": "CVE-2024-50009", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50009" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: amd-pstate: add check for cpufreq_cpu_get\u0027s return value\n\ncpufreq_cpu_get may return NULL. To avoid NULL-dereference check it\nand return in case of error.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50009", "url": "https://www.suse.com/security/cve/CVE-2024-50009" }, { "category": "external", "summary": "SUSE Bug 1232318 for CVE-2024-50009", "url": "https://bugzilla.suse.com/1232318" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50009" }, { "cve": "CVE-2024-50012", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50012" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: Avoid a bad reference count on CPU node\n\nIn the parse_perf_domain function, if the call to\nof_parse_phandle_with_args returns an error, then the reference to the\nCPU device node that was acquired at the start of the function would not\nbe properly decremented.\n\nAddress this by declaring the variable with the __free(device_node)\ncleanup attribute.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50012", "url": "https://www.suse.com/security/cve/CVE-2024-50012" }, { "category": "external", "summary": "SUSE Bug 1232386 for CVE-2024-50012", "url": "https://bugzilla.suse.com/1232386" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50012" }, { "cve": "CVE-2024-50014", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50014" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix access to uninitialised lock in fc replay path\n\nThe following kernel trace can be triggered with fstest generic/629 when\nexecuted against a filesystem with fast-commit feature enabled:\n\nINFO: trying to register non-static key.\nThe code is fine but needs lockdep annotation, or maybe\nyou didn\u0027t initialize this object before use?\nturning off the locking correctness validator.\nCPU: 0 PID: 866 Comm: mount Not tainted 6.10.0+ #11\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-3-gd478f380-prebuilt.qemu.org 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x66/0x90\n register_lock_class+0x759/0x7d0\n __lock_acquire+0x85/0x2630\n ? __find_get_block+0xb4/0x380\n lock_acquire+0xd1/0x2d0\n ? __ext4_journal_get_write_access+0xd5/0x160\n _raw_spin_lock+0x33/0x40\n ? __ext4_journal_get_write_access+0xd5/0x160\n __ext4_journal_get_write_access+0xd5/0x160\n ext4_reserve_inode_write+0x61/0xb0\n __ext4_mark_inode_dirty+0x79/0x270\n ? ext4_ext_replay_set_iblocks+0x2f8/0x450\n ext4_ext_replay_set_iblocks+0x330/0x450\n ext4_fc_replay+0x14c8/0x1540\n ? jread+0x88/0x2e0\n ? rcu_is_watching+0x11/0x40\n do_one_pass+0x447/0xd00\n jbd2_journal_recover+0x139/0x1b0\n jbd2_journal_load+0x96/0x390\n ext4_load_and_init_journal+0x253/0xd40\n ext4_fill_super+0x2cc6/0x3180\n...\n\nIn the replay path there\u0027s an attempt to lock sbi-\u003es_bdev_wb_lock in\nfunction ext4_check_bdev_write_error(). Unfortunately, at this point this\nspinlock has not been initialized yet. Moving it\u0027s initialization to an\nearlier point in __ext4_fill_super() fixes this splat.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50014", "url": "https://www.suse.com/security/cve/CVE-2024-50014" }, { "category": "external", "summary": "SUSE Bug 1232446 for CVE-2024-50014", "url": "https://bugzilla.suse.com/1232446" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50014" }, { "cve": "CVE-2024-50026", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50026" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: wd33c93: Don\u0027t use stale scsi_pointer value\n\nA regression was introduced with commit dbb2da557a6a (\"scsi: wd33c93:\nMove the SCSI pointer to private command data\") which results in an oops\nin wd33c93_intr(). That commit added the scsi_pointer variable and\ninitialized it from hostdata-\u003econnected. However, during selection,\nhostdata-\u003econnected is not yet valid. Fix this by getting the current\nscsi_pointer from hostdata-\u003eselecting.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50026", "url": "https://www.suse.com/security/cve/CVE-2024-50026" }, { "category": "external", "summary": "SUSE Bug 1231952 for CVE-2024-50026", "url": "https://bugzilla.suse.com/1231952" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50026" }, { "cve": "CVE-2024-50067", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50067" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nuprobe: avoid out-of-bounds memory access of fetching args\n\nUprobe needs to fetch args into a percpu buffer, and then copy to ring\nbuffer to avoid non-atomic context problem.\n\nSometimes user-space strings, arrays can be very large, but the size of\npercpu buffer is only page size. And store_trace_args() won\u0027t check\nwhether these data exceeds a single page or not, caused out-of-bounds\nmemory access.\n\nIt could be reproduced by following steps:\n1. build kernel with CONFIG_KASAN enabled\n2. save follow program as test.c\n\n```\n\\#include \u003cstdio.h\u003e\n\\#include \u003cstdlib.h\u003e\n\\#include \u003cstring.h\u003e\n\n// If string length large than MAX_STRING_SIZE, the fetch_store_strlen()\n// will return 0, cause __get_data_size() return shorter size, and\n// store_trace_args() will not trigger out-of-bounds access.\n// So make string length less than 4096.\n\\#define STRLEN 4093\n\nvoid generate_string(char *str, int n)\n{\n int i;\n for (i = 0; i \u003c n; ++i)\n {\n char c = i % 26 + \u0027a\u0027;\n str[i] = c;\n }\n str[n-1] = \u0027\\0\u0027;\n}\n\nvoid print_string(char *str)\n{\n printf(\"%s\\n\", str);\n}\n\nint main()\n{\n char tmp[STRLEN];\n\n generate_string(tmp, STRLEN);\n print_string(tmp);\n\n return 0;\n}\n```\n3. compile program\n`gcc -o test test.c`\n\n4. get the offset of `print_string()`\n```\nobjdump -t test | grep -w print_string\n0000000000401199 g F .text 000000000000001b print_string\n```\n\n5. configure uprobe with offset 0x1199\n```\noff=0x1199\n\ncd /sys/kernel/debug/tracing/\necho \"p /root/test:${off} arg1=+0(%di):ustring arg2=\\$comm arg3=+0(%di):ustring\"\n \u003e uprobe_events\necho 1 \u003e events/uprobes/enable\necho 1 \u003e tracing_on\n```\n\n6. run `test`, and kasan will report error.\n==================================================================\nBUG: KASAN: use-after-free in strncpy_from_user+0x1d6/0x1f0\nWrite of size 8 at addr ffff88812311c004 by task test/499CPU: 0 UID: 0 PID: 499 Comm: test Not tainted 6.12.0-rc3+ #18\nHardware name: Red Hat KVM, BIOS 1.16.0-4.al8 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x55/0x70\n print_address_description.constprop.0+0x27/0x310\n kasan_report+0x10f/0x120\n ? strncpy_from_user+0x1d6/0x1f0\n strncpy_from_user+0x1d6/0x1f0\n ? rmqueue.constprop.0+0x70d/0x2ad0\n process_fetch_insn+0xb26/0x1470\n ? __pfx_process_fetch_insn+0x10/0x10\n ? _raw_spin_lock+0x85/0xe0\n ? __pfx__raw_spin_lock+0x10/0x10\n ? __pte_offset_map+0x1f/0x2d0\n ? unwind_next_frame+0xc5f/0x1f80\n ? arch_stack_walk+0x68/0xf0\n ? is_bpf_text_address+0x23/0x30\n ? kernel_text_address.part.0+0xbb/0xd0\n ? __kernel_text_address+0x66/0xb0\n ? unwind_get_return_address+0x5e/0xa0\n ? __pfx_stack_trace_consume_entry+0x10/0x10\n ? arch_stack_walk+0xa2/0xf0\n ? _raw_spin_lock_irqsave+0x8b/0xf0\n ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n ? depot_alloc_stack+0x4c/0x1f0\n ? _raw_spin_unlock_irqrestore+0xe/0x30\n ? stack_depot_save_flags+0x35d/0x4f0\n ? kasan_save_stack+0x34/0x50\n ? kasan_save_stack+0x24/0x50\n ? mutex_lock+0x91/0xe0\n ? __pfx_mutex_lock+0x10/0x10\n prepare_uprobe_buffer.part.0+0x2cd/0x500\n uprobe_dispatcher+0x2c3/0x6a0\n ? __pfx_uprobe_dispatcher+0x10/0x10\n ? __kasan_slab_alloc+0x4d/0x90\n handler_chain+0xdd/0x3e0\n handle_swbp+0x26e/0x3d0\n ? __pfx_handle_swbp+0x10/0x10\n ? uprobe_pre_sstep_notifier+0x151/0x1b0\n irqentry_exit_to_user_mode+0xe2/0x1b0\n asm_exc_int3+0x39/0x40\nRIP: 0033:0x401199\nCode: 01 c2 0f b6 45 fb 88 02 83 45 fc 01 8b 45 fc 3b 45 e4 7c b7 8b 45 e4 48 98 48 8d 50 ff 48 8b 45 e8 48 01 d0 ce\nRSP: 002b:00007ffdf00576a8 EFLAGS: 00000206\nRAX: 00007ffdf00576b0 RBX: 0000000000000000 RCX: 0000000000000ff2\nRDX: 0000000000000ffc RSI: 0000000000000ffd RDI: 00007ffdf00576b0\nRBP: 00007ffdf00586b0 R08: 00007feb2f9c0d20 R09: 00007feb2f9c0d20\nR10: 0000000000000001 R11: 0000000000000202 R12: 0000000000401040\nR13: 00007ffdf0058780 R14: 0000000000000000 R15: 0000000000000000\n \u003c/TASK\u003e\n\nThis commit enforces the buffer\u0027s maxlen less than a page-size to avoid\nstore_trace_args() out-of-memory access.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50067", "url": "https://www.suse.com/security/cve/CVE-2024-50067" }, { "category": "external", "summary": "SUSE Bug 1232416 for CVE-2024-50067", "url": "https://bugzilla.suse.com/1232416" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50067" }, { "cve": "CVE-2024-50082", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50082" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race\n\nWe\u0027re seeing crashes from rq_qos_wake_function that look like this:\n\n BUG: unable to handle page fault for address: ffffafe180a40084\n #PF: supervisor write access in kernel mode\n #PF: error_code(0x0002) - not-present page\n PGD 100000067 P4D 100000067 PUD 10027c067 PMD 10115d067 PTE 0\n Oops: Oops: 0002 [#1] PREEMPT SMP PTI\n CPU: 17 UID: 0 PID: 0 Comm: swapper/17 Not tainted 6.12.0-rc3-00013-geca631b8fe80 #11\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\n RIP: 0010:_raw_spin_lock_irqsave+0x1d/0x40\n Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 41 54 9c 41 5c fa 65 ff 05 62 97 30 4c 31 c0 ba 01 00 00 00 \u003cf0\u003e 0f b1 17 75 0a 4c 89 e0 41 5c c3 cc cc cc cc 89 c6 e8 2c 0b 00\n RSP: 0018:ffffafe180580ca0 EFLAGS: 00010046\n RAX: 0000000000000000 RBX: ffffafe180a3f7a8 RCX: 0000000000000011\n RDX: 0000000000000001 RSI: 0000000000000003 RDI: ffffafe180a40084\n RBP: 0000000000000000 R08: 00000000001e7240 R09: 0000000000000011\n R10: 0000000000000028 R11: 0000000000000888 R12: 0000000000000002\n R13: ffffafe180a40084 R14: 0000000000000000 R15: 0000000000000003\n FS: 0000000000000000(0000) GS:ffff9aaf1f280000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: ffffafe180a40084 CR3: 000000010e428002 CR4: 0000000000770ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \u003cIRQ\u003e\n try_to_wake_up+0x5a/0x6a0\n rq_qos_wake_function+0x71/0x80\n __wake_up_common+0x75/0xa0\n __wake_up+0x36/0x60\n scale_up.part.0+0x50/0x110\n wb_timer_fn+0x227/0x450\n ...\n\nSo rq_qos_wake_function() calls wake_up_process(data-\u003etask), which calls\ntry_to_wake_up(), which faults in raw_spin_lock_irqsave(\u0026p-\u003epi_lock).\n\np comes from data-\u003etask, and data comes from the waitqueue entry, which\nis stored on the waiter\u0027s stack in rq_qos_wait(). Analyzing the core\ndump with drgn, I found that the waiter had already woken up and moved\non to a completely unrelated code path, clobbering what was previously\ndata-\u003etask. Meanwhile, the waker was passing the clobbered garbage in\ndata-\u003etask to wake_up_process(), leading to the crash.\n\nWhat\u0027s happening is that in between rq_qos_wake_function() deleting the\nwaitqueue entry and calling wake_up_process(), rq_qos_wait() is finding\nthat it already got a token and returning. The race looks like this:\n\nrq_qos_wait() rq_qos_wake_function()\n==============================================================\nprepare_to_wait_exclusive()\n data-\u003egot_token = true;\n list_del_init(\u0026curr-\u003eentry);\nif (data.got_token)\n break;\nfinish_wait(\u0026rqw-\u003ewait, \u0026data.wq);\n ^- returns immediately because\n list_empty_careful(\u0026wq_entry-\u003eentry)\n is true\n... return, go do something else ...\n wake_up_process(data-\u003etask)\n (NO LONGER VALID!)-^\n\nNormally, finish_wait() is supposed to synchronize against the waker.\nBut, as noted above, it is returning immediately because the waitqueue\nentry has already been removed from the waitqueue.\n\nThe bug is that rq_qos_wake_function() is accessing the waitqueue entry\nAFTER deleting it. Note that autoremove_wake_function() wakes the waiter\nand THEN deletes the waitqueue entry, which is the proper order.\n\nFix it by swapping the order. We also need to use\nlist_del_init_careful() to match the list_empty_careful() in\nfinish_wait().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50082", "url": "https://www.suse.com/security/cve/CVE-2024-50082" }, { "category": "external", "summary": "SUSE Bug 1232500 for CVE-2024-50082", "url": "https://bugzilla.suse.com/1232500" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50082" }, { "cve": "CVE-2024-50084", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50084" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()\n\nCommit a3c1e45156ad (\"net: microchip: vcap: Fix use-after-free error in\nkunit test\") fixed the use-after-free error, but introduced below\nmemory leaks by removing necessary vcap_free_rule(), add it to fix it.\n\n\tunreferenced object 0xffffff80ca58b700 (size 192):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898264\n\t hex dump (first 32 bytes):\n\t 00 12 7a 00 05 00 00 00 0a 00 00 00 64 00 00 00 ..z.........d...\n\t 00 00 00 00 00 00 00 00 00 04 0b cc 80 ff ff ff ................\n\t backtrace (crc 9c09c3fe):\n\t [\u003c0000000052a0be73\u003e] kmemleak_alloc+0x34/0x40\n\t [\u003c0000000043605459\u003e] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [\u003c0000000040a01b8d\u003e] vcap_alloc_rule+0x3cc/0x9c4\n\t [\u003c000000003fe86110\u003e] vcap_api_encode_rule_test+0x1ac/0x16b0\n\t [\u003c00000000b3595fc4\u003e] kunit_try_run_case+0x13c/0x3ac\n\t [\u003c0000000010f5d2bf\u003e] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [\u003c00000000c5d82c9a\u003e] kthread+0x2e8/0x374\n\t [\u003c00000000f4287308\u003e] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80cc0b0400 (size 64):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898265\n\t hex dump (first 32 bytes):\n\t 80 04 0b cc 80 ff ff ff 18 b7 58 ca 80 ff ff ff ..........X.....\n\t 39 00 00 00 02 00 00 00 06 05 04 03 02 01 ff ff 9...............\n\t backtrace (crc daf014e9):\n\t [\u003c0000000052a0be73\u003e] kmemleak_alloc+0x34/0x40\n\t [\u003c0000000043605459\u003e] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [\u003c000000000ff63fd4\u003e] vcap_rule_add_key+0x2cc/0x528\n\t [\u003c00000000dfdb1e81\u003e] vcap_api_encode_rule_test+0x224/0x16b0\n\t [\u003c00000000b3595fc4\u003e] kunit_try_run_case+0x13c/0x3ac\n\t [\u003c0000000010f5d2bf\u003e] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [\u003c00000000c5d82c9a\u003e] kthread+0x2e8/0x374\n\t [\u003c00000000f4287308\u003e] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80cc0b0700 (size 64):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898265\n\t hex dump (first 32 bytes):\n\t 80 07 0b cc 80 ff ff ff 28 b7 58 ca 80 ff ff ff ........(.X.....\n\t 3c 00 00 00 00 00 00 00 01 2f 03 b3 ec ff ff ff \u003c......../......\n\t backtrace (crc 8d877792):\n\t [\u003c0000000052a0be73\u003e] kmemleak_alloc+0x34/0x40\n\t [\u003c0000000043605459\u003e] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [\u003c000000006eadfab7\u003e] vcap_rule_add_action+0x2d0/0x52c\n\t [\u003c00000000323475d1\u003e] vcap_api_encode_rule_test+0x4d4/0x16b0\n\t [\u003c00000000b3595fc4\u003e] kunit_try_run_case+0x13c/0x3ac\n\t [\u003c0000000010f5d2bf\u003e] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [\u003c00000000c5d82c9a\u003e] kthread+0x2e8/0x374\n\t [\u003c00000000f4287308\u003e] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80cc0b0900 (size 64):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898266\n\t hex dump (first 32 bytes):\n\t 80 09 0b cc 80 ff ff ff 80 06 0b cc 80 ff ff ff ................\n\t 7d 00 00 00 01 00 00 00 00 00 00 00 ff 00 00 00 }...............\n\t backtrace (crc 34181e56):\n\t [\u003c0000000052a0be73\u003e] kmemleak_alloc+0x34/0x40\n\t [\u003c0000000043605459\u003e] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [\u003c000000000ff63fd4\u003e] vcap_rule_add_key+0x2cc/0x528\n\t [\u003c00000000991e3564\u003e] vcap_val_rule+0xcf0/0x13e8\n\t [\u003c00000000fc9868e5\u003e] vcap_api_encode_rule_test+0x678/0x16b0\n\t [\u003c00000000b3595fc4\u003e] kunit_try_run_case+0x13c/0x3ac\n\t [\u003c0000000010f5d2bf\u003e] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [\u003c00000000c5d82c9a\u003e] kthread+0x2e8/0x374\n\t [\u003c00000000f4287308\u003e] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80cc0b0980 (size 64):\n\t comm \"kunit_try_catch\", pid 1215, jiffies 4294898266\n\t hex dump (first 32 bytes):\n\t 18 b7 58 ca 80 ff ff ff 00 09 0b cc 80 ff ff ff ..X.............\n\t 67 00 00 00 00 00 00 00 01 01 74 88 c0 ff ff ff g.........t.....\n\t backtrace (crc 275fd9be):\n\t [\u003c0000000052a0be73\u003e] kmemleak_alloc+0x34/0x40\n\t [\u003c0000000043605459\u003e] __kmalloc_cache_noprof+0x26c/0x2f4\n\t [\u003c000000000ff63fd4\u003e] vcap_rule_add_key+0x2cc/0x528\n\t [\u003c000000001396a1a2\u003e] test_add_de\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50084", "url": "https://www.suse.com/security/cve/CVE-2024-50084" }, { "category": "external", "summary": "SUSE Bug 1232494 for CVE-2024-50084", "url": "https://bugzilla.suse.com/1232494" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50084" }, { "cve": "CVE-2024-50087", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50087" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix uninitialized pointer free on read_alloc_one_name() error\n\nThe function read_alloc_one_name() does not initialize the name field of\nthe passed fscrypt_str struct if kmalloc fails to allocate the\ncorresponding buffer. Thus, it is not guaranteed that\nfscrypt_str.name is initialized when freeing it.\n\nThis is a follow-up to the linked patch that fixes the remaining\ninstances of the bug introduced by commit e43eec81c516 (\"btrfs: use\nstruct qstr instead of name and namelen pairs\").", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50087", "url": "https://www.suse.com/security/cve/CVE-2024-50087" }, { "category": "external", "summary": "SUSE Bug 1232499 for CVE-2024-50087", "url": "https://bugzilla.suse.com/1232499" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50087" }, { "cve": "CVE-2024-50088", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50088" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix uninitialized pointer free in add_inode_ref()\n\nThe add_inode_ref() function does not initialize the \"name\" struct when\nit is declared. If any of the following calls to \"read_one_inode()\nreturns NULL,\n\n\tdir = read_one_inode(root, parent_objectid);\n\tif (!dir) {\n\t\tret = -ENOENT;\n\t\tgoto out;\n\t}\n\n\tinode = read_one_inode(root, inode_objectid);\n\tif (!inode) {\n\t\tret = -EIO;\n\t\tgoto out;\n\t}\n\nthen \"name.name\" would be freed on \"out\" before being initialized.\n\nout:\n\t...\n\tkfree(name.name);\n\nThis issue was reported by Coverity with CID 1526744.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50088", "url": "https://www.suse.com/security/cve/CVE-2024-50088" }, { "category": "external", "summary": "SUSE Bug 1232498 for CVE-2024-50088", "url": "https://bugzilla.suse.com/1232498" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50088" }, { "cve": "CVE-2024-50089", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50089" } ], "notes": [ { "category": "general", "text": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50089", "url": "https://www.suse.com/security/cve/CVE-2024-50089" }, { "category": "external", "summary": "SUSE Bug 1232860 for CVE-2024-50089", "url": "https://bugzilla.suse.com/1232860" }, { "category": "external", "summary": "SUSE Bug 1233250 for CVE-2024-50089", "url": "https://bugzilla.suse.com/1233250" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50089" }, { "cve": "CVE-2024-50093", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50093" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: intel: int340x: processor: Fix warning during module unload\n\nThe processor_thermal driver uses pcim_device_enable() to enable a PCI\ndevice, which means the device will be automatically disabled on driver\ndetach. Thus there is no need to call pci_disable_device() again on it.\n\nWith recent PCI device resource management improvements, e.g. commit\nf748a07a0b64 (\"PCI: Remove legacy pcim_release()\"), this problem is\nexposed and triggers the warining below.\n\n [ 224.010735] proc_thermal_pci 0000:00:04.0: disabling already-disabled device\n [ 224.010747] WARNING: CPU: 8 PID: 4442 at drivers/pci/pci.c:2250 pci_disable_device+0xe5/0x100\n ...\n [ 224.010844] Call Trace:\n [ 224.010845] \u003cTASK\u003e\n [ 224.010847] ? show_regs+0x6d/0x80\n [ 224.010851] ? __warn+0x8c/0x140\n [ 224.010854] ? pci_disable_device+0xe5/0x100\n [ 224.010856] ? report_bug+0x1c9/0x1e0\n [ 224.010859] ? handle_bug+0x46/0x80\n [ 224.010862] ? exc_invalid_op+0x1d/0x80\n [ 224.010863] ? asm_exc_invalid_op+0x1f/0x30\n [ 224.010867] ? pci_disable_device+0xe5/0x100\n [ 224.010869] ? pci_disable_device+0xe5/0x100\n [ 224.010871] ? kfree+0x21a/0x2b0\n [ 224.010873] pcim_disable_device+0x20/0x30\n [ 224.010875] devm_action_release+0x16/0x20\n [ 224.010878] release_nodes+0x47/0xc0\n [ 224.010880] devres_release_all+0x9f/0xe0\n [ 224.010883] device_unbind_cleanup+0x12/0x80\n [ 224.010885] device_release_driver_internal+0x1ca/0x210\n [ 224.010887] driver_detach+0x4e/0xa0\n [ 224.010889] bus_remove_driver+0x6f/0xf0\n [ 224.010890] driver_unregister+0x35/0x60\n [ 224.010892] pci_unregister_driver+0x44/0x90\n [ 224.010894] proc_thermal_pci_driver_exit+0x14/0x5f0 [processor_thermal_device_pci]\n ...\n [ 224.010921] ---[ end trace 0000000000000000 ]---\n\nRemove the excess pci_disable_device() calls.\n\n[ rjw: Subject and changelog edits ]", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50093", "url": "https://www.suse.com/security/cve/CVE-2024-50093" }, { "category": "external", "summary": "SUSE Bug 1232877 for CVE-2024-50093", "url": "https://bugzilla.suse.com/1232877" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50093" }, { "cve": "CVE-2024-50095", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50095" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mad: Improve handling of timed out WRs of mad agent\n\nCurrent timeout handler of mad agent acquires/releases mad_agent_priv\nlock for every timed out WRs. This causes heavy locking contention\nwhen higher no. of WRs are to be handled inside timeout handler.\n\nThis leads to softlockup with below trace in some use cases where\nrdma-cm path is used to establish connection between peer nodes\n\nTrace:\n-----\n BUG: soft lockup - CPU#4 stuck for 26s! [kworker/u128:3:19767]\n CPU: 4 PID: 19767 Comm: kworker/u128:3 Kdump: loaded Tainted: G OE\n ------- --- 5.14.0-427.13.1.el9_4.x86_64 #1\n Hardware name: Dell Inc. PowerEdge R740/01YM03, BIOS 2.4.8 11/26/2019\n Workqueue: ib_mad1 timeout_sends [ib_core]\n RIP: 0010:__do_softirq+0x78/0x2ac\n RSP: 0018:ffffb253449e4f98 EFLAGS: 00000246\n RAX: 00000000ffffffff RBX: 0000000000000000 RCX: 000000000000001f\n RDX: 000000000000001d RSI: 000000003d1879ab RDI: fff363b66fd3a86b\n RBP: ffffb253604cbcd8 R08: 0000009065635f3b R09: 0000000000000000\n R10: 0000000000000040 R11: ffffb253449e4ff8 R12: 0000000000000000\n R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000040\n FS: 0000000000000000(0000) GS:ffff8caa1fc80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fd9ec9db900 CR3: 0000000891934006 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \u003cIRQ\u003e\n ? show_trace_log_lvl+0x1c4/0x2df\n ? show_trace_log_lvl+0x1c4/0x2df\n ? __irq_exit_rcu+0xa1/0xc0\n ? watchdog_timer_fn+0x1b2/0x210\n ? __pfx_watchdog_timer_fn+0x10/0x10\n ? __hrtimer_run_queues+0x127/0x2c0\n ? hrtimer_interrupt+0xfc/0x210\n ? __sysvec_apic_timer_interrupt+0x5c/0x110\n ? sysvec_apic_timer_interrupt+0x37/0x90\n ? asm_sysvec_apic_timer_interrupt+0x16/0x20\n ? __do_softirq+0x78/0x2ac\n ? __do_softirq+0x60/0x2ac\n __irq_exit_rcu+0xa1/0xc0\n sysvec_call_function_single+0x72/0x90\n \u003c/IRQ\u003e\n \u003cTASK\u003e\n asm_sysvec_call_function_single+0x16/0x20\n RIP: 0010:_raw_spin_unlock_irq+0x14/0x30\n RSP: 0018:ffffb253604cbd88 EFLAGS: 00000247\n RAX: 000000000001960d RBX: 0000000000000002 RCX: ffff8cad2a064800\n RDX: 000000008020001b RSI: 0000000000000001 RDI: ffff8cad5d39f66c\n RBP: ffff8cad5d39f600 R08: 0000000000000001 R09: 0000000000000000\n R10: ffff8caa443e0c00 R11: ffffb253604cbcd8 R12: ffff8cacb8682538\n R13: 0000000000000005 R14: ffffb253604cbd90 R15: ffff8cad5d39f66c\n cm_process_send_error+0x122/0x1d0 [ib_cm]\n timeout_sends+0x1dd/0x270 [ib_core]\n process_one_work+0x1e2/0x3b0\n ? __pfx_worker_thread+0x10/0x10\n worker_thread+0x50/0x3a0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xdd/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x29/0x50\n \u003c/TASK\u003e\n\nSimplified timeout handler by creating local list of timed out WRs\nand invoke send handler post creating the list. The new method acquires/\nreleases lock once to fetch the list and hence helps to reduce locking\ncontetiong when processing higher no. of WRs", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50095", "url": "https://www.suse.com/security/cve/CVE-2024-50095" }, { "category": "external", "summary": "SUSE Bug 1232873 for CVE-2024-50095", "url": "https://bugzilla.suse.com/1232873" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50095" }, { "cve": "CVE-2024-50096", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50096" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error\n\nThe `nouveau_dmem_copy_one` function ensures that the copy push command is\nsent to the device firmware but does not track whether it was executed\nsuccessfully.\n\nIn the case of a copy error (e.g., firmware or hardware failure), the\ncopy push command will be sent via the firmware channel, and\n`nouveau_dmem_copy_one` will likely report success, leading to the\n`migrate_to_ram` function returning a dirty HIGH_USER page to the user.\n\nThis can result in a security vulnerability, as a HIGH_USER page that may\ncontain sensitive or corrupted data could be returned to the user.\n\nTo prevent this vulnerability, we allocate a zero page. Thus, in case of\nan error, a non-dirty (zero) page will be returned to the user.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50096", "url": "https://www.suse.com/security/cve/CVE-2024-50096" }, { "category": "external", "summary": "SUSE Bug 1232870 for CVE-2024-50096", "url": "https://bugzilla.suse.com/1232870" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50096" }, { "cve": "CVE-2024-50098", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50098" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Set SDEV_OFFLINE when UFS is shut down\n\nThere is a history of deadlock if reboot is performed at the beginning\nof booting. SDEV_QUIESCE was set for all LU\u0027s scsi_devices by UFS\nshutdown, and at that time the audio driver was waiting on\nblk_mq_submit_bio() holding a mutex_lock while reading the fw binary.\nAfter that, a deadlock issue occurred while audio driver shutdown was\nwaiting for mutex_unlock of blk_mq_submit_bio(). To solve this, set\nSDEV_OFFLINE for all LUs except WLUN, so that any I/O that comes down\nafter a UFS shutdown will return an error.\n\n[ 31.907781]I[0: swapper/0: 0] 1 130705007 1651079834 11289729804 0 D( 2) 3 ffffff882e208000 * init [device_shutdown]\n[ 31.907793]I[0: swapper/0: 0] Mutex: 0xffffff8849a2b8b0: owner[0xffffff882e28cb00 kworker/6:0 :49]\n[ 31.907806]I[0: swapper/0: 0] Call trace:\n[ 31.907810]I[0: swapper/0: 0] __switch_to+0x174/0x338\n[ 31.907819]I[0: swapper/0: 0] __schedule+0x5ec/0x9cc\n[ 31.907826]I[0: swapper/0: 0] schedule+0x7c/0xe8\n[ 31.907834]I[0: swapper/0: 0] schedule_preempt_disabled+0x24/0x40\n[ 31.907842]I[0: swapper/0: 0] __mutex_lock+0x408/0xdac\n[ 31.907849]I[0: swapper/0: 0] __mutex_lock_slowpath+0x14/0x24\n[ 31.907858]I[0: swapper/0: 0] mutex_lock+0x40/0xec\n[ 31.907866]I[0: swapper/0: 0] device_shutdown+0x108/0x280\n[ 31.907875]I[0: swapper/0: 0] kernel_restart+0x4c/0x11c\n[ 31.907883]I[0: swapper/0: 0] __arm64_sys_reboot+0x15c/0x280\n[ 31.907890]I[0: swapper/0: 0] invoke_syscall+0x70/0x158\n[ 31.907899]I[0: swapper/0: 0] el0_svc_common+0xb4/0xf4\n[ 31.907909]I[0: swapper/0: 0] do_el0_svc+0x2c/0xb0\n[ 31.907918]I[0: swapper/0: 0] el0_svc+0x34/0xe0\n[ 31.907928]I[0: swapper/0: 0] el0t_64_sync_handler+0x68/0xb4\n[ 31.907937]I[0: swapper/0: 0] el0t_64_sync+0x1a0/0x1a4\n\n[ 31.908774]I[0: swapper/0: 0] 49 0 11960702 11236868007 0 D( 2) 6 ffffff882e28cb00 * kworker/6:0 [__bio_queue_enter]\n[ 31.908783]I[0: swapper/0: 0] Call trace:\n[ 31.908788]I[0: swapper/0: 0] __switch_to+0x174/0x338\n[ 31.908796]I[0: swapper/0: 0] __schedule+0x5ec/0x9cc\n[ 31.908803]I[0: swapper/0: 0] schedule+0x7c/0xe8\n[ 31.908811]I[0: swapper/0: 0] __bio_queue_enter+0xb8/0x178\n[ 31.908818]I[0: swapper/0: 0] blk_mq_submit_bio+0x194/0x67c\n[ 31.908827]I[0: swapper/0: 0] __submit_bio+0xb8/0x19c", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50098", "url": "https://www.suse.com/security/cve/CVE-2024-50098" }, { "category": "external", "summary": "SUSE Bug 1232881 for CVE-2024-50098", "url": "https://bugzilla.suse.com/1232881" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50098" }, { "cve": "CVE-2024-50099", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50099" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: probes: Remove broken LDR (literal) uprobe support\n\nThe simulate_ldr_literal() and simulate_ldrsw_literal() functions are\nunsafe to use for uprobes. Both functions were originally written for\nuse with kprobes, and access memory with plain C accesses. When uprobes\nwas added, these were reused unmodified even though they cannot safely\naccess user memory.\n\nThere are three key problems:\n\n1) The plain C accesses do not have corresponding extable entries, and\n thus if they encounter a fault the kernel will treat these as\n unintentional accesses to user memory, resulting in a BUG() which\n will kill the kernel thread, and likely lead to further issues (e.g.\n lockup or panic()).\n\n2) The plain C accesses are subject to HW PAN and SW PAN, and so when\n either is in use, any attempt to simulate an access to user memory\n will fault. Thus neither simulate_ldr_literal() nor\n simulate_ldrsw_literal() can do anything useful when simulating a\n user instruction on any system with HW PAN or SW PAN.\n\n3) The plain C accesses are privileged, as they run in kernel context,\n and in practice can access a small range of kernel virtual addresses.\n The instructions they simulate have a range of +/-1MiB, and since the\n simulated instructions must itself be a user instructions in the\n TTBR0 address range, these can address the final 1MiB of the TTBR1\n acddress range by wrapping downwards from an address in the first\n 1MiB of the TTBR0 address range.\n\n In contemporary kernels the last 8MiB of TTBR1 address range is\n reserved, and accesses to this will always fault, meaning this is no\n worse than (1).\n\n Historically, it was theoretically possible for the linear map or\n vmemmap to spill into the final 8MiB of the TTBR1 address range, but\n in practice this is extremely unlikely to occur as this would\n require either:\n\n * Having enough physical memory to fill the entire linear map all the\n way to the final 1MiB of the TTBR1 address range.\n\n * Getting unlucky with KASLR randomization of the linear map such\n that the populated region happens to overlap with the last 1MiB of\n the TTBR address range.\n\n ... and in either case if we were to spill into the final page there\n would be larger problems as the final page would alias with error\n pointers.\n\nPractically speaking, (1) and (2) are the big issues. Given there have\nbeen no reports of problems since the broken code was introduced, it\nappears that no-one is relying on probing these instructions with\nuprobes.\n\nAvoid these issues by not allowing uprobes on LDR (literal) and LDRSW\n(literal), limiting the use of simulate_ldr_literal() and\nsimulate_ldrsw_literal() to kprobes. Attempts to place uprobes on LDR\n(literal) and LDRSW (literal) will be rejected as\narm_probe_decode_insn() will return INSN_REJECTED. In future we can\nconsider introducing working uprobes support for these instructions, but\nthis will require more significant work.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50099", "url": "https://www.suse.com/security/cve/CVE-2024-50099" }, { "category": "external", "summary": "SUSE Bug 1232887 for CVE-2024-50099", "url": "https://bugzilla.suse.com/1232887" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50099" }, { "cve": "CVE-2024-50100", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50100" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: gadget: dummy-hcd: Fix \"task hung\" problem\n\nThe syzbot fuzzer has been encountering \"task hung\" problems ever\nsince the dummy-hcd driver was changed to use hrtimers instead of\nregular timers. It turns out that the problems are caused by a subtle\ndifference between the timer_pending() and hrtimer_active() APIs.\n\nThe changeover blindly replaced the first by the second. However,\ntimer_pending() returns True when the timer is queued but not when its\ncallback is running, whereas hrtimer_active() returns True when the\nhrtimer is queued _or_ its callback is running. This difference\noccasionally caused dummy_urb_enqueue() to think that the callback\nroutine had not yet started when in fact it was almost finished. As a\nresult the hrtimer was not restarted, which made it impossible for the\ndriver to dequeue later the URB that was just enqueued. This caused\nusb_kill_urb() to hang, and things got worse from there.\n\nSince hrtimers have no API for telling when they are queued and the\ncallback isn\u0027t running, the driver must keep track of this for itself.\nThat\u0027s what this patch does, adding a new \"timer_pending\" flag and\nsetting or clearing it at the appropriate times.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50100", "url": "https://www.suse.com/security/cve/CVE-2024-50100" }, { "category": "external", "summary": "SUSE Bug 1232876 for CVE-2024-50100", "url": "https://bugzilla.suse.com/1232876" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50100" }, { "cve": "CVE-2024-50101", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50101" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix incorrect pci_for_each_dma_alias() for non-PCI devices\n\nPreviously, the domain_context_clear() function incorrectly called\npci_for_each_dma_alias() to set up context entries for non-PCI devices.\nThis could lead to kernel hangs or other unexpected behavior.\n\nAdd a check to only call pci_for_each_dma_alias() for PCI devices. For\nnon-PCI devices, domain_context_clear_one() is called directly.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50101", "url": "https://www.suse.com/security/cve/CVE-2024-50101" }, { "category": "external", "summary": "SUSE Bug 1232869 for CVE-2024-50101", "url": "https://bugzilla.suse.com/1232869" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50101" }, { "cve": "CVE-2024-50102", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50102" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86: fix user address masking non-canonical speculation issue\n\nIt turns out that AMD has a \"Meltdown Lite(tm)\" issue with non-canonical\naccesses in kernel space. And so using just the high bit to decide\nwhether an access is in user space or kernel space ends up with the good\nold \"leak speculative data\" if you have the right gadget using the\nresult:\n\n CVE-2020-12965 \"Transient Execution of Non-Canonical Accesses\"\n\nNow, the kernel surrounds the access with a STAC/CLAC pair, and those\ninstructions end up serializing execution on older Zen architectures,\nwhich closes the speculation window.\n\nBut that was true only up until Zen 5, which renames the AC bit [1].\nThat improves performance of STAC/CLAC a lot, but also means that the\nspeculation window is now open.\n\nNote that this affects not just the new address masking, but also the\nregular valid_user_address() check used by access_ok(), and the asm\nversion of the sign bit check in the get_user() helpers.\n\nIt does not affect put_user() or clear_user() variants, since there\u0027s no\nspeculative result to be used in a gadget for those operations.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50102", "url": "https://www.suse.com/security/cve/CVE-2024-50102" }, { "category": "external", "summary": "SUSE Bug 1232880 for CVE-2024-50102", "url": "https://bugzilla.suse.com/1232880" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50102" }, { "cve": "CVE-2024-50103", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50103" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: Fix NULL Dereference in asoc_qcom_lpass_cpu_platform_probe()\n\nA devm_kzalloc() in asoc_qcom_lpass_cpu_platform_probe() could\npossibly return NULL pointer. NULL Pointer Dereference may be\ntriggerred without addtional check.\nAdd a NULL check for the returned pointer.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50103", "url": "https://www.suse.com/security/cve/CVE-2024-50103" }, { "category": "external", "summary": "SUSE Bug 1232878 for CVE-2024-50103", "url": "https://bugzilla.suse.com/1232878" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50103" }, { "cve": "CVE-2024-50108", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50108" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Disable PSR-SU on Parade 08-01 TCON too\n\nStuart Hayhurst has found that both at bootup and fullscreen VA-API video\nis leading to black screens for around 1 second and kernel WARNING [1] traces\nwhen calling dmub_psr_enable() with Parade 08-01 TCON.\n\nThese symptoms all go away with PSR-SU disabled for this TCON, so disable\nit for now while DMUB traces [2] from the failure can be analyzed and the failure\nstate properly root caused.\n\n(cherry picked from commit afb634a6823d8d9db23c5fb04f79c5549349628b)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50108", "url": "https://www.suse.com/security/cve/CVE-2024-50108" }, { "category": "external", "summary": "SUSE Bug 1232884 for CVE-2024-50108", "url": "https://bugzilla.suse.com/1232884" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50108" }, { "cve": "CVE-2024-50110", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50110" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix one more kernel-infoleak in algo dumping\n\nDuring fuzz testing, the following issue was discovered:\n\nBUG: KMSAN: kernel-infoleak in _copy_to_iter+0x598/0x2a30\n _copy_to_iter+0x598/0x2a30\n __skb_datagram_iter+0x168/0x1060\n skb_copy_datagram_iter+0x5b/0x220\n netlink_recvmsg+0x362/0x1700\n sock_recvmsg+0x2dc/0x390\n __sys_recvfrom+0x381/0x6d0\n __x64_sys_recvfrom+0x130/0x200\n x64_sys_call+0x32c8/0x3cc0\n do_syscall_64+0xd8/0x1c0\n entry_SYSCALL_64_after_hwframe+0x79/0x81\n\nUninit was stored to memory at:\n copy_to_user_state_extra+0xcc1/0x1e00\n dump_one_state+0x28c/0x5f0\n xfrm_state_walk+0x548/0x11e0\n xfrm_dump_sa+0x1e0/0x840\n netlink_dump+0x943/0x1c40\n __netlink_dump_start+0x746/0xdb0\n xfrm_user_rcv_msg+0x429/0xc00\n netlink_rcv_skb+0x613/0x780\n xfrm_netlink_rcv+0x77/0xc0\n netlink_unicast+0xe90/0x1280\n netlink_sendmsg+0x126d/0x1490\n __sock_sendmsg+0x332/0x3d0\n ____sys_sendmsg+0x863/0xc30\n ___sys_sendmsg+0x285/0x3e0\n __x64_sys_sendmsg+0x2d6/0x560\n x64_sys_call+0x1316/0x3cc0\n do_syscall_64+0xd8/0x1c0\n entry_SYSCALL_64_after_hwframe+0x79/0x81\n\nUninit was created at:\n __kmalloc+0x571/0xd30\n attach_auth+0x106/0x3e0\n xfrm_add_sa+0x2aa0/0x4230\n xfrm_user_rcv_msg+0x832/0xc00\n netlink_rcv_skb+0x613/0x780\n xfrm_netlink_rcv+0x77/0xc0\n netlink_unicast+0xe90/0x1280\n netlink_sendmsg+0x126d/0x1490\n __sock_sendmsg+0x332/0x3d0\n ____sys_sendmsg+0x863/0xc30\n ___sys_sendmsg+0x285/0x3e0\n __x64_sys_sendmsg+0x2d6/0x560\n x64_sys_call+0x1316/0x3cc0\n do_syscall_64+0xd8/0x1c0\n entry_SYSCALL_64_after_hwframe+0x79/0x81\n\nBytes 328-379 of 732 are uninitialized\nMemory access of size 732 starts at ffff88800e18e000\nData copied to user address 00007ff30f48aff0\n\nCPU: 2 PID: 18167 Comm: syz-executor.0 Not tainted 6.8.11 #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n\nFixes copying of xfrm algorithms where some random\ndata of the structure fields can end up in userspace.\nPadding in structures may be filled with random (possibly sensitve)\ndata and should never be given directly to user-space.\n\nA similar issue was resolved in the commit\n8222d5910dae (\"xfrm: Zero padding when dumping algos and encap\")\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50110", "url": "https://www.suse.com/security/cve/CVE-2024-50110" }, { "category": "external", "summary": "SUSE Bug 1232885 for CVE-2024-50110", "url": "https://bugzilla.suse.com/1232885" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50110" }, { "cve": "CVE-2024-50115", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50115" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory\n\nIgnore nCR3[4:0] when loading PDPTEs from memory for nested SVM, as bits\n4:0 of CR3 are ignored when PAE paging is used, and thus VMRUN doesn\u0027t\nenforce 32-byte alignment of nCR3.\n\nIn the absolute worst case scenario, failure to ignore bits 4:0 can result\nin an out-of-bounds read, e.g. if the target page is at the end of a\nmemslot, and the VMM isn\u0027t using guard pages.\n\nPer the APM:\n\n The CR3 register points to the base address of the page-directory-pointer\n table. The page-directory-pointer table is aligned on a 32-byte boundary,\n with the low 5 address bits 4:0 assumed to be 0.\n\nAnd the SDM\u0027s much more explicit:\n\n 4:0 Ignored\n\nNote, KVM gets this right when loading PDPTRs, it\u0027s only the nSVM flow\nthat is broken.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50115", "url": "https://www.suse.com/security/cve/CVE-2024-50115" }, { "category": "external", "summary": "SUSE Bug 1225742 for CVE-2024-50115", "url": "https://bugzilla.suse.com/1225742" }, { "category": "external", "summary": "SUSE Bug 1232919 for CVE-2024-50115", "url": "https://bugzilla.suse.com/1232919" }, { "category": "external", "summary": "SUSE Bug 1233019 for CVE-2024-50115", "url": "https://bugzilla.suse.com/1233019" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.2, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50115" }, { "cve": "CVE-2024-50116", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50116" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix kernel bug due to missing clearing of buffer delay flag\n\nSyzbot reported that after nilfs2 reads a corrupted file system image\nand degrades to read-only, the BUG_ON check for the buffer delay flag\nin submit_bh_wbc() may fail, causing a kernel bug.\n\nThis is because the buffer delay flag is not cleared when clearing the\nbuffer state flags to discard a page/folio or a buffer head. So, fix\nthis.\n\nThis became necessary when the use of nilfs2\u0027s own page clear routine\nwas expanded. This state inconsistency does not occur if the buffer\nis written normally by log writing.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50116", "url": "https://www.suse.com/security/cve/CVE-2024-50116" }, { "category": "external", "summary": "SUSE Bug 1232892 for CVE-2024-50116", "url": "https://bugzilla.suse.com/1232892" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50116" }, { "cve": "CVE-2024-50117", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50117" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd: Guard against bad data for ATIF ACPI method\n\nIf a BIOS provides bad data in response to an ATIF method call\nthis causes a NULL pointer dereference in the caller.\n\n```\n? show_regs (arch/x86/kernel/dumpstack.c:478 (discriminator 1))\n? __die (arch/x86/kernel/dumpstack.c:423 arch/x86/kernel/dumpstack.c:434)\n? page_fault_oops (arch/x86/mm/fault.c:544 (discriminator 2) arch/x86/mm/fault.c:705 (discriminator 2))\n? do_user_addr_fault (arch/x86/mm/fault.c:440 (discriminator 1) arch/x86/mm/fault.c:1232 (discriminator 1))\n? acpi_ut_update_object_reference (drivers/acpi/acpica/utdelete.c:642)\n? exc_page_fault (arch/x86/mm/fault.c:1542)\n? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:623)\n? amdgpu_atif_query_backlight_caps.constprop.0 (drivers/gpu/drm/amd/amdgpu/amdgpu_acpi.c:387 (discriminator 2)) amdgpu\n? amdgpu_atif_query_backlight_caps.constprop.0 (drivers/gpu/drm/amd/amdgpu/amdgpu_acpi.c:386 (discriminator 1)) amdgpu\n```\n\nIt has been encountered on at least one system, so guard for it.\n\n(cherry picked from commit c9b7c809b89f24e9372a4e7f02d64c950b07fdee)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50117", "url": "https://www.suse.com/security/cve/CVE-2024-50117" }, { "category": "external", "summary": "SUSE Bug 1232897 for CVE-2024-50117", "url": "https://bugzilla.suse.com/1232897" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50117" }, { "cve": "CVE-2024-50121", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50121" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net\n\nIn the normal case, when we excute `echo 0 \u003e /proc/fs/nfsd/threads`, the\nfunction `nfs4_state_destroy_net` in `nfs4_state_shutdown_net` will\nrelease all resources related to the hashed `nfs4_client`. If the\n`nfsd_client_shrinker` is running concurrently, the `expire_client`\nfunction will first unhash this client and then destroy it. This can\nlead to the following warning. Additionally, numerous use-after-free\nerrors may occur as well.\n\nnfsd_client_shrinker echo 0 \u003e /proc/fs/nfsd/threads\n\nexpire_client nfsd_shutdown_net\n unhash_client ...\n nfs4_state_shutdown_net\n /* won\u0027t wait shrinker exit */\n /* cancel_work(\u0026nn-\u003enfsd_shrinker_work)\n * nfsd_file for this /* won\u0027t destroy unhashed client1 */\n * client1 still alive nfs4_state_destroy_net\n */\n\n nfsd_file_cache_shutdown\n /* trigger warning */\n kmem_cache_destroy(nfsd_file_slab)\n kmem_cache_destroy(nfsd_file_mark_slab)\n /* release nfsd_file and mark */\n __destroy_client\n\n====================================================================\nBUG nfsd_file (Not tainted): Objects remaining in nfsd_file on\n__kmem_cache_shutdown()\n--------------------------------------------------------------------\nCPU: 4 UID: 0 PID: 764 Comm: sh Not tainted 6.12.0-rc3+ #1\n\n dump_stack_lvl+0x53/0x70\n slab_err+0xb0/0xf0\n __kmem_cache_shutdown+0x15c/0x310\n kmem_cache_destroy+0x66/0x160\n nfsd_file_cache_shutdown+0xac/0x210 [nfsd]\n nfsd_destroy_serv+0x251/0x2a0 [nfsd]\n nfsd_svc+0x125/0x1e0 [nfsd]\n write_threads+0x16a/0x2a0 [nfsd]\n nfsctl_transaction_write+0x74/0xa0 [nfsd]\n vfs_write+0x1a5/0x6d0\n ksys_write+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n====================================================================\nBUG nfsd_file_mark (Tainted: G B W ): Objects remaining\nnfsd_file_mark on __kmem_cache_shutdown()\n--------------------------------------------------------------------\n\n dump_stack_lvl+0x53/0x70\n slab_err+0xb0/0xf0\n __kmem_cache_shutdown+0x15c/0x310\n kmem_cache_destroy+0x66/0x160\n nfsd_file_cache_shutdown+0xc8/0x210 [nfsd]\n nfsd_destroy_serv+0x251/0x2a0 [nfsd]\n nfsd_svc+0x125/0x1e0 [nfsd]\n write_threads+0x16a/0x2a0 [nfsd]\n nfsctl_transaction_write+0x74/0xa0 [nfsd]\n vfs_write+0x1a5/0x6d0\n ksys_write+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nTo resolve this issue, cancel `nfsd_shrinker_work` using synchronous\nmode in nfs4_state_shutdown_net.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50121", "url": "https://www.suse.com/security/cve/CVE-2024-50121" }, { "category": "external", "summary": "SUSE Bug 1232925 for CVE-2024-50121", "url": "https://bugzilla.suse.com/1232925" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50121" }, { "cve": "CVE-2024-50124", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50124" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: Fix UAF on iso_sock_timeout\n\nconn-\u003esk maybe have been unlinked/freed while waiting for iso_conn_lock\nso this checks if the conn-\u003esk is still valid by checking if it part of\niso_sk_list.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50124", "url": "https://www.suse.com/security/cve/CVE-2024-50124" }, { "category": "external", "summary": "SUSE Bug 1232926 for CVE-2024-50124", "url": "https://bugzilla.suse.com/1232926" }, { "category": "external", "summary": "SUSE Bug 1232927 for CVE-2024-50124", "url": "https://bugzilla.suse.com/1232927" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50124" }, { "cve": "CVE-2024-50125", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50125" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: Fix UAF on sco_sock_timeout\n\nconn-\u003esk maybe have been unlinked/freed while waiting for sco_conn_lock\nso this checks if the conn-\u003esk is still valid by checking if it part of\nsco_sk_list.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50125", "url": "https://www.suse.com/security/cve/CVE-2024-50125" }, { "category": "external", "summary": "SUSE Bug 1232928 for CVE-2024-50125", "url": "https://bugzilla.suse.com/1232928" }, { "category": "external", "summary": "SUSE Bug 1232929 for CVE-2024-50125", "url": "https://bugzilla.suse.com/1232929" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50125" }, { "cve": "CVE-2024-50127", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50127" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: fix use-after-free in taprio_change()\n\nIn \u0027taprio_change()\u0027, \u0027admin\u0027 pointer may become dangling due to sched\nswitch / removal caused by \u0027advance_sched()\u0027, and critical section\nprotected by \u0027q-\u003ecurrent_entry_lock\u0027 is too small to prevent from such\na scenario (which causes use-after-free detected by KASAN). Fix this\nby prefer \u0027rcu_replace_pointer()\u0027 over \u0027rcu_assign_pointer()\u0027 to update\n\u0027admin\u0027 immediately before an attempt to schedule freeing.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50127", "url": "https://www.suse.com/security/cve/CVE-2024-50127" }, { "category": "external", "summary": "SUSE Bug 1232907 for CVE-2024-50127", "url": "https://bugzilla.suse.com/1232907" }, { "category": "external", "summary": "SUSE Bug 1232908 for CVE-2024-50127", "url": "https://bugzilla.suse.com/1232908" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50127" }, { "cve": "CVE-2024-50128", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50128" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: fix global oob in wwan_rtnl_policy\n\nThe variable wwan_rtnl_link_ops assign a *bigger* maxtype which leads to\na global out-of-bounds read when parsing the netlink attributes. Exactly\nsame bug cause as the oob fixed in commit b33fb5b801c6 (\"net: qualcomm:\nrmnet: fix global oob in rmnet_policy\").\n\n==================================================================\nBUG: KASAN: global-out-of-bounds in validate_nla lib/nlattr.c:388 [inline]\nBUG: KASAN: global-out-of-bounds in __nla_validate_parse+0x19d7/0x29a0 lib/nlattr.c:603\nRead of size 1 at addr ffffffff8b09cb60 by task syz.1.66276/323862\n\nCPU: 0 PID: 323862 Comm: syz.1.66276 Not tainted 6.1.70 #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x177/0x231 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:284 [inline]\n print_report+0x14f/0x750 mm/kasan/report.c:395\n kasan_report+0x139/0x170 mm/kasan/report.c:495\n validate_nla lib/nlattr.c:388 [inline]\n __nla_validate_parse+0x19d7/0x29a0 lib/nlattr.c:603\n __nla_parse+0x3c/0x50 lib/nlattr.c:700\n nla_parse_nested_deprecated include/net/netlink.h:1269 [inline]\n __rtnl_newlink net/core/rtnetlink.c:3514 [inline]\n rtnl_newlink+0x7bc/0x1fd0 net/core/rtnetlink.c:3623\n rtnetlink_rcv_msg+0x794/0xef0 net/core/rtnetlink.c:6122\n netlink_rcv_skb+0x1de/0x420 net/netlink/af_netlink.c:2508\n netlink_unicast_kernel net/netlink/af_netlink.c:1326 [inline]\n netlink_unicast+0x74b/0x8c0 net/netlink/af_netlink.c:1352\n netlink_sendmsg+0x882/0xb90 net/netlink/af_netlink.c:1874\n sock_sendmsg_nosec net/socket.c:716 [inline]\n __sock_sendmsg net/socket.c:728 [inline]\n ____sys_sendmsg+0x5cc/0x8f0 net/socket.c:2499\n ___sys_sendmsg+0x21c/0x290 net/socket.c:2553\n __sys_sendmsg net/socket.c:2582 [inline]\n __do_sys_sendmsg net/socket.c:2591 [inline]\n __se_sys_sendmsg+0x19e/0x270 net/socket.c:2589\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x45/0x90 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\nRIP: 0033:0x7f67b19a24ad\nRSP: 002b:00007f67b17febb8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f67b1b45f80 RCX: 00007f67b19a24ad\nRDX: 0000000000000000 RSI: 0000000020005e40 RDI: 0000000000000004\nRBP: 00007f67b1a1e01d R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007ffd2513764f R14: 00007ffd251376e0 R15: 00007f67b17fed40\n \u003c/TASK\u003e\n\nThe buggy address belongs to the variable:\n wwan_rtnl_policy+0x20/0x40\n\nThe buggy address belongs to the physical page:\npage:ffffea00002c2700 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0xb09c\nflags: 0xfff00000001000(reserved|node=0|zone=1|lastcpupid=0x7ff)\nraw: 00fff00000001000 ffffea00002c2708 ffffea00002c2708 0000000000000000\nraw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner info is not present (never set?)\n\nMemory state around the buggy address:\n ffffffff8b09ca00: 05 f9 f9 f9 05 f9 f9 f9 00 01 f9 f9 00 01 f9 f9\n ffffffff8b09ca80: 00 00 00 05 f9 f9 f9 f9 00 00 03 f9 f9 f9 f9 f9\n\u003effffffff8b09cb00: 00 00 00 00 05 f9 f9 f9 00 00 00 00 f9 f9 f9 f9\n ^\n ffffffff8b09cb80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n==================================================================\n\nAccording to the comment of `nla_parse_nested_deprecated`, use correct size\n`IFLA_WWAN_MAX` here to fix this issue.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50128", "url": "https://www.suse.com/security/cve/CVE-2024-50128" }, { "category": "external", "summary": "SUSE Bug 1232905 for CVE-2024-50128", "url": "https://bugzilla.suse.com/1232905" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50128" }, { "cve": "CVE-2024-50130", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50130" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bpf: must hold reference on net namespace\n\nBUG: KASAN: slab-use-after-free in __nf_unregister_net_hook+0x640/0x6b0\nRead of size 8 at addr ffff8880106fe400 by task repro/72=\nbpf_nf_link_release+0xda/0x1e0\nbpf_link_free+0x139/0x2d0\nbpf_link_release+0x68/0x80\n__fput+0x414/0xb60\n\nEric says:\n It seems that bpf was able to defer the __nf_unregister_net_hook()\n after exit()/close() time.\n Perhaps a netns reference is missing, because the netns has been\n dismantled/freed already.\n bpf_nf_link_attach() does :\n link-\u003enet = net;\n But I do not see a reference being taken on net.\n\nAdd such a reference and release it after hook unreg.\nNote that I was unable to get syzbot reproducer to work, so I\ndo not know if this resolves this splat.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50130", "url": "https://www.suse.com/security/cve/CVE-2024-50130" }, { "category": "external", "summary": "SUSE Bug 1232894 for CVE-2024-50130", "url": "https://bugzilla.suse.com/1232894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50130" }, { "cve": "CVE-2024-50131", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50131" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Consider the NULL character when validating the event length\n\nstrlen() returns a string length excluding the null byte. If the string\nlength equals to the maximum buffer length, the buffer will have no\nspace for the NULL terminating character.\n\nThis commit checks this condition and returns failure for it.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50131", "url": "https://www.suse.com/security/cve/CVE-2024-50131" }, { "category": "external", "summary": "SUSE Bug 1232896 for CVE-2024-50131", "url": "https://bugzilla.suse.com/1232896" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50131" }, { "cve": "CVE-2024-50134", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50134" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vboxvideo: Replace fake VLA at end of vbva_mouse_pointer_shape with real VLA\n\nReplace the fake VLA at end of the vbva_mouse_pointer_shape shape with\na real VLA to fix a \"memcpy: detected field-spanning write error\" warning:\n\n[ 13.319813] memcpy: detected field-spanning write (size 16896) of single field \"p-\u003edata\" at drivers/gpu/drm/vboxvideo/hgsmi_base.c:154 (size 4)\n[ 13.319841] WARNING: CPU: 0 PID: 1105 at drivers/gpu/drm/vboxvideo/hgsmi_base.c:154 hgsmi_update_pointer_shape+0x192/0x1c0 [vboxvideo]\n[ 13.320038] Call Trace:\n[ 13.320173] hgsmi_update_pointer_shape [vboxvideo]\n[ 13.320184] vbox_cursor_atomic_update [vboxvideo]\n\nNote as mentioned in the added comment it seems the original length\ncalculation for the allocated and send hgsmi buffer is 4 bytes too large.\nChanging this is not the goal of this patch, so this behavior is kept.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50134", "url": "https://www.suse.com/security/cve/CVE-2024-50134" }, { "category": "external", "summary": "SUSE Bug 1232890 for CVE-2024-50134", "url": "https://bugzilla.suse.com/1232890" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50134" }, { "cve": "CVE-2024-50135", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50135" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix race condition between reset and nvme_dev_disable()\n\nnvme_dev_disable() modifies the dev-\u003eonline_queues field, therefore\nnvme_pci_update_nr_queues() should avoid racing against it, otherwise\nwe could end up passing invalid values to blk_mq_update_nr_hw_queues().\n\n WARNING: CPU: 39 PID: 61303 at drivers/pci/msi/api.c:347\n pci_irq_get_affinity+0x187/0x210\n Workqueue: nvme-reset-wq nvme_reset_work [nvme]\n RIP: 0010:pci_irq_get_affinity+0x187/0x210\n Call Trace:\n \u003cTASK\u003e\n ? blk_mq_pci_map_queues+0x87/0x3c0\n ? pci_irq_get_affinity+0x187/0x210\n blk_mq_pci_map_queues+0x87/0x3c0\n nvme_pci_map_queues+0x189/0x460 [nvme]\n blk_mq_update_nr_hw_queues+0x2a/0x40\n nvme_reset_work+0x1be/0x2a0 [nvme]\n\nFix the bug by locking the shutdown_lock mutex before using\ndev-\u003eonline_queues. Give up if nvme_dev_disable() is running or if\nit has been executed already.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50135", "url": "https://www.suse.com/security/cve/CVE-2024-50135" }, { "category": "external", "summary": "SUSE Bug 1232888 for CVE-2024-50135", "url": "https://bugzilla.suse.com/1232888" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50135" }, { "cve": "CVE-2024-50136", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50136" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Unregister notifier on eswitch init failure\n\nIt otherwise remains registered and a subsequent attempt at eswitch\nenabling might trigger warnings of the sort:\n\n[ 682.589148] ------------[ cut here ]------------\n[ 682.590204] notifier callback eswitch_vport_event [mlx5_core] already registered\n[ 682.590256] WARNING: CPU: 13 PID: 2660 at kernel/notifier.c:31 notifier_chain_register+0x3e/0x90\n[...snipped]\n[ 682.610052] Call Trace:\n[ 682.610369] \u003cTASK\u003e\n[ 682.610663] ? __warn+0x7c/0x110\n[ 682.611050] ? notifier_chain_register+0x3e/0x90\n[ 682.611556] ? report_bug+0x148/0x170\n[ 682.611977] ? handle_bug+0x36/0x70\n[ 682.612384] ? exc_invalid_op+0x13/0x60\n[ 682.612817] ? asm_exc_invalid_op+0x16/0x20\n[ 682.613284] ? notifier_chain_register+0x3e/0x90\n[ 682.613789] atomic_notifier_chain_register+0x25/0x40\n[ 682.614322] mlx5_eswitch_enable_locked+0x1d4/0x3b0 [mlx5_core]\n[ 682.614965] mlx5_eswitch_enable+0xc9/0x100 [mlx5_core]\n[ 682.615551] mlx5_device_enable_sriov+0x25/0x340 [mlx5_core]\n[ 682.616170] mlx5_core_sriov_configure+0x50/0x170 [mlx5_core]\n[ 682.616789] sriov_numvfs_store+0xb0/0x1b0\n[ 682.617248] kernfs_fop_write_iter+0x117/0x1a0\n[ 682.617734] vfs_write+0x231/0x3f0\n[ 682.618138] ksys_write+0x63/0xe0\n[ 682.618536] do_syscall_64+0x4c/0x100\n[ 682.618958] entry_SYSCALL_64_after_hwframe+0x4b/0x53", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50136", "url": "https://www.suse.com/security/cve/CVE-2024-50136" }, { "category": "external", "summary": "SUSE Bug 1232914 for CVE-2024-50136", "url": "https://bugzilla.suse.com/1232914" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50136" }, { "cve": "CVE-2024-50138", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50138" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Use raw_spinlock_t in ringbuf\n\nThe function __bpf_ringbuf_reserve is invoked from a tracepoint, which\ndisables preemption. Using spinlock_t in this context can lead to a\n\"sleep in atomic\" warning in the RT variant. This issue is illustrated\nin the example below:\n\nBUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48\nin_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 556208, name: test_progs\npreempt_count: 1, expected: 0\nRCU nest depth: 1, expected: 1\nINFO: lockdep is turned off.\nPreemption disabled at:\n[\u003cffffd33a5c88ea44\u003e] migrate_enable+0xc0/0x39c\nCPU: 7 PID: 556208 Comm: test_progs Tainted: G\nHardware name: Qualcomm SA8775P Ride (DT)\nCall trace:\n dump_backtrace+0xac/0x130\n show_stack+0x1c/0x30\n dump_stack_lvl+0xac/0xe8\n dump_stack+0x18/0x30\n __might_resched+0x3bc/0x4fc\n rt_spin_lock+0x8c/0x1a4\n __bpf_ringbuf_reserve+0xc4/0x254\n bpf_ringbuf_reserve_dynptr+0x5c/0xdc\n bpf_prog_ac3d15160d62622a_test_read_write+0x104/0x238\n trace_call_bpf+0x238/0x774\n perf_call_bpf_enter.isra.0+0x104/0x194\n perf_syscall_enter+0x2f8/0x510\n trace_sys_enter+0x39c/0x564\n syscall_trace_enter+0x220/0x3c0\n do_el0_svc+0x138/0x1dc\n el0_svc+0x54/0x130\n el0t_64_sync_handler+0x134/0x150\n el0t_64_sync+0x17c/0x180\n\nSwitch the spinlock to raw_spinlock_t to avoid this error.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50138", "url": "https://www.suse.com/security/cve/CVE-2024-50138" }, { "category": "external", "summary": "SUSE Bug 1232935 for CVE-2024-50138", "url": "https://bugzilla.suse.com/1232935" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50138" }, { "cve": "CVE-2024-50139", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50139" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Fix shift-out-of-bounds bug\n\nFix a shift-out-of-bounds bug reported by UBSAN when running\nVM with MTE enabled host kernel.\n\nUBSAN: shift-out-of-bounds in arch/arm64/kvm/sys_regs.c:1988:14\nshift exponent 33 is too large for 32-bit type \u0027int\u0027\nCPU: 26 UID: 0 PID: 7629 Comm: qemu-kvm Not tainted 6.12.0-rc2 #34\nHardware name: IEI NF5280R7/Mitchell MB, BIOS 00.00. 2024-10-12 09:28:54 10/14/2024\nCall trace:\n dump_backtrace+0xa0/0x128\n show_stack+0x20/0x38\n dump_stack_lvl+0x74/0x90\n dump_stack+0x18/0x28\n __ubsan_handle_shift_out_of_bounds+0xf8/0x1e0\n reset_clidr+0x10c/0x1c8\n kvm_reset_sys_regs+0x50/0x1c8\n kvm_reset_vcpu+0xec/0x2b0\n __kvm_vcpu_set_target+0x84/0x158\n kvm_vcpu_set_target+0x138/0x168\n kvm_arch_vcpu_ioctl_vcpu_init+0x40/0x2b0\n kvm_arch_vcpu_ioctl+0x28c/0x4b8\n kvm_vcpu_ioctl+0x4bc/0x7a8\n __arm64_sys_ioctl+0xb4/0x100\n invoke_syscall+0x70/0x100\n el0_svc_common.constprop.0+0x48/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x3c/0x158\n el0t_64_sync_handler+0x120/0x130\n el0t_64_sync+0x194/0x198", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50139", "url": "https://www.suse.com/security/cve/CVE-2024-50139" }, { "category": "external", "summary": "SUSE Bug 1233062 for CVE-2024-50139", "url": "https://bugzilla.suse.com/1233062" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50139" }, { "cve": "CVE-2024-50141", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50141" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: PRM: Find EFI_MEMORY_RUNTIME block for PRM handler and context\n\nPRMT needs to find the correct type of block to translate the PA-VA\nmapping for EFI runtime services.\n\nThe issue arises because the PRMT is finding a block of type\nEFI_CONVENTIONAL_MEMORY, which is not appropriate for runtime services\nas described in Section 2.2.2 (Runtime Services) of the UEFI\nSpecification [1]. Since the PRM handler is a type of runtime service,\nthis causes an exception when the PRM handler is called.\n\n [Firmware Bug]: Unable to handle paging request in EFI runtime service\n WARNING: CPU: 22 PID: 4330 at drivers/firmware/efi/runtime-wrappers.c:341\n __efi_queue_work+0x11c/0x170\n Call trace:\n\nLet PRMT find a block with EFI_MEMORY_RUNTIME for PRM handler and PRM\ncontext.\n\nIf no suitable block is found, a warning message will be printed, but\nthe procedure continues to manage the next PRM handler.\n\nHowever, if the PRM handler is actually called without proper allocation,\nit would result in a failure during error handling.\n\nBy using the correct memory types for runtime services, ensure that the\nPRM handler and the context are properly mapped in the virtual address\nspace during runtime, preventing the paging request error.\n\nThe issue is really that only memory that has been remapped for runtime\nby the firmware can be used by the PRM handler, and so the region needs\nto have the EFI_MEMORY_RUNTIME attribute.\n\n[ rjw: Subject and changelog edits ]", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50141", "url": "https://www.suse.com/security/cve/CVE-2024-50141" }, { "category": "external", "summary": "SUSE Bug 1233065 for CVE-2024-50141", "url": "https://bugzilla.suse.com/1233065" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50141" }, { "cve": "CVE-2024-50145", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50145" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteon_ep: Add SKB allocation failures handling in __octep_oq_process_rx()\n\nbuild_skb() returns NULL in case of a memory allocation failure so handle\nit inside __octep_oq_process_rx() to avoid NULL pointer dereference.\n\n__octep_oq_process_rx() is called during NAPI polling by the driver. If\nskb allocation fails, keep on pulling packets out of the Rx DMA queue: we\nshouldn\u0027t break the polling immediately and thus falsely indicate to the\noctep_napi_poll() that the Rx pressure is going down. As there is no\nassociated skb in this case, don\u0027t process the packets and don\u0027t push them\nup the network stack - they are skipped.\n\nHelper function is implemented to unmmap/flush all the fragment buffers\nused by the dropped packet. \u0027alloc_failures\u0027 counter is incremented to\nmark the skb allocation error in driver statistics.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50145", "url": "https://www.suse.com/security/cve/CVE-2024-50145" }, { "category": "external", "summary": "SUSE Bug 1233044 for CVE-2024-50145", "url": "https://bugzilla.suse.com/1233044" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50145" }, { "cve": "CVE-2024-50146", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50146" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Don\u0027t call cleanup on profile rollback failure\n\nWhen profile rollback fails in mlx5e_netdev_change_profile, the netdev\nprofile var is left set to NULL. Avoid a crash when unloading the driver\nby not calling profile-\u003ecleanup in such a case.\n\nThis was encountered while testing, with the original trigger that\nthe wq rescuer thread creation got interrupted (presumably due to\nCtrl+C-ing modprobe), which gets converted to ENOMEM (-12) by\nmlx5e_priv_init, the profile rollback also fails for the same reason\n(signal still active) so the profile is left as NULL, leading to a crash\nlater in _mlx5e_remove.\n\n [ 732.473932] mlx5_core 0000:08:00.1: E-Switch: Unload vfs: mode(OFFLOADS), nvfs(2), necvfs(0), active vports(2)\n [ 734.525513] workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\n [ 734.557372] mlx5_core 0000:08:00.1: mlx5e_netdev_init_profile:6235:(pid 6086): mlx5e_priv_init failed, err=-12\n [ 734.559187] mlx5_core 0000:08:00.1 eth3: mlx5e_netdev_change_profile: new profile init failed, -12\n [ 734.560153] workqueue: Failed to create a rescuer kthread for wq \"mlx5e\": -EINTR\n [ 734.589378] mlx5_core 0000:08:00.1: mlx5e_netdev_init_profile:6235:(pid 6086): mlx5e_priv_init failed, err=-12\n [ 734.591136] mlx5_core 0000:08:00.1 eth3: mlx5e_netdev_change_profile: failed to rollback to orig profile, -12\n [ 745.537492] BUG: kernel NULL pointer dereference, address: 0000000000000008\n [ 745.538222] #PF: supervisor read access in kernel mode\n\u003csnipped\u003e\n [ 745.551290] Call Trace:\n [ 745.551590] \u003cTASK\u003e\n [ 745.551866] ? __die+0x20/0x60\n [ 745.552218] ? page_fault_oops+0x150/0x400\n [ 745.555307] ? exc_page_fault+0x79/0x240\n [ 745.555729] ? asm_exc_page_fault+0x22/0x30\n [ 745.556166] ? mlx5e_remove+0x6b/0xb0 [mlx5_core]\n [ 745.556698] auxiliary_bus_remove+0x18/0x30\n [ 745.557134] device_release_driver_internal+0x1df/0x240\n [ 745.557654] bus_remove_device+0xd7/0x140\n [ 745.558075] device_del+0x15b/0x3c0\n [ 745.558456] mlx5_rescan_drivers_locked.part.0+0xb1/0x2f0 [mlx5_core]\n [ 745.559112] mlx5_unregister_device+0x34/0x50 [mlx5_core]\n [ 745.559686] mlx5_uninit_one+0x46/0xf0 [mlx5_core]\n [ 745.560203] remove_one+0x4e/0xd0 [mlx5_core]\n [ 745.560694] pci_device_remove+0x39/0xa0\n [ 745.561112] device_release_driver_internal+0x1df/0x240\n [ 745.561631] driver_detach+0x47/0x90\n [ 745.562022] bus_remove_driver+0x84/0x100\n [ 745.562444] pci_unregister_driver+0x3b/0x90\n [ 745.562890] mlx5_cleanup+0xc/0x1b [mlx5_core]\n [ 745.563415] __x64_sys_delete_module+0x14d/0x2f0\n [ 745.563886] ? kmem_cache_free+0x1b0/0x460\n [ 745.564313] ? lockdep_hardirqs_on_prepare+0xe2/0x190\n [ 745.564825] do_syscall_64+0x6d/0x140\n [ 745.565223] entry_SYSCALL_64_after_hwframe+0x4b/0x53\n [ 745.565725] RIP: 0033:0x7f1579b1288b", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50146", "url": "https://www.suse.com/security/cve/CVE-2024-50146" }, { "category": "external", "summary": "SUSE Bug 1233056 for CVE-2024-50146", "url": "https://bugzilla.suse.com/1233056" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50146" }, { "cve": "CVE-2024-50147", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50147" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix command bitmask initialization\n\nCommand bitmask have a dedicated bit for MANAGE_PAGES command, this bit\nisn\u0027t Initialize during command bitmask Initialization, only during\nMANAGE_PAGES.\n\nIn addition, mlx5_cmd_trigger_completions() is trying to trigger\ncompletion for MANAGE_PAGES command as well.\n\nHence, in case health error occurred before any MANAGE_PAGES command\nhave been invoke (for example, during mlx5_enable_hca()),\nmlx5_cmd_trigger_completions() will try to trigger completion for\nMANAGE_PAGES command, which will result in null-ptr-deref error.[1]\n\nFix it by Initialize command bitmask correctly.\n\nWhile at it, re-write the code for better understanding.\n\n[1]\nBUG: KASAN: null-ptr-deref in mlx5_cmd_trigger_completions+0x1db/0x600 [mlx5_core]\nWrite of size 4 at addr 0000000000000214 by task kworker/u96:2/12078\nCPU: 10 PID: 12078 Comm: kworker/u96:2 Not tainted 6.9.0-rc2_for_upstream_debug_2024_04_07_19_01 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nWorkqueue: mlx5_health0000:08:00.0 mlx5_fw_fatal_reporter_err_work [mlx5_core]\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x7e/0xc0\n kasan_report+0xb9/0xf0\n kasan_check_range+0xec/0x190\n mlx5_cmd_trigger_completions+0x1db/0x600 [mlx5_core]\n mlx5_cmd_flush+0x94/0x240 [mlx5_core]\n enter_error_state+0x6c/0xd0 [mlx5_core]\n mlx5_fw_fatal_reporter_err_work+0xf3/0x480 [mlx5_core]\n process_one_work+0x787/0x1490\n ? lockdep_hardirqs_on_prepare+0x400/0x400\n ? pwq_dec_nr_in_flight+0xda0/0xda0\n ? assign_work+0x168/0x240\n worker_thread+0x586/0xd30\n ? rescuer_thread+0xae0/0xae0\n kthread+0x2df/0x3b0\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x2d/0x70\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork_asm+0x11/0x20\n \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50147", "url": "https://www.suse.com/security/cve/CVE-2024-50147" }, { "category": "external", "summary": "SUSE Bug 1233067 for CVE-2024-50147", "url": "https://bugzilla.suse.com/1233067" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50147" }, { "cve": "CVE-2024-50148", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50148" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: bnep: fix wild-memory-access in proto_unregister\n\nThere\u0027s issue as follows:\n KASAN: maybe wild-memory-access in range [0xdead...108-0xdead...10f]\n CPU: 3 UID: 0 PID: 2805 Comm: rmmod Tainted: G W\n RIP: 0010:proto_unregister+0xee/0x400\n Call Trace:\n \u003cTASK\u003e\n __do_sys_delete_module+0x318/0x580\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nAs bnep_init() ignore bnep_sock_init()\u0027s return value, and bnep_sock_init()\nwill cleanup all resource. Then when remove bnep module will call\nbnep_sock_cleanup() to cleanup sock\u0027s resource.\nTo solve above issue just return bnep_sock_init()\u0027s return value in\nbnep_exit().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50148", "url": "https://www.suse.com/security/cve/CVE-2024-50148" }, { "category": "external", "summary": "SUSE Bug 1233063 for CVE-2024-50148", "url": "https://bugzilla.suse.com/1233063" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50148" }, { "cve": "CVE-2024-50150", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50150" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: altmode should keep reference to parent\n\nThe altmode device release refers to its parent device, but without keeping\na reference to it.\n\nWhen registering the altmode, get a reference to the parent and put it in\nthe release function.\n\nBefore this fix, when using CONFIG_DEBUG_KOBJECT_RELEASE, we see issues\nlike this:\n\n[ 43.572860] kobject: \u0027port0.0\u0027 (ffff8880057ba008): kobject_release, parent 0000000000000000 (delayed 3000)\n[ 43.573532] kobject: \u0027port0.1\u0027 (ffff8880057bd008): kobject_release, parent 0000000000000000 (delayed 1000)\n[ 43.574407] kobject: \u0027port0\u0027 (ffff8880057b9008): kobject_release, parent 0000000000000000 (delayed 3000)\n[ 43.575059] kobject: \u0027port1.0\u0027 (ffff8880057ca008): kobject_release, parent 0000000000000000 (delayed 4000)\n[ 43.575908] kobject: \u0027port1.1\u0027 (ffff8880057c9008): kobject_release, parent 0000000000000000 (delayed 4000)\n[ 43.576908] kobject: \u0027typec\u0027 (ffff8880062dbc00): kobject_release, parent 0000000000000000 (delayed 4000)\n[ 43.577769] kobject: \u0027port1\u0027 (ffff8880057bf008): kobject_release, parent 0000000000000000 (delayed 3000)\n[ 46.612867] ==================================================================\n[ 46.613402] BUG: KASAN: slab-use-after-free in typec_altmode_release+0x38/0x129\n[ 46.614003] Read of size 8 at addr ffff8880057b9118 by task kworker/2:1/48\n[ 46.614538]\n[ 46.614668] CPU: 2 UID: 0 PID: 48 Comm: kworker/2:1 Not tainted 6.12.0-rc1-00138-gedbae730ad31 #535\n[ 46.615391] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014\n[ 46.616042] Workqueue: events kobject_delayed_cleanup\n[ 46.616446] Call Trace:\n[ 46.616648] \u003cTASK\u003e\n[ 46.616820] dump_stack_lvl+0x5b/0x7c\n[ 46.617112] ? typec_altmode_release+0x38/0x129\n[ 46.617470] print_report+0x14c/0x49e\n[ 46.617769] ? rcu_read_unlock_sched+0x56/0x69\n[ 46.618117] ? __virt_addr_valid+0x19a/0x1ab\n[ 46.618456] ? kmem_cache_debug_flags+0xc/0x1d\n[ 46.618807] ? typec_altmode_release+0x38/0x129\n[ 46.619161] kasan_report+0x8d/0xb4\n[ 46.619447] ? typec_altmode_release+0x38/0x129\n[ 46.619809] ? process_scheduled_works+0x3cb/0x85f\n[ 46.620185] typec_altmode_release+0x38/0x129\n[ 46.620537] ? process_scheduled_works+0x3cb/0x85f\n[ 46.620907] device_release+0xaf/0xf2\n[ 46.621206] kobject_delayed_cleanup+0x13b/0x17a\n[ 46.621584] process_scheduled_works+0x4f6/0x85f\n[ 46.621955] ? __pfx_process_scheduled_works+0x10/0x10\n[ 46.622353] ? hlock_class+0x31/0x9a\n[ 46.622647] ? lock_acquired+0x361/0x3c3\n[ 46.622956] ? move_linked_works+0x46/0x7d\n[ 46.623277] worker_thread+0x1ce/0x291\n[ 46.623582] ? __kthread_parkme+0xc8/0xdf\n[ 46.623900] ? __pfx_worker_thread+0x10/0x10\n[ 46.624236] kthread+0x17e/0x190\n[ 46.624501] ? kthread+0xfb/0x190\n[ 46.624756] ? __pfx_kthread+0x10/0x10\n[ 46.625015] ret_from_fork+0x20/0x40\n[ 46.625268] ? __pfx_kthread+0x10/0x10\n[ 46.625532] ret_from_fork_asm+0x1a/0x30\n[ 46.625805] \u003c/TASK\u003e\n[ 46.625953]\n[ 46.626056] Allocated by task 678:\n[ 46.626287] kasan_save_stack+0x24/0x44\n[ 46.626555] kasan_save_track+0x14/0x2d\n[ 46.626811] __kasan_kmalloc+0x3f/0x4d\n[ 46.627049] __kmalloc_noprof+0x1bf/0x1f0\n[ 46.627362] typec_register_port+0x23/0x491\n[ 46.627698] cros_typec_probe+0x634/0xbb6\n[ 46.628026] platform_probe+0x47/0x8c\n[ 46.628311] really_probe+0x20a/0x47d\n[ 46.628605] device_driver_attach+0x39/0x72\n[ 46.628940] bind_store+0x87/0xd7\n[ 46.629213] kernfs_fop_write_iter+0x1aa/0x218\n[ 46.629574] vfs_write+0x1d6/0x29b\n[ 46.629856] ksys_write+0xcd/0x13b\n[ 46.630128] do_syscall_64+0xd4/0x139\n[ 46.630420] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 46.630820]\n[ 46.630946] Freed by task 48:\n[ 46.631182] kasan_save_stack+0x24/0x44\n[ 46.631493] kasan_save_track+0x14/0x2d\n[ 46.631799] kasan_save_free_info+0x3f/0x4d\n[ 46.632144] __kasan_slab_free+0x37/0x45\n[ 46.632474]\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50150", "url": "https://www.suse.com/security/cve/CVE-2024-50150" }, { "category": "external", "summary": "SUSE Bug 1233051 for CVE-2024-50150", "url": "https://bugzilla.suse.com/1233051" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50150" }, { "cve": "CVE-2024-50153", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50153" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Fix null-ptr-deref in target_alloc_device()\n\nThere is a null-ptr-deref issue reported by KASAN:\n\nBUG: KASAN: null-ptr-deref in target_alloc_device+0xbc4/0xbe0 [target_core_mod]\n...\n kasan_report+0xb9/0xf0\n target_alloc_device+0xbc4/0xbe0 [target_core_mod]\n core_dev_setup_virtual_lun0+0xef/0x1f0 [target_core_mod]\n target_core_init_configfs+0x205/0x420 [target_core_mod]\n do_one_initcall+0xdd/0x4e0\n...\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nIn target_alloc_device(), if allocing memory for dev queues fails, then\ndev will be freed by dev-\u003etransport-\u003efree_device(), but dev-\u003etransport\nis not initialized at that time, which will lead to a null pointer\nreference problem.\n\nFixing this bug by freeing dev with hba-\u003ebackend-\u003eops-\u003efree_device().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50153", "url": "https://www.suse.com/security/cve/CVE-2024-50153" }, { "category": "external", "summary": "SUSE Bug 1233061 for CVE-2024-50153", "url": "https://bugzilla.suse.com/1233061" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50153" }, { "cve": "CVE-2024-50154", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50154" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp/dccp: Don\u0027t use timer_pending() in reqsk_queue_unlink().\n\nMartin KaFai Lau reported use-after-free [0] in reqsk_timer_handler().\n\n \"\"\"\n We are seeing a use-after-free from a bpf prog attached to\n trace_tcp_retransmit_synack. The program passes the req-\u003esk to the\n bpf_sk_storage_get_tracing kernel helper which does check for null\n before using it.\n \"\"\"\n\nThe commit 83fccfc3940c (\"inet: fix potential deadlock in\nreqsk_queue_unlink()\") added timer_pending() in reqsk_queue_unlink() not\nto call del_timer_sync() from reqsk_timer_handler(), but it introduced a\nsmall race window.\n\nBefore the timer is called, expire_timers() calls detach_timer(timer, true)\nto clear timer-\u003eentry.pprev and marks it as not pending.\n\nIf reqsk_queue_unlink() checks timer_pending() just after expire_timers()\ncalls detach_timer(), TCP will miss del_timer_sync(); the reqsk timer will\ncontinue running and send multiple SYN+ACKs until it expires.\n\nThe reported UAF could happen if req-\u003esk is close()d earlier than the timer\nexpiration, which is 63s by default.\n\nThe scenario would be\n\n 1. inet_csk_complete_hashdance() calls inet_csk_reqsk_queue_drop(),\n but del_timer_sync() is missed\n\n 2. reqsk timer is executed and scheduled again\n\n 3. req-\u003esk is accept()ed and reqsk_put() decrements rsk_refcnt, but\n reqsk timer still has another one, and inet_csk_accept() does not\n clear req-\u003esk for non-TFO sockets\n\n 4. sk is close()d\n\n 5. reqsk timer is executed again, and BPF touches req-\u003esk\n\nLet\u0027s not use timer_pending() by passing the caller context to\n__inet_csk_reqsk_queue_drop().\n\nNote that reqsk timer is pinned, so the issue does not happen in most\nuse cases. [1]\n\n[0]\nBUG: KFENCE: use-after-free read in bpf_sk_storage_get_tracing+0x2e/0x1b0\n\nUse-after-free read at 0x00000000a891fb3a (in kfence-#1):\nbpf_sk_storage_get_tracing+0x2e/0x1b0\nbpf_prog_5ea3e95db6da0438_tcp_retransmit_synack+0x1d20/0x1dda\nbpf_trace_run2+0x4c/0xc0\ntcp_rtx_synack+0xf9/0x100\nreqsk_timer_handler+0xda/0x3d0\nrun_timer_softirq+0x292/0x8a0\nirq_exit_rcu+0xf5/0x320\nsysvec_apic_timer_interrupt+0x6d/0x80\nasm_sysvec_apic_timer_interrupt+0x16/0x20\nintel_idle_irq+0x5a/0xa0\ncpuidle_enter_state+0x94/0x273\ncpu_startup_entry+0x15e/0x260\nstart_secondary+0x8a/0x90\nsecondary_startup_64_no_verify+0xfa/0xfb\n\nkfence-#1: 0x00000000a72cc7b6-0x00000000d97616d9, size=2376, cache=TCPv6\n\nallocated by task 0 on cpu 9 at 260507.901592s:\nsk_prot_alloc+0x35/0x140\nsk_clone_lock+0x1f/0x3f0\ninet_csk_clone_lock+0x15/0x160\ntcp_create_openreq_child+0x1f/0x410\ntcp_v6_syn_recv_sock+0x1da/0x700\ntcp_check_req+0x1fb/0x510\ntcp_v6_rcv+0x98b/0x1420\nipv6_list_rcv+0x2258/0x26e0\nnapi_complete_done+0x5b1/0x2990\nmlx5e_napi_poll+0x2ae/0x8d0\nnet_rx_action+0x13e/0x590\nirq_exit_rcu+0xf5/0x320\ncommon_interrupt+0x80/0x90\nasm_common_interrupt+0x22/0x40\ncpuidle_enter_state+0xfb/0x273\ncpu_startup_entry+0x15e/0x260\nstart_secondary+0x8a/0x90\nsecondary_startup_64_no_verify+0xfa/0xfb\n\nfreed by task 0 on cpu 9 at 260507.927527s:\nrcu_core_si+0x4ff/0xf10\nirq_exit_rcu+0xf5/0x320\nsysvec_apic_timer_interrupt+0x6d/0x80\nasm_sysvec_apic_timer_interrupt+0x16/0x20\ncpuidle_enter_state+0xfb/0x273\ncpu_startup_entry+0x15e/0x260\nstart_secondary+0x8a/0x90\nsecondary_startup_64_no_verify+0xfa/0xfb", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50154", "url": "https://www.suse.com/security/cve/CVE-2024-50154" }, { "category": "external", "summary": "SUSE Bug 1233070 for CVE-2024-50154", "url": "https://bugzilla.suse.com/1233070" }, { "category": "external", "summary": "SUSE Bug 1233072 for CVE-2024-50154", "url": "https://bugzilla.suse.com/1233072" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50154" }, { "cve": "CVE-2024-50155", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50155" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetdevsim: use cond_resched() in nsim_dev_trap_report_work()\n\nI am still seeing many syzbot reports hinting that syzbot\nmight fool nsim_dev_trap_report_work() with hundreds of ports [1]\n\nLets use cond_resched(), and system_unbound_wq\ninstead of implicit system_wq.\n\n[1]\nINFO: task syz-executor:20633 blocked for more than 143 seconds.\n Not tainted 6.12.0-rc2-syzkaller-00205-g1d227fcc7222 #0\n\"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:syz-executor state:D stack:25856 pid:20633 tgid:20633 ppid:1 flags:0x00004006\n...\nNMI backtrace for cpu 1\nCPU: 1 UID: 0 PID: 16760 Comm: kworker/1:0 Not tainted 6.12.0-rc2-syzkaller-00205-g1d227fcc7222 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nWorkqueue: events nsim_dev_trap_report_work\n RIP: 0010:__sanitizer_cov_trace_pc+0x0/0x70 kernel/kcov.c:210\nCode: 89 fb e8 23 00 00 00 48 8b 3d 04 fb 9c 0c 48 89 de 5b e9 c3 c7 5d 00 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 \u003cf3\u003e 0f 1e fa 48 8b 04 24 65 48 8b 0c 25 c0 d7 03 00 65 8b 15 60 f0\nRSP: 0018:ffffc90000a187e8 EFLAGS: 00000246\nRAX: 0000000000000100 RBX: ffffc90000a188e0 RCX: ffff888027d3bc00\nRDX: ffff888027d3bc00 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffff88804a2e6000 R08: ffffffff8a4bc495 R09: ffffffff89da3577\nR10: 0000000000000004 R11: ffffffff8a4bc2b0 R12: dffffc0000000000\nR13: ffff88806573b503 R14: dffffc0000000000 R15: ffff8880663cca00\nFS: 0000000000000000(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fc90a747f98 CR3: 000000000e734000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 000000000000002b DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400\nCall Trace:\n \u003cNMI\u003e\n \u003c/NMI\u003e\n \u003cTASK\u003e\n __local_bh_enable_ip+0x1bb/0x200 kernel/softirq.c:382\n spin_unlock_bh include/linux/spinlock.h:396 [inline]\n nsim_dev_trap_report drivers/net/netdevsim/dev.c:820 [inline]\n nsim_dev_trap_report_work+0x75d/0xaa0 drivers/net/netdevsim/dev.c:850\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa63/0x1850 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50155", "url": "https://www.suse.com/security/cve/CVE-2024-50155" }, { "category": "external", "summary": "SUSE Bug 1233035 for CVE-2024-50155", "url": "https://bugzilla.suse.com/1233035" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50155" }, { "cve": "CVE-2024-50156", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50156" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Avoid NULL dereference in msm_disp_state_print_regs()\n\nIf the allocation in msm_disp_state_dump_regs() failed then\n`block-\u003estate` can be NULL. The msm_disp_state_print_regs() function\n_does_ have code to try to handle it with:\n\n if (*reg)\n dump_addr = *reg;\n\n...but since \"dump_addr\" is initialized to NULL the above is actually\na noop. The code then goes on to dereference `dump_addr`.\n\nMake the function print \"Registers not stored\" when it sees a NULL to\nsolve this. Since we\u0027re touching the code, fix\nmsm_disp_state_print_regs() not to pointlessly take a double-pointer\nand properly mark the pointer as `const`.\n\nPatchwork: https://patchwork.freedesktop.org/patch/619657/", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50156", "url": "https://www.suse.com/security/cve/CVE-2024-50156" }, { "category": "external", "summary": "SUSE Bug 1233073 for CVE-2024-50156", "url": "https://bugzilla.suse.com/1233073" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50156" }, { "cve": "CVE-2024-50157", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50157" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop\n\nDriver waits indefinitely for the fifo occupancy to go below a threshold\nas soon as the pacing interrupt is received. This can cause soft lockup on\none of the processors, if the rate of DB is very high.\n\nAdd a loop count for FPGA and exit the __wait_for_fifo_occupancy_below_th\nif the loop is taking more time. Pacing will be continuing until the\noccupancy is below the threshold. This is ensured by the checks in\nbnxt_re_pacing_timer_exp and further scheduling the work for pacing based\non the fifo occupancy.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50157", "url": "https://www.suse.com/security/cve/CVE-2024-50157" }, { "category": "external", "summary": "SUSE Bug 1233032 for CVE-2024-50157", "url": "https://bugzilla.suse.com/1233032" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50157" }, { "cve": "CVE-2024-50158", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50158" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Fix out of bound check\n\nDriver exports pacing stats only on GenP5 and P7 adapters. But while\nparsing the pacing stats, driver has a check for \"rdev-\u003edbr_pacing\". This\ncaused a trace when KASAN is enabled.\n\nBUG: KASAN: slab-out-of-bounds in bnxt_re_get_hw_stats+0x2b6a/0x2e00 [bnxt_re]\nWrite of size 8 at addr ffff8885942a6340 by task modprobe/4809", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50158", "url": "https://www.suse.com/security/cve/CVE-2024-50158" }, { "category": "external", "summary": "SUSE Bug 1233036 for CVE-2024-50158", "url": "https://bugzilla.suse.com/1233036" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50158" }, { "cve": "CVE-2024-50159", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50159" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix the double free in scmi_debugfs_common_setup()\n\nClang static checker(scan-build) throws below warning:\n | drivers/firmware/arm_scmi/driver.c:line 2915, column 2\n | Attempt to free released memory.\n\nWhen devm_add_action_or_reset() fails, scmi_debugfs_common_cleanup()\nwill run twice which causes double free of \u0027dbg-\u003ename\u0027.\n\nRemove the redundant scmi_debugfs_common_cleanup() to fix this problem.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50159", "url": "https://www.suse.com/security/cve/CVE-2024-50159" }, { "category": "external", "summary": "SUSE Bug 1233041 for CVE-2024-50159", "url": "https://bugzilla.suse.com/1233041" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50159" }, { "cve": "CVE-2024-50160", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50160" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/cs8409: Fix possible NULL dereference\n\nIf snd_hda_gen_add_kctl fails to allocate memory and returns NULL, then\nNULL pointer dereference will occur in the next line.\n\nSince dolphin_fixups function is a hda_fixup function which is not supposed\nto return any errors, add simple check before dereference, ignore the fail.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50160", "url": "https://www.suse.com/security/cve/CVE-2024-50160" }, { "category": "external", "summary": "SUSE Bug 1233074 for CVE-2024-50160", "url": "https://bugzilla.suse.com/1233074" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50160" }, { "cve": "CVE-2024-50166", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50166" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfsl/fman: Fix refcount handling of fman-related devices\n\nIn mac_probe() there are multiple calls to of_find_device_by_node(),\nfman_bind() and fman_port_bind() which takes references to of_dev-\u003edev.\nNot all references taken by these calls are released later on error path\nin mac_probe() and in mac_remove() which lead to reference leaks.\n\nAdd references release.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50166", "url": "https://www.suse.com/security/cve/CVE-2024-50166" }, { "category": "external", "summary": "SUSE Bug 1233050 for CVE-2024-50166", "url": "https://bugzilla.suse.com/1233050" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50166" }, { "cve": "CVE-2024-50167", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50167" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbe2net: fix potential memory leak in be_xmit()\n\nThe be_xmit() returns NETDEV_TX_OK without freeing skb\nin case of be_xmit_enqueue() fails, add dev_kfree_skb_any() to fix it.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50167", "url": "https://www.suse.com/security/cve/CVE-2024-50167" }, { "category": "external", "summary": "SUSE Bug 1233049 for CVE-2024-50167", "url": "https://bugzilla.suse.com/1233049" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50167" }, { "cve": "CVE-2024-50169", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50169" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Update rx_bytes on read_skb()\n\nMake sure virtio_transport_inc_rx_pkt() and virtio_transport_dec_rx_pkt()\ncalls are balanced (i.e. virtio_vsock_sock::rx_bytes doesn\u0027t lie) after\nvsock_transport::read_skb().\n\nWhile here, also inform the peer that we\u0027ve freed up space and it has more\ncredit.\n\nFailing to update rx_bytes after packet is dequeued leads to a warning on\nSOCK_STREAM recv():\n\n[ 233.396654] rx_queue is empty, but rx_bytes is non-zero\n[ 233.396702] WARNING: CPU: 11 PID: 40601 at net/vmw_vsock/virtio_transport_common.c:589", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50169", "url": "https://www.suse.com/security/cve/CVE-2024-50169" }, { "category": "external", "summary": "SUSE Bug 1233320 for CVE-2024-50169", "url": "https://bugzilla.suse.com/1233320" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50169" }, { "cve": "CVE-2024-50171", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50171" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: systemport: fix potential memory leak in bcm_sysport_xmit()\n\nThe bcm_sysport_xmit() returns NETDEV_TX_OK without freeing skb\nin case of dma_map_single() fails, add dev_kfree_skb() to fix it.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50171", "url": "https://www.suse.com/security/cve/CVE-2024-50171" }, { "category": "external", "summary": "SUSE Bug 1233057 for CVE-2024-50171", "url": "https://bugzilla.suse.com/1233057" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50171" }, { "cve": "CVE-2024-50172", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50172" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Fix a possible memory leak\n\nIn bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails\ndriver is not freeing the memory allocated for \"rdev-\u003echip_ctx\".", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50172", "url": "https://www.suse.com/security/cve/CVE-2024-50172" }, { "category": "external", "summary": "SUSE Bug 1233029 for CVE-2024-50172", "url": "https://bugzilla.suse.com/1233029" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50172" }, { "cve": "CVE-2024-50175", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50175" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: qcom: camss: Remove use_count guard in stop_streaming\n\nThe use_count check was introduced so that multiple concurrent Raw Data\nInterfaces RDIs could be driven by different virtual channels VCs on the\nCSIPHY input driving the video pipeline.\n\nThis is an invalid use of use_count though as use_count pertains to the\nnumber of times a video entity has been opened by user-space not the number\nof active streams.\n\nIf use_count and stream-on count don\u0027t agree then stop_streaming() will\nbreak as is currently the case and has become apparent when using CAMSS\nwith libcamera\u0027s released softisp 0.3.\n\nThe use of use_count like this is a bit hacky and right now breaks regular\nusage of CAMSS for a single stream case. Stopping qcam results in the splat\nbelow, and then it cannot be started again and any attempts to do so fails\nwith -EBUSY.\n\n[ 1265.509831] WARNING: CPU: 5 PID: 919 at drivers/media/common/videobuf2/videobuf2-core.c:2183 __vb2_queue_cancel+0x230/0x2c8 [videobuf2_common]\n...\n[ 1265.510630] Call trace:\n[ 1265.510636] __vb2_queue_cancel+0x230/0x2c8 [videobuf2_common]\n[ 1265.510648] vb2_core_streamoff+0x24/0xcc [videobuf2_common]\n[ 1265.510660] vb2_ioctl_streamoff+0x5c/0xa8 [videobuf2_v4l2]\n[ 1265.510673] v4l_streamoff+0x24/0x30 [videodev]\n[ 1265.510707] __video_do_ioctl+0x190/0x3f4 [videodev]\n[ 1265.510732] video_usercopy+0x304/0x8c4 [videodev]\n[ 1265.510757] video_ioctl2+0x18/0x34 [videodev]\n[ 1265.510782] v4l2_ioctl+0x40/0x60 [videodev]\n...\n[ 1265.510944] videobuf2_common: driver bug: stop_streaming operation is leaving buffer 0 in active state\n[ 1265.511175] videobuf2_common: driver bug: stop_streaming operation is leaving buffer 1 in active state\n[ 1265.511398] videobuf2_common: driver bug: stop_streaming operation is leaving buffer 2 in active st\n\nOne CAMSS specific way to handle multiple VCs on the same RDI might be:\n\n- Reference count each pipeline enable for CSIPHY, CSID, VFE and RDIx.\n- The video buffers are already associated with msm_vfeN_rdiX so\n release video buffers when told to do so by stop_streaming.\n- Only release the power-domains for the CSIPHY, CSID and VFE when\n their internal refcounts drop.\n\nEither way refusing to release video buffers based on use_count is\nerroneous and should be reverted. The silicon enabling code for selecting\nVCs is perfectly fine. Its a \"known missing feature\" that concurrent VCs\nwon\u0027t work with CAMSS right now.\n\nInitial testing with this code didn\u0027t show an error but, SoftISP and \"real\"\nusage with Google Hangouts breaks the upstream code pretty quickly, we need\nto do a partial revert and take another pass at VCs.\n\nThis commit partially reverts commit 89013969e232 (\"media: camss: sm8250:\nPipeline starting and stopping for multiple virtual channels\")", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50175", "url": "https://www.suse.com/security/cve/CVE-2024-50175" }, { "category": "external", "summary": "SUSE Bug 1233092 for CVE-2024-50175", "url": "https://bugzilla.suse.com/1233092" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50175" }, { "cve": "CVE-2024-50176", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50176" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: k3-r5: Fix error handling when power-up failed\n\nBy simply bailing out, the driver was violating its rule and internal\nassumptions that either both or no rproc should be initialized. E.g.,\nthis could cause the first core to be available but not the second one,\nleading to crashes on its shutdown later on while trying to dereference\nthat second instance.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50176", "url": "https://www.suse.com/security/cve/CVE-2024-50176" }, { "category": "external", "summary": "SUSE Bug 1233091 for CVE-2024-50176", "url": "https://bugzilla.suse.com/1233091" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50176" }, { "cve": "CVE-2024-50177", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50177" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix a UBSAN warning in DML2.1\n\nWhen programming phantom pipe, since cursor_width is explicity set to 0,\nthis causes calculation logic to trigger overflow for an unsigned int\ntriggering the kernel\u0027s UBSAN check as below:\n\n[ 40.962845] UBSAN: shift-out-of-bounds in /tmp/amd.EfpumTkO/amd/amdgpu/../display/dc/dml2/dml21/src/dml2_core/dml2_core_dcn4_calcs.c:3312:34\n[ 40.962849] shift exponent 4294967170 is too large for 32-bit type \u0027unsigned int\u0027\n[ 40.962852] CPU: 1 PID: 1670 Comm: gnome-shell Tainted: G W OE 6.5.0-41-generic #41~22.04.2-Ubuntu\n[ 40.962854] Hardware name: Gigabyte Technology Co., Ltd. X670E AORUS PRO X/X670E AORUS PRO X, BIOS F21 01/10/2024\n[ 40.962856] Call Trace:\n[ 40.962857] \u003cTASK\u003e\n[ 40.962860] dump_stack_lvl+0x48/0x70\n[ 40.962870] dump_stack+0x10/0x20\n[ 40.962872] __ubsan_handle_shift_out_of_bounds+0x1ac/0x360\n[ 40.962878] calculate_cursor_req_attributes.cold+0x1b/0x28 [amdgpu]\n[ 40.963099] dml_core_mode_support+0x6b91/0x16bc0 [amdgpu]\n[ 40.963327] ? srso_alias_return_thunk+0x5/0x7f\n[ 40.963331] ? CalculateWatermarksMALLUseAndDRAMSpeedChangeSupport+0x18b8/0x2790 [amdgpu]\n[ 40.963534] ? srso_alias_return_thunk+0x5/0x7f\n[ 40.963536] ? dml_core_mode_support+0xb3db/0x16bc0 [amdgpu]\n[ 40.963730] dml2_core_calcs_mode_support_ex+0x2c/0x90 [amdgpu]\n[ 40.963906] ? srso_alias_return_thunk+0x5/0x7f\n[ 40.963909] ? dml2_core_calcs_mode_support_ex+0x2c/0x90 [amdgpu]\n[ 40.964078] core_dcn4_mode_support+0x72/0xbf0 [amdgpu]\n[ 40.964247] dml2_top_optimization_perform_optimization_phase+0x1d3/0x2a0 [amdgpu]\n[ 40.964420] dml2_build_mode_programming+0x23d/0x750 [amdgpu]\n[ 40.964587] dml21_validate+0x274/0x770 [amdgpu]\n[ 40.964761] ? srso_alias_return_thunk+0x5/0x7f\n[ 40.964763] ? resource_append_dpp_pipes_for_plane_composition+0x27c/0x3b0 [amdgpu]\n[ 40.964942] dml2_validate+0x504/0x750 [amdgpu]\n[ 40.965117] ? dml21_copy+0x95/0xb0 [amdgpu]\n[ 40.965291] ? srso_alias_return_thunk+0x5/0x7f\n[ 40.965295] dcn401_validate_bandwidth+0x4e/0x70 [amdgpu]\n[ 40.965491] update_planes_and_stream_state+0x38d/0x5c0 [amdgpu]\n[ 40.965672] update_planes_and_stream_v3+0x52/0x1e0 [amdgpu]\n[ 40.965845] ? srso_alias_return_thunk+0x5/0x7f\n[ 40.965849] dc_update_planes_and_stream+0x71/0xb0 [amdgpu]\n\nFix this by adding a guard for checking cursor width before triggering\nthe size calculation.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50177", "url": "https://www.suse.com/security/cve/CVE-2024-50177" }, { "category": "external", "summary": "SUSE Bug 1233115 for CVE-2024-50177", "url": "https://bugzilla.suse.com/1233115" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50177" }, { "cve": "CVE-2024-50179", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50179" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: remove the incorrect Fw reference check when dirtying pages\n\nWhen doing the direct-io reads it will also try to mark pages dirty,\nbut for the read path it won\u0027t hold the Fw caps and there is case\nwill it get the Fw reference.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50179", "url": "https://www.suse.com/security/cve/CVE-2024-50179" }, { "category": "external", "summary": "SUSE Bug 1233123 for CVE-2024-50179", "url": "https://bugzilla.suse.com/1233123" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50179" }, { "cve": "CVE-2024-50180", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50180" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: sisfb: Fix strbuf array overflow\n\nThe values of the variables xres and yres are placed in strbuf.\nThese variables are obtained from strbuf1.\nThe strbuf1 array contains digit characters\nand a space if the array contains non-digit characters.\nThen, when executing sprintf(strbuf, \"%ux%ux8\", xres, yres);\nmore than 16 bytes will be written to strbuf.\nIt is suggested to increase the size of the strbuf array to 24.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50180", "url": "https://www.suse.com/security/cve/CVE-2024-50180" }, { "category": "external", "summary": "SUSE Bug 1233125 for CVE-2024-50180", "url": "https://bugzilla.suse.com/1233125" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50180" }, { "cve": "CVE-2024-50181", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50181" } ], "notes": [ { "category": "general", "text": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50181", "url": "https://www.suse.com/security/cve/CVE-2024-50181" }, { "category": "external", "summary": "SUSE Bug 1233127 for CVE-2024-50181", "url": "https://bugzilla.suse.com/1233127" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50181" }, { "cve": "CVE-2024-50182", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50182" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsecretmem: disable memfd_secret() if arch cannot set direct map\n\nReturn -ENOSYS from memfd_secret() syscall if !can_set_direct_map(). This\nis the case for example on some arm64 configurations, where marking 4k\nPTEs in the direct map not present can only be done if the direct map is\nset up at 4k granularity in the first place (as ARM\u0027s break-before-make\nsemantics do not easily allow breaking apart large/gigantic pages).\n\nMore precisely, on arm64 systems with !can_set_direct_map(),\nset_direct_map_invalid_noflush() is a no-op, however it returns success\n(0) instead of an error. This means that memfd_secret will seemingly\n\"work\" (e.g. syscall succeeds, you can mmap the fd and fault in pages),\nbut it does not actually achieve its goal of removing its memory from the\ndirect map.\n\nNote that with this patch, memfd_secret() will start erroring on systems\nwhere can_set_direct_map() returns false (arm64 with\nCONFIG_RODATA_FULL_DEFAULT_ENABLED=n, CONFIG_DEBUG_PAGEALLOC=n and\nCONFIG_KFENCE=n), but that still seems better than the current silent\nfailure. Since CONFIG_RODATA_FULL_DEFAULT_ENABLED defaults to \u0027y\u0027, most\narm64 systems actually have a working memfd_secret() and aren\u0027t be\naffected.\n\nFrom going through the iterations of the original memfd_secret patch\nseries, it seems that disabling the syscall in these scenarios was the\nintended behavior [1] (preferred over having\nset_direct_map_invalid_noflush return an error as that would result in\nSIGBUSes at page-fault time), however the check for it got dropped between\nv16 [2] and v17 [3], when secretmem moved away from CMA allocations.\n\n[1]: https://lore.kernel.org/lkml/20201124164930.GK8537@kernel.org/\n[2]: https://lore.kernel.org/lkml/20210121122723.3446-11-rppt@kernel.org/#t\n[3]: https://lore.kernel.org/lkml/20201125092208.12544-10-rppt@kernel.org/", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50182", "url": "https://www.suse.com/security/cve/CVE-2024-50182" }, { "category": "external", "summary": "SUSE Bug 1233129 for CVE-2024-50182", "url": "https://bugzilla.suse.com/1233129" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50182" }, { "cve": "CVE-2024-50183", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50183" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instance\n\nDeleting an NPIV instance requires all fabric ndlps to be released before\nan NPIV\u0027s resources can be torn down. Failure to release fabric ndlps\nbeforehand opens kref imbalance race conditions. Fix by forcing the DA_ID\nto complete synchronously with usage of wait_queue.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50183", "url": "https://www.suse.com/security/cve/CVE-2024-50183" }, { "category": "external", "summary": "SUSE Bug 1233130 for CVE-2024-50183", "url": "https://bugzilla.suse.com/1233130" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50183" }, { "cve": "CVE-2024-50184", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50184" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_pmem: Check device status before requesting flush\n\nIf a pmem device is in a bad status, the driver side could wait for\nhost ack forever in virtio_pmem_flush(), causing the system to hang.\n\nSo add a status check in the beginning of virtio_pmem_flush() to return\nearly if the device is not activated.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50184", "url": "https://www.suse.com/security/cve/CVE-2024-50184" }, { "category": "external", "summary": "SUSE Bug 1233135 for CVE-2024-50184", "url": "https://bugzilla.suse.com/1233135" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50184" }, { "cve": "CVE-2024-50186", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50186" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: explicitly clear the sk pointer, when pf-\u003ecreate fails\n\nWe have recently noticed the exact same KASAN splat as in commit\n6cd4a78d962b (\"net: do not leave a dangling sk pointer, when socket\ncreation fails\"). The problem is that commit did not fully address the\nproblem, as some pf-\u003ecreate implementations do not use sk_common_release\nin their error paths.\n\nFor example, we can use the same reproducer as in the above commit, but\nchanging ping to arping. arping uses AF_PACKET socket and if packet_create\nfails, it will just sk_free the allocated sk object.\n\nWhile we could chase all the pf-\u003ecreate implementations and make sure they\nNULL the freed sk object on error from the socket, we can\u0027t guarantee\nfuture protocols will not make the same mistake.\n\nSo it is easier to just explicitly NULL the sk pointer upon return from\npf-\u003ecreate in __sock_create. We do know that pf-\u003ecreate always releases the\nallocated sk object on error, so if the pointer is not NULL, it is\ndefinitely dangling.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50186", "url": "https://www.suse.com/security/cve/CVE-2024-50186" }, { "category": "external", "summary": "SUSE Bug 1233110 for CVE-2024-50186", "url": "https://bugzilla.suse.com/1233110" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50186" }, { "cve": "CVE-2024-50187", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50187" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Stop the active perfmon before being destroyed\n\nUpon closing the file descriptor, the active performance monitor is not\nstopped. Although all perfmons are destroyed in `vc4_perfmon_close_file()`,\nthe active performance monitor\u0027s pointer (`vc4-\u003eactive_perfmon`) is still\nretained.\n\nIf we open a new file descriptor and submit a few jobs with performance\nmonitors, the driver will attempt to stop the active performance monitor\nusing the stale pointer in `vc4-\u003eactive_perfmon`. However, this pointer\nis no longer valid because the previous process has already terminated,\nand all performance monitors associated with it have been destroyed and\nfreed.\n\nTo fix this, when the active performance monitor belongs to a given\nprocess, explicitly stop it before destroying and freeing it.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50187", "url": "https://www.suse.com/security/cve/CVE-2024-50187" }, { "category": "external", "summary": "SUSE Bug 1233108 for CVE-2024-50187", "url": "https://bugzilla.suse.com/1233108" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50187" }, { "cve": "CVE-2024-50188", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50188" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: dp83869: fix memory corruption when enabling fiber\n\nWhen configuring the fiber port, the DP83869 PHY driver incorrectly\ncalls linkmode_set_bit() with a bit mask (1 \u003c\u003c 10) rather than a bit\nnumber (10). This corrupts some other memory location -- in case of\narm64 the priv pointer in the same structure.\n\nSince the advertising flags are updated from supported at the end of the\nfunction the incorrect line isn\u0027t needed at all and can be removed.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50188", "url": "https://www.suse.com/security/cve/CVE-2024-50188" }, { "category": "external", "summary": "SUSE Bug 1233107 for CVE-2024-50188", "url": "https://bugzilla.suse.com/1233107" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50188" }, { "cve": "CVE-2024-50189", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50189" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: amd_sfh: Switch to device-managed dmam_alloc_coherent()\n\nUsing the device-managed version allows to simplify clean-up in probe()\nerror path.\n\nAdditionally, this device-managed ensures proper cleanup, which helps to\nresolve memory errors, page faults, btrfs going read-only, and btrfs\ndisk corruption.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50189", "url": "https://www.suse.com/security/cve/CVE-2024-50189" }, { "category": "external", "summary": "SUSE Bug 1233105 for CVE-2024-50189", "url": "https://bugzilla.suse.com/1233105" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50189" }, { "cve": "CVE-2024-50192", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50192" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/gic-v4: Don\u0027t allow a VMOVP on a dying VPE\n\nKunkun Jiang reported that there is a small window of opportunity for\nuserspace to force a change of affinity for a VPE while the VPE has already\nbeen unmapped, but the corresponding doorbell interrupt still visible in\n/proc/irq/.\n\nPlug the race by checking the value of vmapp_count, which tracks whether\nthe VPE is mapped ot not, and returning an error in this case.\n\nThis involves making vmapp_count common to both GICv4.1 and its v4.0\nancestor.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50192", "url": "https://www.suse.com/security/cve/CVE-2024-50192" }, { "category": "external", "summary": "SUSE Bug 1233106 for CVE-2024-50192", "url": "https://bugzilla.suse.com/1233106" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50192" }, { "cve": "CVE-2024-50194", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50194" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: probes: Fix uprobes for big-endian kernels\n\nThe arm64 uprobes code is broken for big-endian kernels as it doesn\u0027t\nconvert the in-memory instruction encoding (which is always\nlittle-endian) into the kernel\u0027s native endianness before analyzing and\nsimulating instructions. This may result in a few distinct problems:\n\n* The kernel may may erroneously reject probing an instruction which can\n safely be probed.\n\n* The kernel may erroneously erroneously permit stepping an\n instruction out-of-line when that instruction cannot be stepped\n out-of-line safely.\n\n* The kernel may erroneously simulate instruction incorrectly dur to\n interpretting the byte-swapped encoding.\n\nThe endianness mismatch isn\u0027t caught by the compiler or sparse because:\n\n* The arch_uprobe::{insn,ixol} fields are encoded as arrays of u8, so\n the compiler and sparse have no idea these contain a little-endian\n 32-bit value. The core uprobes code populates these with a memcpy()\n which similarly does not handle endianness.\n\n* While the uprobe_opcode_t type is an alias for __le32, both\n arch_uprobe_analyze_insn() and arch_uprobe_skip_sstep() cast from u8[]\n to the similarly-named probe_opcode_t, which is an alias for u32.\n Hence there is no endianness conversion warning.\n\nFix this by changing the arch_uprobe::{insn,ixol} fields to __le32 and\nadding the appropriate __le32_to_cpu() conversions prior to consuming\nthe instruction encoding. The core uprobes copies these fields as opaque\nranges of bytes, and so is unaffected by this change.\n\nAt the same time, remove MAX_UINSN_BYTES and consistently use\nAARCH64_INSN_SIZE for clarity.\n\nTested with the following:\n\n| #include \u003cstdio.h\u003e\n| #include \u003cstdbool.h\u003e\n|\n| #define noinline __attribute__((noinline))\n|\n| static noinline void *adrp_self(void)\n| {\n| void *addr;\n|\n| asm volatile(\n| \" adrp %x0, adrp_self\\n\"\n| \" add %x0, %x0, :lo12:adrp_self\\n\"\n| : \"=r\" (addr));\n| }\n|\n|\n| int main(int argc, char *argv)\n| {\n| void *ptr = adrp_self();\n| bool equal = (ptr == adrp_self);\n|\n| printf(\"adrp_self =\u003e %p\\n\"\n| \"adrp_self() =\u003e %p\\n\"\n| \"%s\\n\",\n| adrp_self, ptr, equal ? \"EQUAL\" : \"NOT EQUAL\");\n|\n| return 0;\n| }\n\n.... where the adrp_self() function was compiled to:\n\n| 00000000004007e0 \u003cadrp_self\u003e:\n| 4007e0: 90000000 adrp x0, 400000 \u003c__ehdr_start\u003e\n| 4007e4: 911f8000 add x0, x0, #0x7e0\n| 4007e8: d65f03c0 ret\n\nBefore this patch, the ADRP is not recognized, and is assumed to be\nsteppable, resulting in corruption of the result:\n\n| # ./adrp-self\n| adrp_self =\u003e 0x4007e0\n| adrp_self() =\u003e 0x4007e0\n| EQUAL\n| # echo \u0027p /root/adrp-self:0x007e0\u0027 \u003e /sys/kernel/tracing/uprobe_events\n| # echo 1 \u003e /sys/kernel/tracing/events/uprobes/enable\n| # ./adrp-self\n| adrp_self =\u003e 0x4007e0\n| adrp_self() =\u003e 0xffffffffff7e0\n| NOT EQUAL\n\nAfter this patch, the ADRP is correctly recognized and simulated:\n\n| # ./adrp-self\n| adrp_self =\u003e 0x4007e0\n| adrp_self() =\u003e 0x4007e0\n| EQUAL\n| #\n| # echo \u0027p /root/adrp-self:0x007e0\u0027 \u003e /sys/kernel/tracing/uprobe_events\n| # echo 1 \u003e /sys/kernel/tracing/events/uprobes/enable\n| # ./adrp-self\n| adrp_self =\u003e 0x4007e0\n| adrp_self() =\u003e 0x4007e0\n| EQUAL", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50194", "url": "https://www.suse.com/security/cve/CVE-2024-50194" }, { "category": "external", "summary": "SUSE Bug 1233111 for CVE-2024-50194", "url": "https://bugzilla.suse.com/1233111" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50194" }, { "cve": "CVE-2024-50195", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50195" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-clock: Fix missing timespec64 check in pc_clock_settime()\n\nAs Andrew pointed out, it will make sense that the PTP core\nchecked timespec64 struct\u0027s tv_sec and tv_nsec range before calling\nptp-\u003einfo-\u003esettime64().\n\nAs the man manual of clock_settime() said, if tp.tv_sec is negative or\ntp.tv_nsec is outside the range [0..999,999,999], it should return EINVAL,\nwhich include dynamic clocks which handles PTP clock, and the condition is\nconsistent with timespec64_valid(). As Thomas suggested, timespec64_valid()\nonly check the timespec is valid, but not ensure that the time is\nin a valid range, so check it ahead using timespec64_valid_strict()\nin pc_clock_settime() and return -EINVAL if not valid.\n\nThere are some drivers that use tp-\u003etv_sec and tp-\u003etv_nsec directly to\nwrite registers without validity checks and assume that the higher layer\nhas checked it, which is dangerous and will benefit from this, such as\nhclge_ptp_settime(), igb_ptp_settime_i210(), _rcar_gen4_ptp_settime(),\nand some drivers can remove the checks of itself.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50195", "url": "https://www.suse.com/security/cve/CVE-2024-50195" }, { "category": "external", "summary": "SUSE Bug 1233103 for CVE-2024-50195", "url": "https://bugzilla.suse.com/1233103" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50195" }, { "cve": "CVE-2024-50196", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50196" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: ocelot: fix system hang on level based interrupts\n\nThe current implementation only calls chained_irq_enter() and\nchained_irq_exit() if it detects pending interrupts.\n\n```\nfor (i = 0; i \u003c info-\u003estride; i++) {\n\turegmap_read(info-\u003emap, id_reg + 4 * i, \u0026reg);\n\tif (!reg)\n\t\tcontinue;\n\n\tchained_irq_enter(parent_chip, desc);\n```\n\nHowever, in case of GPIO pin configured in level mode and the parent\ncontroller configured in edge mode, GPIO interrupt might be lowered by the\nhardware. In the result, if the interrupt is short enough, the parent\ninterrupt is still pending while the GPIO interrupt is cleared;\nchained_irq_enter() never gets called and the system hangs trying to\nservice the parent interrupt.\n\nMoving chained_irq_enter() and chained_irq_exit() outside the for loop\nensures that they are called even when GPIO interrupt is lowered by the\nhardware.\n\nThe similar code with chained_irq_enter() / chained_irq_exit() functions\nwrapping interrupt checking loop may be found in many other drivers:\n```\ngrep -r -A 10 chained_irq_enter drivers/pinctrl\n```", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50196", "url": "https://www.suse.com/security/cve/CVE-2024-50196" }, { "category": "external", "summary": "SUSE Bug 1233113 for CVE-2024-50196", "url": "https://bugzilla.suse.com/1233113" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50196" }, { "cve": "CVE-2024-50198", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50198" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: veml6030: fix IIO device retrieval from embedded device\n\nThe dev pointer that is received as an argument in the\nin_illuminance_period_available_show function references the device\nembedded in the IIO device, not in the i2c client.\n\ndev_to_iio_dev() must be used to accessthe right data. The current\nimplementation leads to a segmentation fault on every attempt to read\nthe attribute because indio_dev gets a NULL assignment.\n\nThis bug has been present since the first appearance of the driver,\napparently since the last version (V6) before getting applied. A\nconstant attribute was used until then, and the last modifications might\nhave not been tested again.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50198", "url": "https://www.suse.com/security/cve/CVE-2024-50198" }, { "category": "external", "summary": "SUSE Bug 1233100 for CVE-2024-50198", "url": "https://bugzilla.suse.com/1233100" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50198" }, { "cve": "CVE-2024-50200", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50200" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmaple_tree: correct tree corruption on spanning store\n\nPatch series \"maple_tree: correct tree corruption on spanning store\", v3.\n\nThere has been a nasty yet subtle maple tree corruption bug that appears\nto have been in existence since the inception of the algorithm.\n\nThis bug seems far more likely to happen since commit f8d112a4e657\n(\"mm/mmap: avoid zeroing vma tree in mmap_region()\"), which is the point\nat which reports started to be submitted concerning this bug.\n\nWe were made definitely aware of the bug thanks to the kind efforts of\nBert Karwatzki who helped enormously in my being able to track this down\nand identify the cause of it.\n\nThe bug arises when an attempt is made to perform a spanning store across\ntwo leaf nodes, where the right leaf node is the rightmost child of the\nshared parent, AND the store completely consumes the right-mode node.\n\nThis results in mas_wr_spanning_store() mitakenly duplicating the new and\nexisting entries at the maximum pivot within the range, and thus maple\ntree corruption.\n\nThe fix patch corrects this by detecting this scenario and disallowing the\nmistaken duplicate copy.\n\nThe fix patch commit message goes into great detail as to how this occurs.\n\nThis series also includes a test which reliably reproduces the issue, and\nasserts that the fix works correctly.\n\nBert has kindly tested the fix and confirmed it resolved his issues. Also\nMikhail Gavrilov kindly reported what appears to be precisely the same\nbug, which this fix should also resolve.\n\n\nThis patch (of 2):\n\nThere has been a subtle bug present in the maple tree implementation from\nits inception.\n\nThis arises from how stores are performed - when a store occurs, it will\noverwrite overlapping ranges and adjust the tree as necessary to\naccommodate this.\n\nA range may always ultimately span two leaf nodes. In this instance we\nwalk the two leaf nodes, determine which elements are not overwritten to\nthe left and to the right of the start and end of the ranges respectively\nand then rebalance the tree to contain these entries and the newly\ninserted one.\n\nThis kind of store is dubbed a \u0027spanning store\u0027 and is implemented by\nmas_wr_spanning_store().\n\nIn order to reach this stage, mas_store_gfp() invokes\nmas_wr_preallocate(), mas_wr_store_type() and mas_wr_walk() in turn to\nwalk the tree and update the object (mas) to traverse to the location\nwhere the write should be performed, determining its store type.\n\nWhen a spanning store is required, this function returns false stopping at\nthe parent node which contains the target range, and mas_wr_store_type()\nmarks the mas-\u003estore_type as wr_spanning_store to denote this fact.\n\nWhen we go to perform the store in mas_wr_spanning_store(), we first\ndetermine the elements AFTER the END of the range we wish to store (that\nis, to the right of the entry to be inserted) - we do this by walking to\nthe NEXT pivot in the tree (i.e. r_mas.last + 1), starting at the node we\nhave just determined contains the range over which we intend to write.\n\nWe then turn our attention to the entries to the left of the entry we are\ninserting, whose state is represented by l_mas, and copy these into a \u0027big\nnode\u0027, which is a special node which contains enough slots to contain two\nleaf node\u0027s worth of data.\n\nWe then copy the entry we wish to store immediately after this - the copy\nand the insertion of the new entry is performed by mas_store_b_node().\n\nAfter this we copy the elements to the right of the end of the range which\nwe are inserting, if we have not exceeded the length of the node (i.e. \nr_mas.offset \u003c= r_mas.end).\n\nHerein lies the bug - under very specific circumstances, this logic can\nbreak and corrupt the maple tree.\n\nConsider the following tree:\n\nHeight\n 0 Root Node\n / \\\n pivot = 0xffff / \\ pivot = ULONG_MAX\n / \n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50200", "url": "https://www.suse.com/security/cve/CVE-2024-50200" }, { "category": "external", "summary": "SUSE Bug 1233088 for CVE-2024-50200", "url": "https://bugzilla.suse.com/1233088" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50200" }, { "cve": "CVE-2024-50201", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50201" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: Fix encoder-\u003epossible_clones\n\nInclude the encoder itself in its possible_clones bitmask.\nIn the past nothing validated that drivers were populating\npossible_clones correctly, but that changed in commit\n74d2aacbe840 (\"drm: Validate encoder-\u003epossible_clones\").\nLooks like radeon never got the memo and is still not\nfollowing the rules 100% correctly.\n\nThis results in some warnings during driver initialization:\nBogus possible_clones: [ENCODER:46:TV-46] possible_clones=0x4 (full encoder mask=0x7)\nWARNING: CPU: 0 PID: 170 at drivers/gpu/drm/drm_mode_config.c:615 drm_mode_config_validate+0x113/0x39c\n...\n\n(cherry picked from commit 3b6e7d40649c0d75572039aff9d0911864c689db)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50201", "url": "https://www.suse.com/security/cve/CVE-2024-50201" }, { "category": "external", "summary": "SUSE Bug 1233104 for CVE-2024-50201", "url": "https://bugzilla.suse.com/1233104" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50201" }, { "cve": "CVE-2024-50205", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50205" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size()\n\nThe step variable is initialized to zero. It is changed in the loop,\nbut if it\u0027s not changed it will remain zero. Add a variable check\nbefore the division.\n\nThe observed behavior was introduced by commit 826b5de90c0b\n(\"ALSA: firewire-lib: fix insufficient PCM rule for period/buffer size\"),\nand it is difficult to show that any of the interval parameters will\nsatisfy the snd_interval_test() condition with data from the\namdtp_rate_table[] table.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50205", "url": "https://www.suse.com/security/cve/CVE-2024-50205" }, { "category": "external", "summary": "SUSE Bug 1233293 for CVE-2024-50205", "url": "https://bugzilla.suse.com/1233293" }, { "category": "external", "summary": "SUSE Bug 1233294 for CVE-2024-50205", "url": "https://bugzilla.suse.com/1233294" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50205" }, { "cve": "CVE-2024-50208", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50208" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages\n\nAvoid memory corruption while setting up Level-2 PBL pages for the non MR\nresources when num_pages \u003e 256K.\n\nThere will be a single PDE page address (contiguous pages in the case of \u003e\nPAGE_SIZE), but, current logic assumes multiple pages, leading to invalid\nmemory access after 256K PBL entries in the PDE.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50208", "url": "https://www.suse.com/security/cve/CVE-2024-50208" }, { "category": "external", "summary": "SUSE Bug 1233117 for CVE-2024-50208", "url": "https://bugzilla.suse.com/1233117" }, { "category": "external", "summary": "SUSE Bug 1233118 for CVE-2024-50208", "url": "https://bugzilla.suse.com/1233118" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50208" }, { "cve": "CVE-2024-50209", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50209" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Add a check for memory allocation\n\n__alloc_pbl() can return error when memory allocation fails.\nDriver is not checking the status on one of the instances.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50209", "url": "https://www.suse.com/security/cve/CVE-2024-50209" }, { "category": "external", "summary": "SUSE Bug 1233114 for CVE-2024-50209", "url": "https://bugzilla.suse.com/1233114" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50209" }, { "cve": "CVE-2024-50210", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50210" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()\n\nIf get_clock_desc() succeeds, it calls fget() for the clockid\u0027s fd,\nand get the clk-\u003erwsem read lock, so the error path should release\nthe lock to make the lock balance and fput the clockid\u0027s fd to make\nthe refcount balance and release the fd related resource.\n\nHowever the below commit left the error path locked behind resulting in\nunbalanced locking. Check timespec64_valid_strict() before\nget_clock_desc() to fix it, because the \"ts\" is not changed\nafter that.\n\n[pabeni@redhat.com: fixed commit message typo]", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50210", "url": "https://www.suse.com/security/cve/CVE-2024-50210" }, { "category": "external", "summary": "SUSE Bug 1233097 for CVE-2024-50210", "url": "https://bugzilla.suse.com/1233097" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50210" }, { "cve": "CVE-2024-50215", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50215" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: assign dh_key to NULL after kfree_sensitive\n\nctrl-\u003edh_key might be used across multiple calls to nvmet_setup_dhgroup()\nfor the same controller. So it\u0027s better to nullify it after release on\nerror path in order to avoid double free later in nvmet_destroy_auth().\n\nFound by Linux Verification Center (linuxtesting.org) with Svace.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50215", "url": "https://www.suse.com/security/cve/CVE-2024-50215" }, { "category": "external", "summary": "SUSE Bug 1233189 for CVE-2024-50215", "url": "https://bugzilla.suse.com/1233189" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50215" }, { "cve": "CVE-2024-50216", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50216" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix finding a last resort AG in xfs_filestream_pick_ag\n\nWhen the main loop in xfs_filestream_pick_ag fails to find a suitable\nAG it tries to just pick the online AG. But the loop for that uses\nargs-\u003epag as loop iterator while the later code expects pag to be\nset. Fix this by reusing the max_pag case for this last resort, and\nalso add a check for impossible case of no AG just to make sure that\nthe uninitialized pag doesn\u0027t even escape in theory.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50216", "url": "https://www.suse.com/security/cve/CVE-2024-50216" }, { "category": "external", "summary": "SUSE Bug 1233179 for CVE-2024-50216", "url": "https://bugzilla.suse.com/1233179" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50216" }, { "cve": "CVE-2024-50218", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50218" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: pass u64 to ocfs2_truncate_inline maybe overflow\n\nSyzbot reported a kernel BUG in ocfs2_truncate_inline. There are two\nreasons for this: first, the parameter value passed is greater than\nocfs2_max_inline_data_with_xattr, second, the start and end parameters of\nocfs2_truncate_inline are \"unsigned int\".\n\nSo, we need to add a sanity check for byte_start and byte_len right before\nocfs2_truncate_inline() in ocfs2_remove_inode_range(), if they are greater\nthan ocfs2_max_inline_data_with_xattr return -EINVAL.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50218", "url": "https://www.suse.com/security/cve/CVE-2024-50218" }, { "category": "external", "summary": "SUSE Bug 1233191 for CVE-2024-50218", "url": "https://bugzilla.suse.com/1233191" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50218" }, { "cve": "CVE-2024-50221", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50221" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Vangogh: Fix kernel memory out of bounds write\n\nKASAN reports that the GPU metrics table allocated in\nvangogh_tables_init() is not large enough for the memset done in\nsmu_cmn_init_soft_gpu_metrics(). Condensed report follows:\n\n[ 33.861314] BUG: KASAN: slab-out-of-bounds in smu_cmn_init_soft_gpu_metrics+0x73/0x200 [amdgpu]\n[ 33.861799] Write of size 168 at addr ffff888129f59500 by task mangoapp/1067\n...\n[ 33.861808] CPU: 6 UID: 1000 PID: 1067 Comm: mangoapp Tainted: G W 6.12.0-rc4 #356 1a56f59a8b5182eeaf67eb7cb8b13594dd23b544\n[ 33.861816] Tainted: [W]=WARN\n[ 33.861818] Hardware name: Valve Galileo/Galileo, BIOS F7G0107 12/01/2023\n[ 33.861822] Call Trace:\n[ 33.861826] \u003cTASK\u003e\n[ 33.861829] dump_stack_lvl+0x66/0x90\n[ 33.861838] print_report+0xce/0x620\n[ 33.861853] kasan_report+0xda/0x110\n[ 33.862794] kasan_check_range+0xfd/0x1a0\n[ 33.862799] __asan_memset+0x23/0x40\n[ 33.862803] smu_cmn_init_soft_gpu_metrics+0x73/0x200 [amdgpu 13b1bc364ec578808f676eba412c20eaab792779]\n[ 33.863306] vangogh_get_gpu_metrics_v2_4+0x123/0xad0 [amdgpu 13b1bc364ec578808f676eba412c20eaab792779]\n[ 33.864257] vangogh_common_get_gpu_metrics+0xb0c/0xbc0 [amdgpu 13b1bc364ec578808f676eba412c20eaab792779]\n[ 33.865682] amdgpu_dpm_get_gpu_metrics+0xcc/0x110 [amdgpu 13b1bc364ec578808f676eba412c20eaab792779]\n[ 33.866160] amdgpu_get_gpu_metrics+0x154/0x2d0 [amdgpu 13b1bc364ec578808f676eba412c20eaab792779]\n[ 33.867135] dev_attr_show+0x43/0xc0\n[ 33.867147] sysfs_kf_seq_show+0x1f1/0x3b0\n[ 33.867155] seq_read_iter+0x3f8/0x1140\n[ 33.867173] vfs_read+0x76c/0xc50\n[ 33.867198] ksys_read+0xfb/0x1d0\n[ 33.867214] do_syscall_64+0x90/0x160\n...\n[ 33.867353] Allocated by task 378 on cpu 7 at 22.794876s:\n[ 33.867358] kasan_save_stack+0x33/0x50\n[ 33.867364] kasan_save_track+0x17/0x60\n[ 33.867367] __kasan_kmalloc+0x87/0x90\n[ 33.867371] vangogh_init_smc_tables+0x3f9/0x840 [amdgpu]\n[ 33.867835] smu_sw_init+0xa32/0x1850 [amdgpu]\n[ 33.868299] amdgpu_device_init+0x467b/0x8d90 [amdgpu]\n[ 33.868733] amdgpu_driver_load_kms+0x19/0xf0 [amdgpu]\n[ 33.869167] amdgpu_pci_probe+0x2d6/0xcd0 [amdgpu]\n[ 33.869608] local_pci_probe+0xda/0x180\n[ 33.869614] pci_device_probe+0x43f/0x6b0\n\nEmpirically we can confirm that the former allocates 152 bytes for the\ntable, while the latter memsets the 168 large block.\n\nRoot cause appears that when GPU metrics tables for v2_4 parts were added\nit was not considered to enlarge the table to fit.\n\nThe fix in this patch is rather \"brute force\" and perhaps later should be\ndone in a smarter way, by extracting and consolidating the part version to\nsize logic to a common helper, instead of brute forcing the largest\npossible allocation. Nevertheless, for now this works and fixes the out of\nbounds write.\n\nv2:\n * Drop impossible v3_0 case. (Mario)\n\n(cherry picked from commit 0880f58f9609f0200483a49429af0f050d281703)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50221", "url": "https://www.suse.com/security/cve/CVE-2024-50221" }, { "category": "external", "summary": "SUSE Bug 1233185 for CVE-2024-50221", "url": "https://bugzilla.suse.com/1233185" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50221" }, { "cve": "CVE-2024-50224", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50224" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-fsl-dspi: Fix crash when not using GPIO chip select\n\nAdd check for the return value of spi_get_csgpiod() to avoid passing a NULL\npointer to gpiod_direction_output(), preventing a crash when GPIO chip\nselect is not used.\n\nFix below crash:\n[ 4.251960] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[ 4.260762] Mem abort info:\n[ 4.263556] ESR = 0x0000000096000004\n[ 4.267308] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 4.272624] SET = 0, FnV = 0\n[ 4.275681] EA = 0, S1PTW = 0\n[ 4.278822] FSC = 0x04: level 0 translation fault\n[ 4.283704] Data abort info:\n[ 4.286583] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[ 4.292074] CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[ 4.297130] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[ 4.302445] [0000000000000000] user address but active_mm is swapper\n[ 4.308805] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 4.315072] Modules linked in:\n[ 4.318124] CPU: 2 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-rc4-next-20241023-00008-ga20ec42c5fc1 #359\n[ 4.328130] Hardware name: LS1046A QDS Board (DT)\n[ 4.332832] pstate: 40000005 (nZcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 4.339794] pc : gpiod_direction_output+0x34/0x5c\n[ 4.344505] lr : gpiod_direction_output+0x18/0x5c\n[ 4.349208] sp : ffff80008003b8f0\n[ 4.352517] x29: ffff80008003b8f0 x28: 0000000000000000 x27: ffffc96bcc7e9068\n[ 4.359659] x26: ffffc96bcc6e00b0 x25: ffffc96bcc598398 x24: ffff447400132810\n[ 4.366800] x23: 0000000000000000 x22: 0000000011e1a300 x21: 0000000000020002\n[ 4.373940] x20: 0000000000000000 x19: 0000000000000000 x18: ffffffffffffffff\n[ 4.381081] x17: ffff44740016e600 x16: 0000000500000003 x15: 0000000000000007\n[ 4.388221] x14: 0000000000989680 x13: 0000000000020000 x12: 000000000000001e\n[ 4.395362] x11: 0044b82fa09b5a53 x10: 0000000000000019 x9 : 0000000000000008\n[ 4.402502] x8 : 0000000000000002 x7 : 0000000000000007 x6 : 0000000000000000\n[ 4.409641] x5 : 0000000000000200 x4 : 0000000002000000 x3 : 0000000000000000\n[ 4.416781] x2 : 0000000000022202 x1 : 0000000000000000 x0 : 0000000000000000\n[ 4.423921] Call trace:\n[ 4.426362] gpiod_direction_output+0x34/0x5c (P)\n[ 4.431067] gpiod_direction_output+0x18/0x5c (L)\n[ 4.435771] dspi_setup+0x220/0x334", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50224", "url": "https://www.suse.com/security/cve/CVE-2024-50224" }, { "category": "external", "summary": "SUSE Bug 1233188 for CVE-2024-50224", "url": "https://bugzilla.suse.com/1233188" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50224" }, { "cve": "CVE-2024-50225", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50225" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix error propagation of split bios\n\nThe purpose of btrfs_bbio_propagate_error() shall be propagating an error\nof split bio to its original btrfs_bio, and tell the error to the upper\nlayer. However, it\u0027s not working well on some cases.\n\n* Case 1. Immediate (or quick) end_bio with an error\n\nWhen btrfs sends btrfs_bio to mirrored devices, btrfs calls\nbtrfs_bio_end_io() when all the mirroring bios are completed. If that\nbtrfs_bio was split, it is from btrfs_clone_bioset and its end_io function\nis btrfs_orig_write_end_io. For this case, btrfs_bbio_propagate_error()\naccesses the orig_bbio\u0027s bio context to increase the error count.\n\nThat works well in most cases. However, if the end_io is called enough\nfast, orig_bbio\u0027s (remaining part after split) bio context may not be\nproperly set at that time. Since the bio context is set when the orig_bbio\n(the last btrfs_bio) is sent to devices, that might be too late for earlier\nsplit btrfs_bio\u0027s completion. That will result in NULL pointer\ndereference.\n\nThat bug is easily reproducible by running btrfs/146 on zoned devices [1]\nand it shows the following trace.\n\n[1] You need raid-stripe-tree feature as it create \"-d raid0 -m raid1\" FS.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000020\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 1 UID: 0 PID: 13 Comm: kworker/u32:1 Not tainted 6.11.0-rc7-BTRFS-ZNS+ #474\n Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011\n Workqueue: writeback wb_workfn (flush-btrfs-5)\n RIP: 0010:btrfs_bio_end_io+0xae/0xc0 [btrfs]\n BTRFS error (device dm-0): bdev /dev/mapper/error-test errs: wr 2, rd 0, flush 0, corrupt 0, gen 0\n RSP: 0018:ffffc9000006f248 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: ffff888005a7f080 RCX: ffffc9000006f1dc\n RDX: 0000000000000000 RSI: 000000000000000a RDI: ffff888005a7f080\n RBP: ffff888011dfc540 R08: 0000000000000000 R09: 0000000000000001\n R10: ffffffff82e508e0 R11: 0000000000000005 R12: ffff88800ddfbe58\n R13: ffff888005a7f080 R14: ffff888005a7f158 R15: ffff888005a7f158\n FS: 0000000000000000(0000) GS:ffff88803ea80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000020 CR3: 0000000002e22006 CR4: 0000000000370ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \u003cTASK\u003e\n ? __die_body.cold+0x19/0x26\n ? page_fault_oops+0x13e/0x2b0\n ? _printk+0x58/0x73\n ? do_user_addr_fault+0x5f/0x750\n ? exc_page_fault+0x76/0x240\n ? asm_exc_page_fault+0x22/0x30\n ? btrfs_bio_end_io+0xae/0xc0 [btrfs]\n ? btrfs_log_dev_io_error+0x7f/0x90 [btrfs]\n btrfs_orig_write_end_io+0x51/0x90 [btrfs]\n dm_submit_bio+0x5c2/0xa50 [dm_mod]\n ? find_held_lock+0x2b/0x80\n ? blk_try_enter_queue+0x90/0x1e0\n __submit_bio+0xe0/0x130\n ? ktime_get+0x10a/0x160\n ? lockdep_hardirqs_on+0x74/0x100\n submit_bio_noacct_nocheck+0x199/0x410\n btrfs_submit_bio+0x7d/0x150 [btrfs]\n btrfs_submit_chunk+0x1a1/0x6d0 [btrfs]\n ? lockdep_hardirqs_on+0x74/0x100\n ? __folio_start_writeback+0x10/0x2c0\n btrfs_submit_bbio+0x1c/0x40 [btrfs]\n submit_one_bio+0x44/0x60 [btrfs]\n submit_extent_folio+0x13f/0x330 [btrfs]\n ? btrfs_set_range_writeback+0xa3/0xd0 [btrfs]\n extent_writepage_io+0x18b/0x360 [btrfs]\n extent_write_locked_range+0x17c/0x340 [btrfs]\n ? __pfx_end_bbio_data_write+0x10/0x10 [btrfs]\n run_delalloc_cow+0x71/0xd0 [btrfs]\n btrfs_run_delalloc_range+0x176/0x500 [btrfs]\n ? find_lock_delalloc_range+0x119/0x260 [btrfs]\n writepage_delalloc+0x2ab/0x480 [btrfs]\n extent_write_cache_pages+0x236/0x7d0 [btrfs]\n btrfs_writepages+0x72/0x130 [btrfs]\n do_writepages+0xd4/0x240\n ? find_held_lock+0x2b/0x80\n ? wbc_attach_and_unlock_inode+0x12c/0x290\n ? wbc_attach_and_unlock_inode+0x12c/0x29\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50225", "url": "https://www.suse.com/security/cve/CVE-2024-50225" }, { "category": "external", "summary": "SUSE Bug 1233193 for CVE-2024-50225", "url": "https://bugzilla.suse.com/1233193" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50225" }, { "cve": "CVE-2024-50228", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50228" } ], "notes": [ { "category": "general", "text": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50228", "url": "https://www.suse.com/security/cve/CVE-2024-50228" }, { "category": "external", "summary": "SUSE Bug 1233204 for CVE-2024-50228", "url": "https://bugzilla.suse.com/1233204" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50228" }, { "cve": "CVE-2024-50229", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50229" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix potential deadlock with newly created symlinks\n\nSyzbot reported that page_symlink(), called by nilfs_symlink(), triggers\nmemory reclamation involving the filesystem layer, which can result in\ncircular lock dependencies among the reader/writer semaphore\nnilfs-\u003ens_segctor_sem, s_writers percpu_rwsem (intwrite) and the\nfs_reclaim pseudo lock.\n\nThis is because after commit 21fc61c73c39 (\"don\u0027t put symlink bodies in\npagecache into highmem\"), the gfp flags of the page cache for symbolic\nlinks are overwritten to GFP_KERNEL via inode_nohighmem().\n\nThis is not a problem for symlinks read from the backing device, because\nthe __GFP_FS flag is dropped after inode_nohighmem() is called. However,\nwhen a new symlink is created with nilfs_symlink(), the gfp flags remain\noverwritten to GFP_KERNEL. Then, memory allocation called from\npage_symlink() etc. triggers memory reclamation including the FS layer,\nwhich may call nilfs_evict_inode() or nilfs_dirty_inode(). And these can\ncause a deadlock if they are called while nilfs-\u003ens_segctor_sem is held:\n\nFix this issue by dropping the __GFP_FS flag from the page cache GFP flags\nof newly created symlinks in the same way that nilfs_new_inode() and\n__nilfs_read_inode() do, as a workaround until we adopt nofs allocation\nscope consistently or improve the locking constraints.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50229", "url": "https://www.suse.com/security/cve/CVE-2024-50229" }, { "category": "external", "summary": "SUSE Bug 1233205 for CVE-2024-50229", "url": "https://bugzilla.suse.com/1233205" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50229" }, { "cve": "CVE-2024-50230", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50230" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix kernel bug due to missing clearing of checked flag\n\nSyzbot reported that in directory operations after nilfs2 detects\nfilesystem corruption and degrades to read-only,\n__block_write_begin_int(), which is called to prepare block writes, may\nfail the BUG_ON check for accesses exceeding the folio/page size,\ntriggering a kernel bug.\n\nThis was found to be because the \"checked\" flag of a page/folio was not\ncleared when it was discarded by nilfs2\u0027s own routine, which causes the\nsanity check of directory entries to be skipped when the directory\npage/folio is reloaded. So, fix that.\n\nThis was necessary when the use of nilfs2\u0027s own page discard routine was\napplied to more than just metadata files.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50230", "url": "https://www.suse.com/security/cve/CVE-2024-50230" }, { "category": "external", "summary": "SUSE Bug 1233206 for CVE-2024-50230", "url": "https://bugzilla.suse.com/1233206" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50230" }, { "cve": "CVE-2024-50231", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50231" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: gts-helper: Fix memory leaks in iio_gts_build_avail_scale_table()\n\nmodprobe iio-test-gts and rmmod it, then the following memory leak\noccurs:\n\n\tunreferenced object 0xffffff80c810be00 (size 64):\n\t comm \"kunit_try_catch\", pid 1654, jiffies 4294913981\n\t hex dump (first 32 bytes):\n\t 02 00 00 00 08 00 00 00 20 00 00 00 40 00 00 00 ........ ...@...\n\t 80 00 00 00 00 02 00 00 00 04 00 00 00 08 00 00 ................\n\t backtrace (crc a63d875e):\n\t [\u003c0000000028c1b3c2\u003e] kmemleak_alloc+0x34/0x40\n\t [\u003c000000001d6ecc87\u003e] __kmalloc_noprof+0x2bc/0x3c0\n\t [\u003c00000000393795c1\u003e] devm_iio_init_iio_gts+0x4b4/0x16f4\n\t [\u003c0000000071bb4b09\u003e] 0xffffffdf052a62e0\n\t [\u003c000000000315bc18\u003e] 0xffffffdf052a6488\n\t [\u003c00000000f9dc55b5\u003e] kunit_try_run_case+0x13c/0x3ac\n\t [\u003c00000000175a3fd4\u003e] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [\u003c00000000f505065d\u003e] kthread+0x2e8/0x374\n\t [\u003c00000000bbfb0e5d\u003e] ret_from_fork+0x10/0x20\n\tunreferenced object 0xffffff80cbfe9e70 (size 16):\n\t comm \"kunit_try_catch\", pid 1658, jiffies 4294914015\n\t hex dump (first 16 bytes):\n\t 10 00 00 00 40 00 00 00 80 00 00 00 00 00 00 00 ....@...........\n\t backtrace (crc 857f0cb4):\n\t [\u003c0000000028c1b3c2\u003e] kmemleak_alloc+0x34/0x40\n\t [\u003c000000001d6ecc87\u003e] __kmalloc_noprof+0x2bc/0x3c0\n\t [\u003c00000000393795c1\u003e] devm_iio_init_iio_gts+0x4b4/0x16f4\n\t [\u003c0000000071bb4b09\u003e] 0xffffffdf052a62e0\n\t [\u003c000000007d089d45\u003e] 0xffffffdf052a6864\n\t [\u003c00000000f9dc55b5\u003e] kunit_try_run_case+0x13c/0x3ac\n\t [\u003c00000000175a3fd4\u003e] kunit_generic_run_threadfn_adapter+0x80/0xec\n\t [\u003c00000000f505065d\u003e] kthread+0x2e8/0x374\n\t [\u003c00000000bbfb0e5d\u003e] ret_from_fork+0x10/0x20\n\t......\n\nIt includes 5*5 times \"size 64\" memory leaks, which correspond to 5 times\ntest_init_iio_gain_scale() calls with gts_test_gains size 10 (10*size(int))\nand gts_test_itimes size 5. It also includes 5*1 times \"size 16\"\nmemory leak, which correspond to one time __test_init_iio_gain_scale()\ncall with gts_test_gains_gain_low size 3 (3*size(int)) and gts_test_itimes\nsize 5.\n\nThe reason is that the per_time_gains[i] is not freed which is allocated in\nthe \"gts-\u003enum_itime\" for loop in iio_gts_build_avail_scale_table().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50231", "url": "https://www.suse.com/security/cve/CVE-2024-50231" }, { "category": "external", "summary": "SUSE Bug 1233208 for CVE-2024-50231", "url": "https://bugzilla.suse.com/1233208" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50231" }, { "cve": "CVE-2024-50232", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50232" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad7124: fix division by zero in ad7124_set_channel_odr()\n\nIn the ad7124_write_raw() function, parameter val can potentially\nbe zero. This may lead to a division by zero when DIV_ROUND_CLOSEST()\nis called within ad7124_set_channel_odr(). The ad7124_write_raw()\nfunction is invoked through the sequence: iio_write_channel_raw() -\u003e\niio_write_channel_attribute() -\u003e iio_channel_write(), with no checks\nin place to ensure val is non-zero.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50232", "url": "https://www.suse.com/security/cve/CVE-2024-50232" }, { "category": "external", "summary": "SUSE Bug 1233209 for CVE-2024-50232", "url": "https://bugzilla.suse.com/1233209" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50232" }, { "cve": "CVE-2024-50233", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50233" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: iio: frequency: ad9832: fix division by zero in ad9832_calc_freqreg()\n\nIn the ad9832_write_frequency() function, clk_get_rate() might return 0.\nThis can lead to a division by zero when calling ad9832_calc_freqreg().\nThe check if (fout \u003e (clk_get_rate(st-\u003emclk) / 2)) does not protect\nagainst the case when fout is 0. The ad9832_write_frequency() function\nis called from ad9832_write(), and fout is derived from a text buffer,\nwhich can contain any value.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50233", "url": "https://www.suse.com/security/cve/CVE-2024-50233" }, { "category": "external", "summary": "SUSE Bug 1233210 for CVE-2024-50233", "url": "https://bugzilla.suse.com/1233210" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50233" }, { "cve": "CVE-2024-50234", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50234" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlegacy: Clear stale interrupts before resuming device\n\niwl4965 fails upon resume from hibernation on my laptop. The reason\nseems to be a stale interrupt which isn\u0027t being cleared out before\ninterrupts are enabled. We end up with a race beween the resume\ntrying to bring things back up, and the restart work (queued form\nthe interrupt handler) trying to bring things down. Eventually\nthe whole thing blows up.\n\nFix the problem by clearing out any stale interrupts before\ninterrupts get enabled during resume.\n\nHere\u0027s a debug log of the indicent:\n[ 12.042589] ieee80211 phy0: il_isr ISR inta 0x00000080, enabled 0xaa00008b, fh 0x00000000\n[ 12.042625] ieee80211 phy0: il4965_irq_tasklet inta 0x00000080, enabled 0x00000000, fh 0x00000000\n[ 12.042651] iwl4965 0000:10:00.0: RF_KILL bit toggled to enable radio.\n[ 12.042653] iwl4965 0000:10:00.0: On demand firmware reload\n[ 12.042690] ieee80211 phy0: il4965_irq_tasklet End inta 0x00000000, enabled 0xaa00008b, fh 0x00000000, flags 0x00000282\n[ 12.052207] ieee80211 phy0: il4965_mac_start enter\n[ 12.052212] ieee80211 phy0: il_prep_station Add STA to driver ID 31: ff:ff:ff:ff:ff:ff\n[ 12.052244] ieee80211 phy0: il4965_set_hw_ready hardware ready\n[ 12.052324] ieee80211 phy0: il_apm_init Init card\u0027s basic functions\n[ 12.052348] ieee80211 phy0: il_apm_init L1 Enabled; Disabling L0S\n[ 12.055727] ieee80211 phy0: il4965_load_bsm Begin load bsm\n[ 12.056140] ieee80211 phy0: il4965_verify_bsm Begin verify bsm\n[ 12.058642] ieee80211 phy0: il4965_verify_bsm BSM bootstrap uCode image OK\n[ 12.058721] ieee80211 phy0: il4965_load_bsm BSM write complete, poll 1 iterations\n[ 12.058734] ieee80211 phy0: __il4965_up iwl4965 is coming up\n[ 12.058737] ieee80211 phy0: il4965_mac_start Start UP work done.\n[ 12.058757] ieee80211 phy0: __il4965_down iwl4965 is going down\n[ 12.058761] ieee80211 phy0: il_scan_cancel_timeout Scan cancel timeout\n[ 12.058762] ieee80211 phy0: il_do_scan_abort Not performing scan to abort\n[ 12.058765] ieee80211 phy0: il_clear_ucode_stations Clearing ucode stations in driver\n[ 12.058767] ieee80211 phy0: il_clear_ucode_stations No active stations found to be cleared\n[ 12.058819] ieee80211 phy0: _il_apm_stop Stop card, put in low power state\n[ 12.058827] ieee80211 phy0: _il_apm_stop_master stop master\n[ 12.058864] ieee80211 phy0: il4965_clear_free_frames 0 frames on pre-allocated heap on clear.\n[ 12.058869] ieee80211 phy0: Hardware restart was requested\n[ 16.132299] iwl4965 0000:10:00.0: START_ALIVE timeout after 4000ms.\n[ 16.132303] ------------[ cut here ]------------\n[ 16.132304] Hardware became unavailable upon resume. This could be a software issue prior to suspend or a hardware issue.\n[ 16.132338] WARNING: CPU: 0 PID: 181 at net/mac80211/util.c:1826 ieee80211_reconfig+0x8f/0x14b0 [mac80211]\n[ 16.132390] Modules linked in: ctr ccm sch_fq_codel xt_tcpudp xt_multiport xt_state iptable_filter iptable_nat nf_nat nf_conntrack nf_defrag_ipv4 ip_tables x_tables binfmt_misc joydev mousedev btusb btrtl btintel btbcm bluetooth ecdh_generic ecc iTCO_wdt i2c_dev iwl4965 iwlegacy coretemp snd_hda_codec_analog pcspkr psmouse mac80211 snd_hda_codec_generic libarc4 sdhci_pci cqhci sha256_generic sdhci libsha256 firewire_ohci snd_hda_intel snd_intel_dspcfg mmc_core snd_hda_codec snd_hwdep firewire_core led_class iosf_mbi snd_hda_core uhci_hcd lpc_ich crc_itu_t cfg80211 ehci_pci ehci_hcd snd_pcm usbcore mfd_core rfkill snd_timer snd usb_common soundcore video parport_pc parport intel_agp wmi intel_gtt backlight e1000e agpgart evdev\n[ 16.132456] CPU: 0 UID: 0 PID: 181 Comm: kworker/u8:6 Not tainted 6.11.0-cl+ #143\n[ 16.132460] Hardware name: Hewlett-Packard HP Compaq 6910p/30BE, BIOS 68MCU Ver. F.19 07/06/2010\n[ 16.132463] Workqueue: async async_run_entry_fn\n[ 16.132469] RIP: 0010:ieee80211_reconfig+0x8f/0x14b0 [mac80211]\n[ 16.132501] Code: da 02 00 0\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50234", "url": "https://www.suse.com/security/cve/CVE-2024-50234" }, { "category": "external", "summary": "SUSE Bug 1233211 for CVE-2024-50234", "url": "https://bugzilla.suse.com/1233211" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50234" }, { "cve": "CVE-2024-50235", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50235" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: clear wdev-\u003ecqm_config pointer on free\n\nWhen we free wdev-\u003ecqm_config when unregistering, we also\nneed to clear out the pointer since the same wdev/netdev\nmay get re-registered in another network namespace, then\ndestroyed later, running this code again, which results in\na double-free.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50235", "url": "https://www.suse.com/security/cve/CVE-2024-50235" }, { "category": "external", "summary": "SUSE Bug 1233176 for CVE-2024-50235", "url": "https://bugzilla.suse.com/1233176" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50235" }, { "cve": "CVE-2024-50236", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50236" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath10k: Fix memory leak in management tx\n\nIn the current logic, memory is allocated for storing the MSDU context\nduring management packet TX but this memory is not being freed during\nmanagement TX completion. Similar leaks are seen in the management TX\ncleanup logic.\n\nKmemleak reports this problem as below,\n\nunreferenced object 0xffffff80b64ed250 (size 16):\n comm \"kworker/u16:7\", pid 148, jiffies 4294687130 (age 714.199s)\n hex dump (first 16 bytes):\n 00 2b d8 d8 80 ff ff ff c4 74 e9 fd 07 00 00 00 .+.......t......\n backtrace:\n [\u003cffffffe6e7b245dc\u003e] __kmem_cache_alloc_node+0x1e4/0x2d8\n [\u003cffffffe6e7adde88\u003e] kmalloc_trace+0x48/0x110\n [\u003cffffffe6bbd765fc\u003e] ath10k_wmi_tlv_op_gen_mgmt_tx_send+0xd4/0x1d8 [ath10k_core]\n [\u003cffffffe6bbd3eed4\u003e] ath10k_mgmt_over_wmi_tx_work+0x134/0x298 [ath10k_core]\n [\u003cffffffe6e78d5974\u003e] process_scheduled_works+0x1ac/0x400\n [\u003cffffffe6e78d60b8\u003e] worker_thread+0x208/0x328\n [\u003cffffffe6e78dc890\u003e] kthread+0x100/0x1c0\n [\u003cffffffe6e78166c0\u003e] ret_from_fork+0x10/0x20\n\nFree the memory during completion and cleanup to fix the leak.\n\nProtect the mgmt_pending_tx idr_remove() operation in\nath10k_wmi_tlv_op_cleanup_mgmt_tx_send() using ar-\u003edata_lock similar to\nother instances.\n\nTested-on: WCN3990 hw1.0 SNOC WLAN.HL.2.0-01387-QCAHLSWMTPLZ-1", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50236", "url": "https://www.suse.com/security/cve/CVE-2024-50236" }, { "category": "external", "summary": "SUSE Bug 1233212 for CVE-2024-50236", "url": "https://bugzilla.suse.com/1233212" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50236" }, { "cve": "CVE-2024-50237", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50237" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: do not pass a stopped vif to the driver in .get_txpower\n\nAvoid potentially crashing in the driver because of uninitialized private data", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50237", "url": "https://www.suse.com/security/cve/CVE-2024-50237" }, { "category": "external", "summary": "SUSE Bug 1233216 for CVE-2024-50237", "url": "https://bugzilla.suse.com/1233216" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50237" }, { "cve": "CVE-2024-50240", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50240" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: qcom: qmp-usb: fix NULL-deref on runtime suspend\n\nCommit 413db06c05e7 (\"phy: qcom-qmp-usb: clean up probe initialisation\")\nremoved most users of the platform device driver data, but mistakenly\nalso removed the initialisation despite the data still being used in the\nruntime PM callbacks.\n\nRestore the driver data initialisation at probe to avoid a NULL-pointer\ndereference on runtime suspend.\n\nApparently no one uses runtime PM, which currently needs to be enabled\nmanually through sysfs, with this driver.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50240", "url": "https://www.suse.com/security/cve/CVE-2024-50240" }, { "category": "external", "summary": "SUSE Bug 1233217 for CVE-2024-50240", "url": "https://bugzilla.suse.com/1233217" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50240" }, { "cve": "CVE-2024-50245", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50245" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Fix possible deadlock in mi_read\n\nMutex lock with another subclass used in ni_lock_dir().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50245", "url": "https://www.suse.com/security/cve/CVE-2024-50245" }, { "category": "external", "summary": "SUSE Bug 1233203 for CVE-2024-50245", "url": "https://bugzilla.suse.com/1233203" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50245" }, { "cve": "CVE-2024-50246", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50246" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Add rough attr alloc_size check", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50246", "url": "https://www.suse.com/security/cve/CVE-2024-50246" }, { "category": "external", "summary": "SUSE Bug 1233207 for CVE-2024-50246", "url": "https://bugzilla.suse.com/1233207" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50246" }, { "cve": "CVE-2024-50248", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50248" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: Add bounds checking to mi_enum_attr()\n\nAdded bounds checking to make sure that every attr don\u0027t stray beyond\nvalid memory region.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50248", "url": "https://www.suse.com/security/cve/CVE-2024-50248" }, { "category": "external", "summary": "SUSE Bug 1233219 for CVE-2024-50248", "url": "https://bugzilla.suse.com/1233219" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50248" }, { "cve": "CVE-2024-50249", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50249" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Make rmw_lock a raw_spin_lock\n\nThe following BUG was triggered:\n\n=============================\n[ BUG: Invalid wait context ]\n6.12.0-rc2-XXX #406 Not tainted\n-----------------------------\nkworker/1:1/62 is trying to lock:\nffffff8801593030 (\u0026cpc_ptr-\u003ermw_lock){+.+.}-{3:3}, at: cpc_write+0xcc/0x370\nother info that might help us debug this:\ncontext-{5:5}\n2 locks held by kworker/1:1/62:\n #0: ffffff897ef5ec98 (\u0026rq-\u003e__lock){-.-.}-{2:2}, at: raw_spin_rq_lock_nested+0x2c/0x50\n #1: ffffff880154e238 (\u0026sg_policy-\u003eupdate_lock){....}-{2:2}, at: sugov_update_shared+0x3c/0x280\nstack backtrace:\nCPU: 1 UID: 0 PID: 62 Comm: kworker/1:1 Not tainted 6.12.0-rc2-g9654bd3e8806 #406\nWorkqueue: 0x0 (events)\nCall trace:\n dump_backtrace+0xa4/0x130\n show_stack+0x20/0x38\n dump_stack_lvl+0x90/0xd0\n dump_stack+0x18/0x28\n __lock_acquire+0x480/0x1ad8\n lock_acquire+0x114/0x310\n _raw_spin_lock+0x50/0x70\n cpc_write+0xcc/0x370\n cppc_set_perf+0xa0/0x3a8\n cppc_cpufreq_fast_switch+0x40/0xc0\n cpufreq_driver_fast_switch+0x4c/0x218\n sugov_update_shared+0x234/0x280\n update_load_avg+0x6ec/0x7b8\n dequeue_entities+0x108/0x830\n dequeue_task_fair+0x58/0x408\n __schedule+0x4f0/0x1070\n schedule+0x54/0x130\n worker_thread+0xc0/0x2e8\n kthread+0x130/0x148\n ret_from_fork+0x10/0x20\n\nsugov_update_shared() locks a raw_spinlock while cpc_write() locks a\nspinlock.\n\nTo have a correct wait-type order, update rmw_lock to a raw spinlock and\nensure that interrupts will be disabled on the CPU holding it.\n\n[ rjw: Changelog edits ]", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50249", "url": "https://www.suse.com/security/cve/CVE-2024-50249" }, { "category": "external", "summary": "SUSE Bug 1233197 for CVE-2024-50249", "url": "https://bugzilla.suse.com/1233197" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50249" }, { "cve": "CVE-2024-50250", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50250" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfsdax: dax_unshare_iter needs to copy entire blocks\n\nThe code that copies data from srcmap to iomap in dax_unshare_iter is\nvery very broken, which bfoster\u0027s recent fsx changes have exposed.\n\nIf the pos and len passed to dax_file_unshare are not aligned to an\nfsblock boundary, the iter pos and length in the _iter function will\nreflect this unalignment.\n\ndax_iomap_direct_access always returns a pointer to the start of the\nkmapped fsdax page, even if its pos argument is in the middle of that\npage. This is catastrophic for data integrity when iter-\u003epos is not\naligned to a page, because daddr/saddr do not point to the same byte in\nthe file as iter-\u003epos. Hence we corrupt user data by copying it to the\nwrong place.\n\nIf iter-\u003epos + iomap_length() in the _iter function not aligned to a\npage, then we fail to copy a full block, and only partially populate the\ndestination block. This is catastrophic for data confidentiality\nbecause we expose stale pmem contents.\n\nFix both of these issues by aligning copy_pos/copy_len to a page\nboundary (remember, this is fsdax so 1 fsblock == 1 base page) so that\nwe always copy full blocks.\n\nWe\u0027re not done yet -- there\u0027s no call to invalidate_inode_pages2_range,\nso programs that have the file range mmap\u0027d will continue accessing the\nold memory mapping after the file metadata updates have completed.\n\nBe careful with the return value -- if the unshare succeeds, we still\nneed to return the number of bytes that the iomap iter thinks we\u0027re\noperating on.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50250", "url": "https://www.suse.com/security/cve/CVE-2024-50250" }, { "category": "external", "summary": "SUSE Bug 1233226 for CVE-2024-50250", "url": "https://bugzilla.suse.com/1233226" }, { "category": "external", "summary": "SUSE Bug 1233227 for CVE-2024-50250", "url": "https://bugzilla.suse.com/1233227" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50250" }, { "cve": "CVE-2024-50252", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50252" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address\n\nThe device stores IPv6 addresses that are used for encapsulation in\nlinear memory that is managed by the driver.\n\nChanging the remote address of an ip6gre net device never worked\nproperly, but since cited commit the following reproducer [1] would\nresult in a warning [2] and a memory leak [3]. The problem is that the\nnew remote address is never added by the driver to its hash table (and\ntherefore the device) and the old address is never removed from it.\n\nFix by programming the new address when the configuration of the ip6gre\nnet device changes and removing the old one. If the address did not\nchange, then the above would result in increasing the reference count of\nthe address and then decreasing it.\n\n[1]\n # ip link add name bla up type ip6gre local 2001:db8:1::1 remote 2001:db8:2::1 tos inherit ttl inherit\n # ip link set dev bla type ip6gre remote 2001:db8:3::1\n # ip link del dev bla\n # devlink dev reload pci/0000:01:00.0\n\n[2]\nWARNING: CPU: 0 PID: 1682 at drivers/net/ethernet/mellanox/mlxsw/spectrum.c:3002 mlxsw_sp_ipv6_addr_put+0x140/0x1d0\nModules linked in:\nCPU: 0 UID: 0 PID: 1682 Comm: ip Not tainted 6.12.0-rc3-custom-g86b5b55bc835 #151\nHardware name: Nvidia SN5600/VMOD0013, BIOS 5.13 05/31/2023\nRIP: 0010:mlxsw_sp_ipv6_addr_put+0x140/0x1d0\n[...]\nCall Trace:\n \u003cTASK\u003e\n mlxsw_sp_router_netdevice_event+0x55f/0x1240\n notifier_call_chain+0x5a/0xd0\n call_netdevice_notifiers_info+0x39/0x90\n unregister_netdevice_many_notify+0x63e/0x9d0\n rtnl_dellink+0x16b/0x3a0\n rtnetlink_rcv_msg+0x142/0x3f0\n netlink_rcv_skb+0x50/0x100\n netlink_unicast+0x242/0x390\n netlink_sendmsg+0x1de/0x420\n ____sys_sendmsg+0x2bd/0x320\n ___sys_sendmsg+0x9a/0xe0\n __sys_sendmsg+0x7a/0xd0\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n[3]\nunreferenced object 0xffff898081f597a0 (size 32):\n comm \"ip\", pid 1626, jiffies 4294719324\n hex dump (first 32 bytes):\n 20 01 0d b8 00 02 00 00 00 00 00 00 00 00 00 01 ...............\n 21 49 61 83 80 89 ff ff 00 00 00 00 01 00 00 00 !Ia.............\n backtrace (crc fd9be911):\n [\u003c00000000df89c55d\u003e] __kmalloc_cache_noprof+0x1da/0x260\n [\u003c00000000ff2a1ddb\u003e] mlxsw_sp_ipv6_addr_kvdl_index_get+0x281/0x340\n [\u003c000000009ddd445d\u003e] mlxsw_sp_router_netdevice_event+0x47b/0x1240\n [\u003c00000000743e7757\u003e] notifier_call_chain+0x5a/0xd0\n [\u003c000000007c7b9e13\u003e] call_netdevice_notifiers_info+0x39/0x90\n [\u003c000000002509645d\u003e] register_netdevice+0x5f7/0x7a0\n [\u003c00000000c2e7d2a9\u003e] ip6gre_newlink_common.isra.0+0x65/0x130\n [\u003c0000000087cd6d8d\u003e] ip6gre_newlink+0x72/0x120\n [\u003c000000004df7c7cc\u003e] rtnl_newlink+0x471/0xa20\n [\u003c0000000057ed632a\u003e] rtnetlink_rcv_msg+0x142/0x3f0\n [\u003c0000000032e0d5b5\u003e] netlink_rcv_skb+0x50/0x100\n [\u003c00000000908bca63\u003e] netlink_unicast+0x242/0x390\n [\u003c00000000cdbe1c87\u003e] netlink_sendmsg+0x1de/0x420\n [\u003c0000000011db153e\u003e] ____sys_sendmsg+0x2bd/0x320\n [\u003c000000003b6d53eb\u003e] ___sys_sendmsg+0x9a/0xe0\n [\u003c00000000cae27c62\u003e] __sys_sendmsg+0x7a/0xd0", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50252", "url": "https://www.suse.com/security/cve/CVE-2024-50252" }, { "category": "external", "summary": "SUSE Bug 1233201 for CVE-2024-50252", "url": "https://bugzilla.suse.com/1233201" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50252" }, { "cve": "CVE-2024-50255", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50255" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci: fix null-ptr-deref in hci_read_supported_codecs\n\nFix __hci_cmd_sync_sk() to return not NULL for unknown opcodes.\n\n__hci_cmd_sync_sk() returns NULL if a command returns a status event.\nHowever, it also returns NULL where an opcode doesn\u0027t exist in the\nhci_cc table because hci_cmd_complete_evt() assumes status = skb-\u003edata[0]\nfor unknown opcodes.\nThis leads to null-ptr-deref in cmd_sync for HCI_OP_READ_LOCAL_CODECS as\nthere is no hci_cc for HCI_OP_READ_LOCAL_CODECS, which always assumes\nstatus = skb-\u003edata[0].\n\nKASAN: null-ptr-deref in range [0x0000000000000070-0x0000000000000077]\nCPU: 1 PID: 2000 Comm: kworker/u9:5 Not tainted 6.9.0-ga6bcb805883c-dirty #10\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nWorkqueue: hci7 hci_power_on\nRIP: 0010:hci_read_supported_codecs+0xb9/0x870 net/bluetooth/hci_codec.c:138\nCode: 08 48 89 ef e8 b8 c1 8f fd 48 8b 75 00 e9 96 00 00 00 49 89 c6 48 ba 00 00 00 00 00 fc ff df 4c 8d 60 70 4c 89 e3 48 c1 eb 03 \u003c0f\u003e b6 04 13 84 c0 0f 85 82 06 00 00 41 83 3c 24 02 77 0a e8 bf 78\nRSP: 0018:ffff888120bafac8 EFLAGS: 00010212\nRAX: 0000000000000000 RBX: 000000000000000e RCX: ffff8881173f0040\nRDX: dffffc0000000000 RSI: ffffffffa58496c0 RDI: ffff88810b9ad1e4\nRBP: ffff88810b9ac000 R08: ffffffffa77882a7 R09: 1ffffffff4ef1054\nR10: dffffc0000000000 R11: fffffbfff4ef1055 R12: 0000000000000070\nR13: 0000000000000000 R14: 0000000000000000 R15: ffff88810b9ac000\nFS: 0000000000000000(0000) GS:ffff8881f6c00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f6ddaa3439e CR3: 0000000139764003 CR4: 0000000000770ef0\nPKRU: 55555554\nCall Trace:\n \u003cTASK\u003e\n hci_read_local_codecs_sync net/bluetooth/hci_sync.c:4546 [inline]\n hci_init_stage_sync net/bluetooth/hci_sync.c:3441 [inline]\n hci_init4_sync net/bluetooth/hci_sync.c:4706 [inline]\n hci_init_sync net/bluetooth/hci_sync.c:4742 [inline]\n hci_dev_init_sync net/bluetooth/hci_sync.c:4912 [inline]\n hci_dev_open_sync+0x19a9/0x2d30 net/bluetooth/hci_sync.c:4994\n hci_dev_do_open net/bluetooth/hci_core.c:483 [inline]\n hci_power_on+0x11e/0x560 net/bluetooth/hci_core.c:1015\n process_one_work kernel/workqueue.c:3267 [inline]\n process_scheduled_works+0x8ef/0x14f0 kernel/workqueue.c:3348\n worker_thread+0x91f/0xe50 kernel/workqueue.c:3429\n kthread+0x2cb/0x360 kernel/kthread.c:388\n ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50255", "url": "https://www.suse.com/security/cve/CVE-2024-50255" }, { "category": "external", "summary": "SUSE Bug 1233238 for CVE-2024-50255", "url": "https://bugzilla.suse.com/1233238" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50255" }, { "cve": "CVE-2024-50257", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50257" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: Fix use-after-free in get_info()\n\nip6table_nat module unload has refcnt warning for UAF. call trace is:\n\nWARNING: CPU: 1 PID: 379 at kernel/module/main.c:853 module_put+0x6f/0x80\nModules linked in: ip6table_nat(-)\nCPU: 1 UID: 0 PID: 379 Comm: ip6tables Not tainted 6.12.0-rc4-00047-gc2ee9f594da8-dirty #205\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996),\nBIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:module_put+0x6f/0x80\nCall Trace:\n \u003cTASK\u003e\n get_info+0x128/0x180\n do_ip6t_get_ctl+0x6a/0x430\n nf_getsockopt+0x46/0x80\n ipv6_getsockopt+0xb9/0x100\n rawv6_getsockopt+0x42/0x190\n do_sock_getsockopt+0xaa/0x180\n __sys_getsockopt+0x70/0xc0\n __x64_sys_getsockopt+0x20/0x30\n do_syscall_64+0xa2/0x1a0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nConcurrent execution of module unload and get_info() trigered the warning.\nThe root cause is as follows:\n\ncpu0\t\t\t\t cpu1\nmodule_exit\n//mod-\u003estate = MODULE_STATE_GOING\n ip6table_nat_exit\n xt_unregister_template\n\tkfree(t)\n\t//removed from templ_list\n\t\t\t\t getinfo()\n\t\t\t\t\t t = xt_find_table_lock\n\t\t\t\t\t\tlist_for_each_entry(tmpl, \u0026xt_templates[af]...)\n\t\t\t\t\t\t\tif (strcmp(tmpl-\u003ename, name))\n\t\t\t\t\t\t\t\tcontinue; //table not found\n\t\t\t\t\t\t\ttry_module_get\n\t\t\t\t\t\tlist_for_each_entry(t, \u0026xt_net-\u003etables[af]...)\n\t\t\t\t\t\t\treturn t; //not get refcnt\n\t\t\t\t\t module_put(t-\u003eme) //uaf\n unregister_pernet_subsys\n //remove table from xt_net list\n\nWhile xt_table module was going away and has been removed from\nxt_templates list, we couldnt get refcnt of xt_table-\u003eme. Check\nmodule in xt_net-\u003etables list re-traversal to fix it.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50257", "url": "https://www.suse.com/security/cve/CVE-2024-50257" }, { "category": "external", "summary": "SUSE Bug 1233244 for CVE-2024-50257", "url": "https://bugzilla.suse.com/1233244" }, { "category": "external", "summary": "SUSE Bug 1233245 for CVE-2024-50257", "url": "https://bugzilla.suse.com/1233245" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50257" }, { "cve": "CVE-2024-50261", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50261" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmacsec: Fix use-after-free while sending the offloading packet\n\nKASAN reports the following UAF. The metadata_dst, which is used to\nstore the SCI value for macsec offload, is already freed by\nmetadata_dst_free() in macsec_free_netdev(), while driver still use it\nfor sending the packet.\n\nTo fix this issue, dst_release() is used instead to release\nmetadata_dst. So it is not freed instantly in macsec_free_netdev() if\nstill referenced by skb.\n\n BUG: KASAN: slab-use-after-free in mlx5e_xmit+0x1e8f/0x4190 [mlx5_core]\n Read of size 2 at addr ffff88813e42e038 by task kworker/7:2/714\n [...]\n Workqueue: mld mld_ifc_work\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x51/0x60\n print_report+0xc1/0x600\n kasan_report+0xab/0xe0\n mlx5e_xmit+0x1e8f/0x4190 [mlx5_core]\n dev_hard_start_xmit+0x120/0x530\n sch_direct_xmit+0x149/0x11e0\n __qdisc_run+0x3ad/0x1730\n __dev_queue_xmit+0x1196/0x2ed0\n vlan_dev_hard_start_xmit+0x32e/0x510 [8021q]\n dev_hard_start_xmit+0x120/0x530\n __dev_queue_xmit+0x14a7/0x2ed0\n macsec_start_xmit+0x13e9/0x2340\n dev_hard_start_xmit+0x120/0x530\n __dev_queue_xmit+0x14a7/0x2ed0\n ip6_finish_output2+0x923/0x1a70\n ip6_finish_output+0x2d7/0x970\n ip6_output+0x1ce/0x3a0\n NF_HOOK.constprop.0+0x15f/0x190\n mld_sendpack+0x59a/0xbd0\n mld_ifc_work+0x48a/0xa80\n process_one_work+0x5aa/0xe50\n worker_thread+0x79c/0x1290\n kthread+0x28f/0x350\n ret_from_fork+0x2d/0x70\n ret_from_fork_asm+0x11/0x20\n \u003c/TASK\u003e\n\n Allocated by task 3922:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x10/0x30\n __kasan_kmalloc+0x77/0x90\n __kmalloc_noprof+0x188/0x400\n metadata_dst_alloc+0x1f/0x4e0\n macsec_newlink+0x914/0x1410\n __rtnl_newlink+0xe08/0x15b0\n rtnl_newlink+0x5f/0x90\n rtnetlink_rcv_msg+0x667/0xa80\n netlink_rcv_skb+0x12c/0x360\n netlink_unicast+0x551/0x770\n netlink_sendmsg+0x72d/0xbd0\n __sock_sendmsg+0xc5/0x190\n ____sys_sendmsg+0x52e/0x6a0\n ___sys_sendmsg+0xeb/0x170\n __sys_sendmsg+0xb5/0x140\n do_syscall_64+0x4c/0x100\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n Freed by task 4011:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x10/0x30\n kasan_save_free_info+0x37/0x50\n poison_slab_object+0x10c/0x190\n __kasan_slab_free+0x11/0x30\n kfree+0xe0/0x290\n macsec_free_netdev+0x3f/0x140\n netdev_run_todo+0x450/0xc70\n rtnetlink_rcv_msg+0x66f/0xa80\n netlink_rcv_skb+0x12c/0x360\n netlink_unicast+0x551/0x770\n netlink_sendmsg+0x72d/0xbd0\n __sock_sendmsg+0xc5/0x190\n ____sys_sendmsg+0x52e/0x6a0\n ___sys_sendmsg+0xeb/0x170\n __sys_sendmsg+0xb5/0x140\n do_syscall_64+0x4c/0x100\n entry_SYSCALL_64_after_hwframe+0x4b/0x53", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50261", "url": "https://www.suse.com/security/cve/CVE-2024-50261" }, { "category": "external", "summary": "SUSE Bug 1233253 for CVE-2024-50261", "url": "https://bugzilla.suse.com/1233253" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50261" }, { "cve": "CVE-2024-50264", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50264" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: Initialization of the dangling pointer occurring in vsk-\u003etrans\n\nDuring loopback communication, a dangling pointer can be created in\nvsk-\u003etrans, potentially leading to a Use-After-Free condition. This\nissue is resolved by initializing vsk-\u003etrans to NULL.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50264", "url": "https://www.suse.com/security/cve/CVE-2024-50264" }, { "category": "external", "summary": "SUSE Bug 1233453 for CVE-2024-50264", "url": "https://bugzilla.suse.com/1233453" }, { "category": "external", "summary": "SUSE Bug 1233712 for CVE-2024-50264", "url": "https://bugzilla.suse.com/1233712" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50264" }, { "cve": "CVE-2024-50265", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50265" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()\n\nSyzkaller is able to provoke null-ptr-dereference in ocfs2_xa_remove():\n\n[ 57.319872] (a.out,1161,7):ocfs2_xa_remove:2028 ERROR: status = -12\n[ 57.320420] (a.out,1161,7):ocfs2_xa_cleanup_value_truncate:1999 ERROR: Partial truncate while removing xattr overlay.upper. Leaking 1 clusters and removing the entry\n[ 57.321727] BUG: kernel NULL pointer dereference, address: 0000000000000004\n[...]\n[ 57.325727] RIP: 0010:ocfs2_xa_block_wipe_namevalue+0x2a/0xc0\n[...]\n[ 57.331328] Call Trace:\n[ 57.331477] \u003cTASK\u003e\n[...]\n[ 57.333511] ? do_user_addr_fault+0x3e5/0x740\n[ 57.333778] ? exc_page_fault+0x70/0x170\n[ 57.334016] ? asm_exc_page_fault+0x2b/0x30\n[ 57.334263] ? __pfx_ocfs2_xa_block_wipe_namevalue+0x10/0x10\n[ 57.334596] ? ocfs2_xa_block_wipe_namevalue+0x2a/0xc0\n[ 57.334913] ocfs2_xa_remove_entry+0x23/0xc0\n[ 57.335164] ocfs2_xa_set+0x704/0xcf0\n[ 57.335381] ? _raw_spin_unlock+0x1a/0x40\n[ 57.335620] ? ocfs2_inode_cache_unlock+0x16/0x20\n[ 57.335915] ? trace_preempt_on+0x1e/0x70\n[ 57.336153] ? start_this_handle+0x16c/0x500\n[ 57.336410] ? preempt_count_sub+0x50/0x80\n[ 57.336656] ? _raw_read_unlock+0x20/0x40\n[ 57.336906] ? start_this_handle+0x16c/0x500\n[ 57.337162] ocfs2_xattr_block_set+0xa6/0x1e0\n[ 57.337424] __ocfs2_xattr_set_handle+0x1fd/0x5d0\n[ 57.337706] ? ocfs2_start_trans+0x13d/0x290\n[ 57.337971] ocfs2_xattr_set+0xb13/0xfb0\n[ 57.338207] ? dput+0x46/0x1c0\n[ 57.338393] ocfs2_xattr_trusted_set+0x28/0x30\n[ 57.338665] ? ocfs2_xattr_trusted_set+0x28/0x30\n[ 57.338948] __vfs_removexattr+0x92/0xc0\n[ 57.339182] __vfs_removexattr_locked+0xd5/0x190\n[ 57.339456] ? preempt_count_sub+0x50/0x80\n[ 57.339705] vfs_removexattr+0x5f/0x100\n[...]\n\nReproducer uses faultinject facility to fail ocfs2_xa_remove() -\u003e\nocfs2_xa_value_truncate() with -ENOMEM.\n\nIn this case the comment mentions that we can return 0 if\nocfs2_xa_cleanup_value_truncate() is going to wipe the entry\nanyway. But the following \u0027rc\u0027 check is wrong and execution flow do\n\u0027ocfs2_xa_remove_entry(loc);\u0027 twice:\n* 1st: in ocfs2_xa_cleanup_value_truncate();\n* 2nd: returning back to ocfs2_xa_remove() instead of going to \u0027out\u0027.\n\nFix this by skipping the 2nd removal of the same entry and making\nsyzkaller repro happy.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50265", "url": "https://www.suse.com/security/cve/CVE-2024-50265" }, { "category": "external", "summary": "SUSE Bug 1233454 for CVE-2024-50265", "url": "https://bugzilla.suse.com/1233454" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50265" }, { "cve": "CVE-2024-50267", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50267" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: io_edgeport: fix use after free in debug printk\n\nThe \"dev_dbg(\u0026urb-\u003edev-\u003edev, ...\" which happens after usb_free_urb(urb)\nis a use after free of the \"urb\" pointer. Store the \"dev\" pointer at the\nstart of the function to avoid this issue.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50267", "url": "https://www.suse.com/security/cve/CVE-2024-50267" }, { "category": "external", "summary": "SUSE Bug 1233456 for CVE-2024-50267", "url": "https://bugzilla.suse.com/1233456" }, { "category": "external", "summary": "SUSE Bug 1233711 for CVE-2024-50267", "url": "https://bugzilla.suse.com/1233711" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50267" }, { "cve": "CVE-2024-50268", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50268" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd()\n\nThe \"*cmd\" variable can be controlled by the user via debugfs. That means\n\"new_cam\" can be as high as 255 while the size of the uc-\u003eupdated[] array\nis UCSI_MAX_ALTMODES (30).\n\nThe call tree is:\nucsi_cmd() // val comes from simple_attr_write_xsigned()\n-\u003e ucsi_send_command()\n -\u003e ucsi_send_command_common()\n -\u003e ucsi_run_command() // calls ucsi-\u003eops-\u003esync_control()\n -\u003e ucsi_ccg_sync_control()", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50268", "url": "https://www.suse.com/security/cve/CVE-2024-50268" }, { "category": "external", "summary": "SUSE Bug 1233457 for CVE-2024-50268", "url": "https://bugzilla.suse.com/1233457" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50268" }, { "cve": "CVE-2024-50269", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50269" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: musb: sunxi: Fix accessing an released usb phy\n\nCommit 6ed05c68cbca (\"usb: musb: sunxi: Explicitly release USB PHY on\nexit\") will cause that usb phy @glue-\u003exceiv is accessed after released.\n\n1) register platform driver @sunxi_musb_driver\n// get the usb phy @glue-\u003exceiv\nsunxi_musb_probe() -\u003e devm_usb_get_phy().\n\n2) register and unregister platform driver @musb_driver\nmusb_probe() -\u003e sunxi_musb_init()\nuse the phy here\n//the phy is released here\nmusb_remove() -\u003e sunxi_musb_exit() -\u003e devm_usb_put_phy()\n\n3) register @musb_driver again\nmusb_probe() -\u003e sunxi_musb_init()\nuse the phy here but the phy has been released at 2).\n...\n\nFixed by reverting the commit, namely, removing devm_usb_put_phy()\nfrom sunxi_musb_exit().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50269", "url": "https://www.suse.com/security/cve/CVE-2024-50269" }, { "category": "external", "summary": "SUSE Bug 1233458 for CVE-2024-50269", "url": "https://bugzilla.suse.com/1233458" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50269" }, { "cve": "CVE-2024-50271", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50271" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsignal: restore the override_rlimit logic\n\nPrior to commit d64696905554 (\"Reimplement RLIMIT_SIGPENDING on top of\nucounts\") UCOUNT_RLIMIT_SIGPENDING rlimit was not enforced for a class of\nsignals. However now it\u0027s enforced unconditionally, even if\noverride_rlimit is set. This behavior change caused production issues. \n\nFor example, if the limit is reached and a process receives a SIGSEGV\nsignal, sigqueue_alloc fails to allocate the necessary resources for the\nsignal delivery, preventing the signal from being delivered with siginfo. \nThis prevents the process from correctly identifying the fault address and\nhandling the error. From the user-space perspective, applications are\nunaware that the limit has been reached and that the siginfo is\neffectively \u0027corrupted\u0027. This can lead to unpredictable behavior and\ncrashes, as we observed with java applications.\n\nFix this by passing override_rlimit into inc_rlimit_get_ucounts() and skip\nthe comparison to max there if override_rlimit is set. This effectively\nrestores the old behavior.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50271", "url": "https://www.suse.com/security/cve/CVE-2024-50271" }, { "category": "external", "summary": "SUSE Bug 1233460 for CVE-2024-50271", "url": "https://bugzilla.suse.com/1233460" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50271" }, { "cve": "CVE-2024-50273", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50273" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reinitialize delayed ref list after deleting it from the list\n\nAt insert_delayed_ref() if we need to update the action of an existing\nref to BTRFS_DROP_DELAYED_REF, we delete the ref from its ref head\u0027s\nref_add_list using list_del(), which leaves the ref\u0027s add_list member\nnot reinitialized, as list_del() sets the next and prev members of the\nlist to LIST_POISON1 and LIST_POISON2, respectively.\n\nIf later we end up calling drop_delayed_ref() against the ref, which can\nhappen during merging or when destroying delayed refs due to a transaction\nabort, we can trigger a crash since at drop_delayed_ref() we call\nlist_empty() against the ref\u0027s add_list, which returns false since\nthe list was not reinitialized after the list_del() and as a consequence\nwe call list_del() again at drop_delayed_ref(). This results in an\ninvalid list access since the next and prev members are set to poison\npointers, resulting in a splat if CONFIG_LIST_HARDENED and\nCONFIG_DEBUG_LIST are set or invalid poison pointer dereferences\notherwise.\n\nSo fix this by deleting from the list with list_del_init() instead.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50273", "url": "https://www.suse.com/security/cve/CVE-2024-50273" }, { "category": "external", "summary": "SUSE Bug 1233462 for CVE-2024-50273", "url": "https://bugzilla.suse.com/1233462" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50273" }, { "cve": "CVE-2024-50274", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50274" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: avoid vport access in idpf_get_link_ksettings\n\nWhen the device control plane is removed or the platform\nrunning device control plane is rebooted, a reset is detected\non the driver. On driver reset, it releases the resources and\nwaits for the reset to complete. If the reset fails, it takes\nthe error path and releases the vport lock. At this time if the\nmonitoring tools tries to access link settings, it call traces\nfor accessing released vport pointer.\n\nTo avoid it, move link_speed_mbps to netdev_priv structure\nwhich removes the dependency on vport pointer and the vport lock\nin idpf_get_link_ksettings. Also use netif_carrier_ok()\nto check the link status and adjust the offsetof to use link_up\ninstead of link_speed_mbps.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50274", "url": "https://www.suse.com/security/cve/CVE-2024-50274" }, { "category": "external", "summary": "SUSE Bug 1233463 for CVE-2024-50274", "url": "https://bugzilla.suse.com/1233463" }, { "category": "external", "summary": "SUSE Bug 1235104 for CVE-2024-50274", "url": "https://bugzilla.suse.com/1235104" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50274" }, { "cve": "CVE-2024-50275", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50275" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64/sve: Discard stale CPU state when handling SVE traps\n\nThe logic for handling SVE traps manipulates saved FPSIMD/SVE state\nincorrectly, and a race with preemption can result in a task having\nTIF_SVE set and TIF_FOREIGN_FPSTATE clear even though the live CPU state\nis stale (e.g. with SVE traps enabled). This has been observed to result\nin warnings from do_sve_acc() where SVE traps are not expected while\nTIF_SVE is set:\n\n| if (test_and_set_thread_flag(TIF_SVE))\n| WARN_ON(1); /* SVE access shouldn\u0027t have trapped */\n\nWarnings of this form have been reported intermittently, e.g.\n\n https://lore.kernel.org/linux-arm-kernel/CA+G9fYtEGe_DhY2Ms7+L7NKsLYUomGsgqpdBj+QwDLeSg=JhGg@mail.gmail.com/\n https://lore.kernel.org/linux-arm-kernel/000000000000511e9a060ce5a45c@google.com/\n\nThe race can occur when the SVE trap handler is preempted before and\nafter manipulating the saved FPSIMD/SVE state, starting and ending on\nthe same CPU, e.g.\n\n| void do_sve_acc(unsigned long esr, struct pt_regs *regs)\n| {\n| // Trap on CPU 0 with TIF_SVE clear, SVE traps enabled\n| // task-\u003efpsimd_cpu is 0.\n| // per_cpu_ptr(\u0026fpsimd_last_state, 0) is task.\n|\n| ...\n|\n| // Preempted; migrated from CPU 0 to CPU 1.\n| // TIF_FOREIGN_FPSTATE is set.\n|\n| get_cpu_fpsimd_context();\n|\n| if (test_and_set_thread_flag(TIF_SVE))\n| WARN_ON(1); /* SVE access shouldn\u0027t have trapped */\n|\n| sve_init_regs() {\n| if (!test_thread_flag(TIF_FOREIGN_FPSTATE)) {\n| ...\n| } else {\n| fpsimd_to_sve(current);\n| current-\u003ethread.fp_type = FP_STATE_SVE;\n| }\n| }\n|\n| put_cpu_fpsimd_context();\n|\n| // Preempted; migrated from CPU 1 to CPU 0.\n| // task-\u003efpsimd_cpu is still 0\n| // If per_cpu_ptr(\u0026fpsimd_last_state, 0) is still task then:\n| // - Stale HW state is reused (with SVE traps enabled)\n| // - TIF_FOREIGN_FPSTATE is cleared\n| // - A return to userspace skips HW state restore\n| }\n\nFix the case where the state is not live and TIF_FOREIGN_FPSTATE is set\nby calling fpsimd_flush_task_state() to detach from the saved CPU\nstate. This ensures that a subsequent context switch will not reuse the\nstale CPU state, and will instead set TIF_FOREIGN_FPSTATE, forcing the\nnew state to be reloaded from memory prior to a return to userspace.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50275", "url": "https://www.suse.com/security/cve/CVE-2024-50275" }, { "category": "external", "summary": "SUSE Bug 1233464 for CVE-2024-50275", "url": "https://bugzilla.suse.com/1233464" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50275" }, { "cve": "CVE-2024-50276", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50276" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: vertexcom: mse102x: Fix possible double free of TX skb\n\nThe scope of the TX skb is wider than just mse102x_tx_frame_spi(),\nso in case the TX skb room needs to be expanded, we should free the\nthe temporary skb instead of the original skb. Otherwise the original\nTX skb pointer would be freed again in mse102x_tx_work(), which leads\nto crashes:\n\n Internal error: Oops: 0000000096000004 [#2] PREEMPT SMP\n CPU: 0 PID: 712 Comm: kworker/0:1 Tainted: G D 6.6.23\n Hardware name: chargebyte Charge SOM DC-ONE (DT)\n Workqueue: events mse102x_tx_work [mse102x]\n pstate: 20400009 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : skb_release_data+0xb8/0x1d8\n lr : skb_release_data+0x1ac/0x1d8\n sp : ffff8000819a3cc0\n x29: ffff8000819a3cc0 x28: ffff0000046daa60 x27: ffff0000057f2dc0\n x26: ffff000005386c00 x25: 0000000000000002 x24: 00000000ffffffff\n x23: 0000000000000000 x22: 0000000000000001 x21: ffff0000057f2e50\n x20: 0000000000000006 x19: 0000000000000000 x18: ffff00003fdacfcc\n x17: e69ad452d0c49def x16: 84a005feff870102 x15: 0000000000000000\n x14: 000000000000024a x13: 0000000000000002 x12: 0000000000000000\n x11: 0000000000000400 x10: 0000000000000930 x9 : ffff00003fd913e8\n x8 : fffffc00001bc008\n x7 : 0000000000000000 x6 : 0000000000000008\n x5 : ffff00003fd91340 x4 : 0000000000000000 x3 : 0000000000000009\n x2 : 00000000fffffffe x1 : 0000000000000000 x0 : 0000000000000000\n Call trace:\n skb_release_data+0xb8/0x1d8\n kfree_skb_reason+0x48/0xb0\n mse102x_tx_work+0x164/0x35c [mse102x]\n process_one_work+0x138/0x260\n worker_thread+0x32c/0x438\n kthread+0x118/0x11c\n ret_from_fork+0x10/0x20\n Code: aa1303e0 97fffab6 72001c1f 54000141 (f9400660)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50276", "url": "https://www.suse.com/security/cve/CVE-2024-50276" }, { "category": "external", "summary": "SUSE Bug 1233465 for CVE-2024-50276", "url": "https://bugzilla.suse.com/1233465" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50276" }, { "cve": "CVE-2024-50279", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50279" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache: fix out-of-bounds access to the dirty bitset when resizing\n\ndm-cache checks the dirty bits of the cache blocks to be dropped when\nshrinking the fast device, but an index bug in bitset iteration causes\nout-of-bounds access.\n\nReproduce steps:\n\n1. create a cache device of 1024 cache blocks (128 bytes dirty bitset)\n\ndmsetup create cmeta --table \"0 8192 linear /dev/sdc 0\"\ndmsetup create cdata --table \"0 131072 linear /dev/sdc 8192\"\ndmsetup create corig --table \"0 524288 linear /dev/sdc 262144\"\ndd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 oflag=direct\ndmsetup create cache --table \"0 524288 cache /dev/mapper/cmeta \\\n/dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writethrough smq 0\"\n\n2. shrink the fast device to 512 cache blocks, triggering out-of-bounds\n access to the dirty bitset (offset 0x80)\n\ndmsetup suspend cache\ndmsetup reload cdata --table \"0 65536 linear /dev/sdc 8192\"\ndmsetup resume cdata\ndmsetup resume cache\n\nKASAN reports:\n\n BUG: KASAN: vmalloc-out-of-bounds in cache_preresume+0x269/0x7b0\n Read of size 8 at addr ffffc900000f3080 by task dmsetup/131\n\n (...snip...)\n The buggy address belongs to the virtual mapping at\n [ffffc900000f3000, ffffc900000f5000) created by:\n cache_ctr+0x176a/0x35f0\n\n (...snip...)\n Memory state around the buggy address:\n ffffc900000f2f80: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n ffffc900000f3000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n \u003effffc900000f3080: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n ^\n ffffc900000f3100: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n ffffc900000f3180: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n\nFix by making the index post-incremented.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50279", "url": "https://www.suse.com/security/cve/CVE-2024-50279" }, { "category": "external", "summary": "SUSE Bug 1233468 for CVE-2024-50279", "url": "https://bugzilla.suse.com/1233468" }, { "category": "external", "summary": "SUSE Bug 1233708 for CVE-2024-50279", "url": "https://bugzilla.suse.com/1233708" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50279" }, { "cve": "CVE-2024-50282", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50282" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()\n\nAvoid a possible buffer overflow if size is larger than 4K.\n\n(cherry picked from commit f5d873f5825b40d886d03bd2aede91d4cf002434)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50282", "url": "https://www.suse.com/security/cve/CVE-2024-50282" }, { "category": "external", "summary": "SUSE Bug 1233471 for CVE-2024-50282", "url": "https://bugzilla.suse.com/1233471" }, { "category": "external", "summary": "SUSE Bug 1233707 for CVE-2024-50282", "url": "https://bugzilla.suse.com/1233707" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.3, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50282" }, { "cve": "CVE-2024-50287", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50287" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-tpg: prevent the risk of a division by zero\n\nAs reported by Coverity, the logic at tpg_precalculate_line()\nblindly rescales the buffer even when scaled_witdh is equal to\nzero. If this ever happens, this will cause a division by zero.\n\nInstead, add a WARN_ON_ONCE() to trigger such cases and return\nwithout doing any precalculation.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50287", "url": "https://www.suse.com/security/cve/CVE-2024-50287" }, { "category": "external", "summary": "SUSE Bug 1233476 for CVE-2024-50287", "url": "https://bugzilla.suse.com/1233476" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50287" }, { "cve": "CVE-2024-50289", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50289" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: av7110: fix a spectre vulnerability\n\nAs warned by smatch:\n\tdrivers/staging/media/av7110/av7110_ca.c:270 dvb_ca_ioctl() warn: potential spectre issue \u0027av7110-\u003eci_slot\u0027 [w] (local cap)\n\nThere is a spectre-related vulnerability at the code. Fix it.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50289", "url": "https://www.suse.com/security/cve/CVE-2024-50289" }, { "category": "external", "summary": "SUSE Bug 1233478 for CVE-2024-50289", "url": "https://bugzilla.suse.com/1233478" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50289" }, { "cve": "CVE-2024-50290", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50290" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx24116: prevent overflows on SNR calculus\n\nas reported by Coverity, if reading SNR registers fail, a negative\nnumber will be returned, causing an underflow when reading SNR\nregisters.\n\nPrevent that.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50290", "url": "https://www.suse.com/security/cve/CVE-2024-50290" }, { "category": "external", "summary": "SUSE Bug 1225742 for CVE-2024-50290", "url": "https://bugzilla.suse.com/1225742" }, { "category": "external", "summary": "SUSE Bug 1233479 for CVE-2024-50290", "url": "https://bugzilla.suse.com/1233479" }, { "category": "external", "summary": "SUSE Bug 1233681 for CVE-2024-50290", "url": "https://bugzilla.suse.com/1233681" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50290" }, { "cve": "CVE-2024-50292", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50292" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: stm32: spdifrx: fix dma channel release in stm32_spdifrx_remove\n\nIn case of error when requesting ctrl_chan DMA channel, ctrl_chan is not\nnull. So the release of the dma channel leads to the following issue:\n[ 4.879000] st,stm32-spdifrx 500d0000.audio-controller:\ndma_request_slave_channel error -19\n[ 4.888975] Unable to handle kernel NULL pointer dereference\nat virtual address 000000000000003d\n[...]\n[ 5.096577] Call trace:\n[ 5.099099] dma_release_channel+0x24/0x100\n[ 5.103235] stm32_spdifrx_remove+0x24/0x60 [snd_soc_stm32_spdifrx]\n[ 5.109494] stm32_spdifrx_probe+0x320/0x4c4 [snd_soc_stm32_spdifrx]\n\nTo avoid this issue, release channel only if the pointer is valid.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50292", "url": "https://www.suse.com/security/cve/CVE-2024-50292" }, { "category": "external", "summary": "SUSE Bug 1233481 for CVE-2024-50292", "url": "https://bugzilla.suse.com/1233481" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50292" }, { "cve": "CVE-2024-50295", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50295" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: arc: fix the device for dma_map_single/dma_unmap_single\n\nThe ndev-\u003edev and pdev-\u003edev aren\u0027t the same device, use ndev-\u003edev.parent\nwhich has dma_mask, ndev-\u003edev.parent is just pdev-\u003edev.\nOr it would cause the following issue:\n\n[ 39.933526] ------------[ cut here ]------------\n[ 39.938414] WARNING: CPU: 1 PID: 501 at kernel/dma/mapping.c:149 dma_map_page_attrs+0x90/0x1f8", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50295", "url": "https://www.suse.com/security/cve/CVE-2024-50295" }, { "category": "external", "summary": "SUSE Bug 1233484 for CVE-2024-50295", "url": "https://bugzilla.suse.com/1233484" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50295" }, { "cve": "CVE-2024-50296", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50296" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix kernel crash when uninstalling driver\n\nWhen the driver is uninstalled and the VF is disabled concurrently, a\nkernel crash occurs. The reason is that the two actions call function\npci_disable_sriov(). The num_VFs is checked to determine whether to\nrelease the corresponding resources. During the second calling, num_VFs\nis not 0 and the resource release function is called. However, the\ncorresponding resource has been released during the first invoking.\nTherefore, the problem occurs:\n\n[15277.839633][T50670] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020\n...\n[15278.131557][T50670] Call trace:\n[15278.134686][T50670] klist_put+0x28/0x12c\n[15278.138682][T50670] klist_del+0x14/0x20\n[15278.142592][T50670] device_del+0xbc/0x3c0\n[15278.146676][T50670] pci_remove_bus_device+0x84/0x120\n[15278.151714][T50670] pci_stop_and_remove_bus_device+0x6c/0x80\n[15278.157447][T50670] pci_iov_remove_virtfn+0xb4/0x12c\n[15278.162485][T50670] sriov_disable+0x50/0x11c\n[15278.166829][T50670] pci_disable_sriov+0x24/0x30\n[15278.171433][T50670] hnae3_unregister_ae_algo_prepare+0x60/0x90 [hnae3]\n[15278.178039][T50670] hclge_exit+0x28/0xd0 [hclge]\n[15278.182730][T50670] __se_sys_delete_module.isra.0+0x164/0x230\n[15278.188550][T50670] __arm64_sys_delete_module+0x1c/0x30\n[15278.193848][T50670] invoke_syscall+0x50/0x11c\n[15278.198278][T50670] el0_svc_common.constprop.0+0x158/0x164\n[15278.203837][T50670] do_el0_svc+0x34/0xcc\n[15278.207834][T50670] el0_svc+0x20/0x30\n\nFor details, see the following figure.\n\n rmmod hclge disable VFs\n----------------------------------------------------\nhclge_exit() sriov_numvfs_store()\n ... device_lock()\n pci_disable_sriov() hns3_pci_sriov_configure()\n pci_disable_sriov()\n sriov_disable()\n sriov_disable() if !num_VFs :\n if !num_VFs : return;\n return; sriov_del_vfs()\n sriov_del_vfs() ...\n ... klist_put()\n klist_put() ...\n ... num_VFs = 0;\n num_VFs = 0; device_unlock();\n\nIn this patch, when driver is removing, we get the device_lock()\nto protect num_VFs, just like sriov_numvfs_store().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50296", "url": "https://www.suse.com/security/cve/CVE-2024-50296" }, { "category": "external", "summary": "SUSE Bug 1233485 for CVE-2024-50296", "url": "https://bugzilla.suse.com/1233485" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50296" }, { "cve": "CVE-2024-50298", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50298" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: enetc: allocate vf_state during PF probes\n\nIn the previous implementation, vf_state is allocated memory only when VF\nis enabled. However, net_device_ops::ndo_set_vf_mac() may be called before\nVF is enabled to configure the MAC address of VF. If this is the case,\nenetc_pf_set_vf_mac() will access vf_state, resulting in access to a null\npointer. The simplified error log is as follows.\n\nroot@ls1028ardb:~# ip link set eno0 vf 1 mac 00:0c:e7:66:77:89\n[ 173.543315] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004\n[ 173.637254] pc : enetc_pf_set_vf_mac+0x3c/0x80 Message from sy\n[ 173.641973] lr : do_setlink+0x4a8/0xec8\n[ 173.732292] Call trace:\n[ 173.734740] enetc_pf_set_vf_mac+0x3c/0x80\n[ 173.738847] __rtnl_newlink+0x530/0x89c\n[ 173.742692] rtnl_newlink+0x50/0x7c\n[ 173.746189] rtnetlink_rcv_msg+0x128/0x390\n[ 173.750298] netlink_rcv_skb+0x60/0x130\n[ 173.754145] rtnetlink_rcv+0x18/0x24\n[ 173.757731] netlink_unicast+0x318/0x380\n[ 173.761665] netlink_sendmsg+0x17c/0x3c8", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50298", "url": "https://www.suse.com/security/cve/CVE-2024-50298" }, { "category": "external", "summary": "SUSE Bug 1233487 for CVE-2024-50298", "url": "https://bugzilla.suse.com/1233487" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-50298" }, { "cve": "CVE-2024-50301", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50301" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsecurity/keys: fix slab-out-of-bounds in key_task_permission\n\nKASAN reports an out of bounds read:\nBUG: KASAN: slab-out-of-bounds in __kuid_val include/linux/uidgid.h:36\nBUG: KASAN: slab-out-of-bounds in uid_eq include/linux/uidgid.h:63 [inline]\nBUG: KASAN: slab-out-of-bounds in key_task_permission+0x394/0x410\nsecurity/keys/permission.c:54\nRead of size 4 at addr ffff88813c3ab618 by task stress-ng/4362\n\nCPU: 2 PID: 4362 Comm: stress-ng Not tainted 5.10.0-14930-gafbffd6c3ede #15\nCall Trace:\n __dump_stack lib/dump_stack.c:82 [inline]\n dump_stack+0x107/0x167 lib/dump_stack.c:123\n print_address_description.constprop.0+0x19/0x170 mm/kasan/report.c:400\n __kasan_report.cold+0x6c/0x84 mm/kasan/report.c:560\n kasan_report+0x3a/0x50 mm/kasan/report.c:585\n __kuid_val include/linux/uidgid.h:36 [inline]\n uid_eq include/linux/uidgid.h:63 [inline]\n key_task_permission+0x394/0x410 security/keys/permission.c:54\n search_nested_keyrings+0x90e/0xe90 security/keys/keyring.c:793\n\nThis issue was also reported by syzbot.\n\nIt can be reproduced by following these steps(more details [1]):\n1. Obtain more than 32 inputs that have similar hashes, which ends with the\n pattern \u00270xxxxxxxe6\u0027.\n2. Reboot and add the keys obtained in step 1.\n\nThe reproducer demonstrates how this issue happened:\n1. In the search_nested_keyrings function, when it iterates through the\n slots in a node(below tag ascend_to_node), if the slot pointer is meta\n and node-\u003eback_pointer != NULL(it means a root), it will proceed to\n descend_to_node. However, there is an exception. If node is the root,\n and one of the slots points to a shortcut, it will be treated as a\n keyring.\n2. Whether the ptr is keyring decided by keyring_ptr_is_keyring function.\n However, KEYRING_PTR_SUBTYPE is 0x2UL, the same as\n ASSOC_ARRAY_PTR_SUBTYPE_MASK.\n3. When 32 keys with the similar hashes are added to the tree, the ROOT\n has keys with hashes that are not similar (e.g. slot 0) and it splits\n NODE A without using a shortcut. When NODE A is filled with keys that\n all hashes are xxe6, the keys are similar, NODE A will split with a\n shortcut. Finally, it forms the tree as shown below, where slot 6 points\n to a shortcut.\n\n NODE A\n +------\u003e+---+\n ROOT | | 0 | xxe6\n +---+ | +---+\n xxxx | 0 | shortcut : : xxe6\n +---+ | +---+\n xxe6 : : | | | xxe6\n +---+ | +---+\n | 6 |---+ : : xxe6\n +---+ +---+\n xxe6 : : | f | xxe6\n +---+ +---+\n xxe6 | f |\n +---+\n\n4. As mentioned above, If a slot(slot 6) of the root points to a shortcut,\n it may be mistakenly transferred to a key*, leading to a read\n out-of-bounds read.\n\nTo fix this issue, one should jump to descend_to_node if the ptr is a\nshortcut, regardless of whether the node is root or not.\n\n[1] https://lore.kernel.org/linux-kernel/1cfa878e-8c7b-4570-8606-21daf5e13ce7@huaweicloud.com/\n\n[jarkko: tweaked the commit message a bit to have an appropriate closes\n tag.]", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50301", "url": "https://www.suse.com/security/cve/CVE-2024-50301" }, { "category": "external", "summary": "SUSE Bug 1233490 for CVE-2024-50301", "url": "https://bugzilla.suse.com/1233490" }, { "category": "external", "summary": "SUSE Bug 1233680 for CVE-2024-50301", "url": "https://bugzilla.suse.com/1233680" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50301" }, { "cve": "CVE-2024-50302", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50302" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: zero-initialize the report buffer\n\nSince the report buffer is used by all kinds of drivers in various ways, let\u0027s\nzero-initialize it during allocation to make sure that it can\u0027t be ever used\nto leak kernel memory via specially-crafted report.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50302", "url": "https://www.suse.com/security/cve/CVE-2024-50302" }, { "category": "external", "summary": "SUSE Bug 1233491 for CVE-2024-50302", "url": "https://bugzilla.suse.com/1233491" }, { "category": "external", "summary": "SUSE Bug 1233679 for CVE-2024-50302", "url": "https://bugzilla.suse.com/1233679" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-50302" }, { "cve": "CVE-2024-53042", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53042" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_init_flow()\n\nThere are code paths from which the function is called without holding\nthe RCU read lock, resulting in a suspicious RCU usage warning [1].\n\nFix by using l3mdev_master_upper_ifindex_by_index() which will acquire\nthe RCU read lock before calling\nl3mdev_master_upper_ifindex_by_index_rcu().\n\n[1]\nWARNING: suspicious RCU usage\n6.12.0-rc3-custom-gac8f72681cf2 #141 Not tainted\n-----------------------------\nnet/core/dev.c:876 RCU-list traversed in non-reader section!!\n\nother info that might help us debug this:\n\nrcu_scheduler_active = 2, debug_locks = 1\n1 lock held by ip/361:\n #0: ffffffff86fc7cb0 (rtnl_mutex){+.+.}-{3:3}, at: rtnetlink_rcv_msg+0x377/0xf60\n\nstack backtrace:\nCPU: 3 UID: 0 PID: 361 Comm: ip Not tainted 6.12.0-rc3-custom-gac8f72681cf2 #141\nHardware name: Bochs Bochs, BIOS Bochs 01/01/2011\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0xba/0x110\n lockdep_rcu_suspicious.cold+0x4f/0xd6\n dev_get_by_index_rcu+0x1d3/0x210\n l3mdev_master_upper_ifindex_by_index_rcu+0x2b/0xf0\n ip_tunnel_bind_dev+0x72f/0xa00\n ip_tunnel_newlink+0x368/0x7a0\n ipgre_newlink+0x14c/0x170\n __rtnl_newlink+0x1173/0x19c0\n rtnl_newlink+0x6c/0xa0\n rtnetlink_rcv_msg+0x3cc/0xf60\n netlink_rcv_skb+0x171/0x450\n netlink_unicast+0x539/0x7f0\n netlink_sendmsg+0x8c1/0xd80\n ____sys_sendmsg+0x8f9/0xc20\n ___sys_sendmsg+0x197/0x1e0\n __sys_sendmsg+0x122/0x1f0\n do_syscall_64+0xbb/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53042", "url": "https://www.suse.com/security/cve/CVE-2024-53042" }, { "category": "external", "summary": "SUSE Bug 1233540 for CVE-2024-53042", "url": "https://bugzilla.suse.com/1233540" }, { "category": "external", "summary": "SUSE Bug 1233678 for CVE-2024-53042", "url": "https://bugzilla.suse.com/1233678" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-53042" }, { "cve": "CVE-2024-53043", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53043" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp i2c: handle NULL header address\n\ndaddr can be NULL if there is no neighbour table entry present,\nin that case the tx packet should be dropped.\n\nsaddr will usually be set by MCTP core, but check for NULL in case a\npacket is transmitted by a different protocol.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53043", "url": "https://www.suse.com/security/cve/CVE-2024-53043" }, { "category": "external", "summary": "SUSE Bug 1233523 for CVE-2024-53043", "url": "https://bugzilla.suse.com/1233523" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53043" }, { "cve": "CVE-2024-53045", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53045" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: dapm: fix bounds checker error in dapm_widget_list_create\n\nThe widgets array in the snd_soc_dapm_widget_list has a __counted_by\nattribute attached to it, which points to the num_widgets variable. This\nattribute is used in bounds checking, and if it is not set before the\narray is filled, then the bounds sanitizer will issue a warning or a\nkernel panic if CONFIG_UBSAN_TRAP is set.\n\nThis patch sets the size of the widgets list calculated with\nlist_for_each as the initial value for num_widgets as it is used for\nallocating memory for the array. It is updated with the actual number of\nadded elements after the array is filled.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53045", "url": "https://www.suse.com/security/cve/CVE-2024-53045" }, { "category": "external", "summary": "SUSE Bug 1233524 for CVE-2024-53045", "url": "https://bugzilla.suse.com/1233524" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53045" }, { "cve": "CVE-2024-53048", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53048" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix crash on probe for DPLL enabled E810 LOM\n\nThe E810 Lan On Motherboard (LOM) design is vendor specific. Intel\nprovides the reference design, but it is up to vendor on the final\nproduct design. For some cases, like Linux DPLL support, the static\nvalues defined in the driver does not reflect the actual LOM design.\nCurrent implementation of dpll pins is causing the crash on probe\nof the ice driver for such DPLL enabled E810 LOM designs:\n\nWARNING: (...) at drivers/dpll/dpll_core.c:495 dpll_pin_get+0x2c4/0x330\n...\nCall Trace:\n \u003cTASK\u003e\n ? __warn+0x83/0x130\n ? dpll_pin_get+0x2c4/0x330\n ? report_bug+0x1b7/0x1d0\n ? handle_bug+0x42/0x70\n ? exc_invalid_op+0x18/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? dpll_pin_get+0x117/0x330\n ? dpll_pin_get+0x2c4/0x330\n ? dpll_pin_get+0x117/0x330\n ice_dpll_get_pins.isra.0+0x52/0xe0 [ice]\n...\n\nThe number of dpll pins enabled by LOM vendor is greater than expected\nand defined in the driver for Intel designed NICs, which causes the crash.\n\nPrevent the crash and allow generic pin initialization within Linux DPLL\nsubsystem for DPLL enabled E810 LOM designs.\n\nNewly designed solution for described issue will be based on \"per HW\ndesign\" pin initialization. It requires pin information dynamically\nacquired from the firmware and is already in progress, planned for\nnext-tree only.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53048", "url": "https://www.suse.com/security/cve/CVE-2024-53048" }, { "category": "external", "summary": "SUSE Bug 1233721 for CVE-2024-53048", "url": "https://bugzilla.suse.com/1233721" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53048" }, { "cve": "CVE-2024-53051", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53051" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: Add encoder check in intel_hdcp_get_capability\n\nSometimes during hotplug scenario or suspend/resume scenario encoder is\nnot always initialized when intel_hdcp_get_capability add\na check to avoid kernel null pointer dereference.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53051", "url": "https://www.suse.com/security/cve/CVE-2024-53051" }, { "category": "external", "summary": "SUSE Bug 1233547 for CVE-2024-53051", "url": "https://bugzilla.suse.com/1233547" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53051" }, { "cve": "CVE-2024-53052", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53052" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/rw: fix missing NOWAIT check for O_DIRECT start write\n\nWhen io_uring starts a write, it\u0027ll call kiocb_start_write() to bump the\nsuper block rwsem, preventing any freezes from happening while that\nwrite is in-flight. The freeze side will grab that rwsem for writing,\nexcluding any new writers from happening and waiting for existing writes\nto finish. But io_uring unconditionally uses kiocb_start_write(), which\nwill block if someone is currently attempting to freeze the mount point.\nThis causes a deadlock where freeze is waiting for previous writes to\ncomplete, but the previous writes cannot complete, as the task that is\nsupposed to complete them is blocked waiting on starting a new write.\nThis results in the following stuck trace showing that dependency with\nthe write blocked starting a new write:\n\ntask:fio state:D stack:0 pid:886 tgid:886 ppid:876\nCall trace:\n __switch_to+0x1d8/0x348\n __schedule+0x8e8/0x2248\n schedule+0x110/0x3f0\n percpu_rwsem_wait+0x1e8/0x3f8\n __percpu_down_read+0xe8/0x500\n io_write+0xbb8/0xff8\n io_issue_sqe+0x10c/0x1020\n io_submit_sqes+0x614/0x2110\n __arm64_sys_io_uring_enter+0x524/0x1038\n invoke_syscall+0x74/0x268\n el0_svc_common.constprop.0+0x160/0x238\n do_el0_svc+0x44/0x60\n el0_svc+0x44/0xb0\n el0t_64_sync_handler+0x118/0x128\n el0t_64_sync+0x168/0x170\nINFO: task fsfreeze:7364 blocked for more than 15 seconds.\n Not tainted 6.12.0-rc5-00063-g76aaf945701c #7963\n\nwith the attempting freezer stuck trying to grab the rwsem:\n\ntask:fsfreeze state:D stack:0 pid:7364 tgid:7364 ppid:995\nCall trace:\n __switch_to+0x1d8/0x348\n __schedule+0x8e8/0x2248\n schedule+0x110/0x3f0\n percpu_down_write+0x2b0/0x680\n freeze_super+0x248/0x8a8\n do_vfs_ioctl+0x149c/0x1b18\n __arm64_sys_ioctl+0xd0/0x1a0\n invoke_syscall+0x74/0x268\n el0_svc_common.constprop.0+0x160/0x238\n do_el0_svc+0x44/0x60\n el0_svc+0x44/0xb0\n el0t_64_sync_handler+0x118/0x128\n el0t_64_sync+0x168/0x170\n\nFix this by having the io_uring side honor IOCB_NOWAIT, and only attempt a\nblocking grab of the super block rwsem if it isn\u0027t set. For normal issue\nwhere IOCB_NOWAIT would always be set, this returns -EAGAIN which will\nhave io_uring core issue a blocking attempt of the write. That will in\nturn also get completions run, ensuring forward progress.\n\nSince freezing requires CAP_SYS_ADMIN in the first place, this isn\u0027t\nsomething that can be triggered by a regular user.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53052", "url": "https://www.suse.com/security/cve/CVE-2024-53052" }, { "category": "external", "summary": "SUSE Bug 1233548 for CVE-2024-53052", "url": "https://bugzilla.suse.com/1233548" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53052" }, { "cve": "CVE-2024-53055", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53055" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: fix 6 GHz scan construction\n\nIf more than 255 colocated APs exist for the set of all\nAPs found during 2.4/5 GHz scanning, then the 6 GHz scan\nconstruction will loop forever since the loop variable\nhas type u8, which can never reach the number found when\nthat\u0027s bigger than 255, and is stored in a u32 variable.\nAlso move it into the loops to have a smaller scope.\n\nUsing a u32 there is fine, we limit the number of APs in\nthe scan list and each has a limit on the number of RNR\nentries due to the frame size. With a limit of 1000 scan\nresults, a frame size upper bound of 4096 (really it\u0027s\nmore like ~2300) and a TBTT entry size of at least 11,\nwe get an upper bound for the number of ~372k, well in\nthe bounds of a u32.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53055", "url": "https://www.suse.com/security/cve/CVE-2024-53055" }, { "category": "external", "summary": "SUSE Bug 1233550 for CVE-2024-53055", "url": "https://bugzilla.suse.com/1233550" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53055" }, { "cve": "CVE-2024-53056", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53056" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()\n\nIn mtk_crtc_create(), if the call to mbox_request_channel() fails then we\nset the \"mtk_crtc-\u003ecmdq_client.chan\" pointer to NULL. In that situation,\nwe do not call cmdq_pkt_create().\n\nDuring the cleanup, we need to check if the \"mtk_crtc-\u003ecmdq_client.chan\"\nis NULL first before calling cmdq_pkt_destroy(). Calling\ncmdq_pkt_destroy() is unnecessary if we didn\u0027t call cmdq_pkt_create() and\nit will result in a NULL pointer dereference.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53056", "url": "https://www.suse.com/security/cve/CVE-2024-53056" }, { "category": "external", "summary": "SUSE Bug 1233568 for CVE-2024-53056", "url": "https://bugzilla.suse.com/1233568" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53056" }, { "cve": "CVE-2024-53058", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53058" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data\n\nIn case the non-paged data of a SKB carries protocol header and protocol\npayload to be transmitted on a certain platform that the DMA AXI address\nwidth is configured to 40-bit/48-bit, or the size of the non-paged data\nis bigger than TSO_MAX_BUFF_SIZE on a certain platform that the DMA AXI\naddress width is configured to 32-bit, then this SKB requires at least\ntwo DMA transmit descriptors to serve it.\n\nFor example, three descriptors are allocated to split one DMA buffer\nmapped from one piece of non-paged data:\n dma_desc[N + 0],\n dma_desc[N + 1],\n dma_desc[N + 2].\nThen three elements of tx_q-\u003etx_skbuff_dma[] will be allocated to hold\nextra information to be reused in stmmac_tx_clean():\n tx_q-\u003etx_skbuff_dma[N + 0],\n tx_q-\u003etx_skbuff_dma[N + 1],\n tx_q-\u003etx_skbuff_dma[N + 2].\nNow we focus on tx_q-\u003etx_skbuff_dma[entry].buf, which is the DMA buffer\naddress returned by DMA mapping call. stmmac_tx_clean() will try to\nunmap the DMA buffer _ONLY_IF_ tx_q-\u003etx_skbuff_dma[entry].buf\nis a valid buffer address.\n\nThe expected behavior that saves DMA buffer address of this non-paged\ndata to tx_q-\u003etx_skbuff_dma[entry].buf is:\n tx_q-\u003etx_skbuff_dma[N + 0].buf = NULL;\n tx_q-\u003etx_skbuff_dma[N + 1].buf = NULL;\n tx_q-\u003etx_skbuff_dma[N + 2].buf = dma_map_single();\nUnfortunately, the current code misbehaves like this:\n tx_q-\u003etx_skbuff_dma[N + 0].buf = dma_map_single();\n tx_q-\u003etx_skbuff_dma[N + 1].buf = NULL;\n tx_q-\u003etx_skbuff_dma[N + 2].buf = NULL;\n\nOn the stmmac_tx_clean() side, when dma_desc[N + 0] is closed by the\nDMA engine, tx_q-\u003etx_skbuff_dma[N + 0].buf is a valid buffer address\nobviously, then the DMA buffer will be unmapped immediately.\nThere may be a rare case that the DMA engine does not finish the\npending dma_desc[N + 1], dma_desc[N + 2] yet. Now things will go\nhorribly wrong, DMA is going to access a unmapped/unreferenced memory\nregion, corrupted data will be transmited or iommu fault will be\ntriggered :(\n\nIn contrast, the for-loop that maps SKB fragments behaves perfectly\nas expected, and that is how the driver should do for both non-paged\ndata and paged frags actually.\n\nThis patch corrects DMA map/unmap sequences by fixing the array index\nfor tx_q-\u003etx_skbuff_dma[entry].buf when assigning DMA buffer address.\n\nTested and verified on DWXGMAC CORE 3.20a", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53058", "url": "https://www.suse.com/security/cve/CVE-2024-53058" }, { "category": "external", "summary": "SUSE Bug 1233552 for CVE-2024-53058", "url": "https://bugzilla.suse.com/1233552" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53058" }, { "cve": "CVE-2024-53059", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53059" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd()\n\n1. The size of the response packet is not validated.\n2. The response buffer is not freed.\n\nResolve these issues by switching to iwl_mvm_send_cmd_status(),\nwhich handles both size validation and frees the buffer.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53059", "url": "https://www.suse.com/security/cve/CVE-2024-53059" }, { "category": "external", "summary": "SUSE Bug 1233553 for CVE-2024-53059", "url": "https://bugzilla.suse.com/1233553" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53059" }, { "cve": "CVE-2024-53060", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53060" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: prevent NULL pointer dereference if ATIF is not supported\n\nacpi_evaluate_object() may return AE_NOT_FOUND (failure), which\nwould result in dereferencing buffer.pointer (obj) while being NULL.\n\nAlthough this case may be unrealistic for the current code, it is\nstill better to protect against possible bugs.\n\nBail out also when status is AE_NOT_FOUND.\n\nThis fixes 1 FORWARD_NULL issue reported by Coverity\nReport: CID 1600951: Null pointer dereferences (FORWARD_NULL)\n\n(cherry picked from commit 91c9e221fe2553edf2db71627d8453f083de87a1)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53060", "url": "https://www.suse.com/security/cve/CVE-2024-53060" }, { "category": "external", "summary": "SUSE Bug 1233554 for CVE-2024-53060", "url": "https://bugzilla.suse.com/1233554" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53060" }, { "cve": "CVE-2024-53061", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53061" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: s5p-jpeg: prevent buffer overflows\n\nThe current logic allows word to be less than 2. If this happens,\nthere will be buffer overflows, as reported by smatch. Add extra\nchecks to prevent it.\n\nWhile here, remove an unused word = 0 assignment.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53061", "url": "https://www.suse.com/security/cve/CVE-2024-53061" }, { "category": "external", "summary": "SUSE Bug 1233555 for CVE-2024-53061", "url": "https://bugzilla.suse.com/1233555" }, { "category": "external", "summary": "SUSE Bug 1233621 for CVE-2024-53061", "url": "https://bugzilla.suse.com/1233621" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-53061" }, { "cve": "CVE-2024-53063", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53063" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvbdev: prevent the risk of out of memory access\n\nThe dvbdev contains a static variable used to store dvb minors.\n\nThe behavior of it depends if CONFIG_DVB_DYNAMIC_MINORS is set\nor not. When not set, dvb_register_device() won\u0027t check for\nboundaries, as it will rely that a previous call to\ndvb_register_adapter() would already be enforcing it.\n\nOn a similar way, dvb_device_open() uses the assumption\nthat the register functions already did the needed checks.\n\nThis can be fragile if some device ends using different\ncalls. This also generate warnings on static check analysers\nlike Coverity.\n\nSo, add explicit guards to prevent potential risk of OOM issues.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53063", "url": "https://www.suse.com/security/cve/CVE-2024-53063" }, { "category": "external", "summary": "SUSE Bug 1225742 for CVE-2024-53063", "url": "https://bugzilla.suse.com/1225742" }, { "category": "external", "summary": "SUSE Bug 1233557 for CVE-2024-53063", "url": "https://bugzilla.suse.com/1233557" }, { "category": "external", "summary": "SUSE Bug 1233619 for CVE-2024-53063", "url": "https://bugzilla.suse.com/1233619" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-53063" }, { "cve": "CVE-2024-53066", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53066" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfs: Fix KMSAN warning in decode_getfattr_attrs()\n\nFix the following KMSAN warning:\n\nCPU: 1 UID: 0 PID: 7651 Comm: cp Tainted: G B\nTainted: [B]=BAD_PAGE\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009)\n=====================================================\n=====================================================\nBUG: KMSAN: uninit-value in decode_getfattr_attrs+0x2d6d/0x2f90\n decode_getfattr_attrs+0x2d6d/0x2f90\n decode_getfattr_generic+0x806/0xb00\n nfs4_xdr_dec_getattr+0x1de/0x240\n rpcauth_unwrap_resp_decode+0xab/0x100\n rpcauth_unwrap_resp+0x95/0xc0\n call_decode+0x4ff/0xb50\n __rpc_execute+0x57b/0x19d0\n rpc_execute+0x368/0x5e0\n rpc_run_task+0xcfe/0xee0\n nfs4_proc_getattr+0x5b5/0x990\n __nfs_revalidate_inode+0x477/0xd00\n nfs_access_get_cached+0x1021/0x1cc0\n nfs_do_access+0x9f/0xae0\n nfs_permission+0x1e4/0x8c0\n inode_permission+0x356/0x6c0\n link_path_walk+0x958/0x1330\n path_lookupat+0xce/0x6b0\n filename_lookup+0x23e/0x770\n vfs_statx+0xe7/0x970\n vfs_fstatat+0x1f2/0x2c0\n __se_sys_newfstatat+0x67/0x880\n __x64_sys_newfstatat+0xbd/0x120\n x64_sys_call+0x1826/0x3cf0\n do_syscall_64+0xd0/0x1b0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nThe KMSAN warning is triggered in decode_getfattr_attrs(), when calling\ndecode_attr_mdsthreshold(). It appears that fattr-\u003emdsthreshold is not\ninitialized.\n\nFix the issue by initializing fattr-\u003emdsthreshold to NULL in\nnfs_fattr_init().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53066", "url": "https://www.suse.com/security/cve/CVE-2024-53066" }, { "category": "external", "summary": "SUSE Bug 1233560 for CVE-2024-53066", "url": "https://bugzilla.suse.com/1233560" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53066" }, { "cve": "CVE-2024-53068", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53068" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier()\n\nThe scmi_dev-\u003ename is released prematurely in __scmi_device_destroy(),\nwhich causes slab-use-after-free when accessing scmi_dev-\u003ename in\nscmi_bus_notifier(). So move the release of scmi_dev-\u003ename to\nscmi_device_release() to avoid slab-use-after-free.\n\n | BUG: KASAN: slab-use-after-free in strncmp+0xe4/0xec\n | Read of size 1 at addr ffffff80a482bcc0 by task swapper/0/1\n |\n | CPU: 1 PID: 1 Comm: swapper/0 Not tainted 6.6.38-debug #1\n | Hardware name: Qualcomm Technologies, Inc. SA8775P Ride (DT)\n | Call trace:\n | dump_backtrace+0x94/0x114\n | show_stack+0x18/0x24\n | dump_stack_lvl+0x48/0x60\n | print_report+0xf4/0x5b0\n | kasan_report+0xa4/0xec\n | __asan_report_load1_noabort+0x20/0x2c\n | strncmp+0xe4/0xec\n | scmi_bus_notifier+0x5c/0x54c\n | notifier_call_chain+0xb4/0x31c\n | blocking_notifier_call_chain+0x68/0x9c\n | bus_notify+0x54/0x78\n | device_del+0x1bc/0x840\n | device_unregister+0x20/0xb4\n | __scmi_device_destroy+0xac/0x280\n | scmi_device_destroy+0x94/0xd0\n | scmi_chan_setup+0x524/0x750\n | scmi_probe+0x7fc/0x1508\n | platform_probe+0xc4/0x19c\n | really_probe+0x32c/0x99c\n | __driver_probe_device+0x15c/0x3c4\n | driver_probe_device+0x5c/0x170\n | __driver_attach+0x1c8/0x440\n | bus_for_each_dev+0xf4/0x178\n | driver_attach+0x3c/0x58\n | bus_add_driver+0x234/0x4d4\n | driver_register+0xf4/0x3c0\n | __platform_driver_register+0x60/0x88\n | scmi_driver_init+0xb0/0x104\n | do_one_initcall+0xb4/0x664\n | kernel_init_freeable+0x3c8/0x894\n | kernel_init+0x24/0x1e8\n | ret_from_fork+0x10/0x20\n |\n | Allocated by task 1:\n | kasan_save_stack+0x2c/0x54\n | kasan_set_track+0x2c/0x40\n | kasan_save_alloc_info+0x24/0x34\n | __kasan_kmalloc+0xa0/0xb8\n | __kmalloc_node_track_caller+0x6c/0x104\n | kstrdup+0x48/0x84\n | kstrdup_const+0x34/0x40\n | __scmi_device_create.part.0+0x8c/0x408\n | scmi_device_create+0x104/0x370\n | scmi_chan_setup+0x2a0/0x750\n | scmi_probe+0x7fc/0x1508\n | platform_probe+0xc4/0x19c\n | really_probe+0x32c/0x99c\n | __driver_probe_device+0x15c/0x3c4\n | driver_probe_device+0x5c/0x170\n | __driver_attach+0x1c8/0x440\n | bus_for_each_dev+0xf4/0x178\n | driver_attach+0x3c/0x58\n | bus_add_driver+0x234/0x4d4\n | driver_register+0xf4/0x3c0\n | __platform_driver_register+0x60/0x88\n | scmi_driver_init+0xb0/0x104\n | do_one_initcall+0xb4/0x664\n | kernel_init_freeable+0x3c8/0x894\n | kernel_init+0x24/0x1e8\n | ret_from_fork+0x10/0x20\n |\n | Freed by task 1:\n | kasan_save_stack+0x2c/0x54\n | kasan_set_track+0x2c/0x40\n | kasan_save_free_info+0x38/0x5c\n | __kasan_slab_free+0xe8/0x164\n | __kmem_cache_free+0x11c/0x230\n | kfree+0x70/0x130\n | kfree_const+0x20/0x40\n | __scmi_device_destroy+0x70/0x280\n | scmi_device_destroy+0x94/0xd0\n | scmi_chan_setup+0x524/0x750\n | scmi_probe+0x7fc/0x1508\n | platform_probe+0xc4/0x19c\n | really_probe+0x32c/0x99c\n | __driver_probe_device+0x15c/0x3c4\n | driver_probe_device+0x5c/0x170\n | __driver_attach+0x1c8/0x440\n | bus_for_each_dev+0xf4/0x178\n | driver_attach+0x3c/0x58\n | bus_add_driver+0x234/0x4d4\n | driver_register+0xf4/0x3c0\n | __platform_driver_register+0x60/0x88\n | scmi_driver_init+0xb0/0x104\n | do_one_initcall+0xb4/0x664\n | kernel_init_freeable+0x3c8/0x894\n | kernel_init+0x24/0x1e8\n | ret_from_fork+0x10/0x20", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53068", "url": "https://www.suse.com/security/cve/CVE-2024-53068" }, { "category": "external", "summary": "SUSE Bug 1233561 for CVE-2024-53068", "url": "https://bugzilla.suse.com/1233561" }, { "category": "external", "summary": "SUSE Bug 1233618 for CVE-2024-53068", "url": "https://bugzilla.suse.com/1233618" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-53068" }, { "cve": "CVE-2024-53072", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53072" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Detect when STB is not available\n\nLoading the amd_pmc module as:\n\n amd_pmc enable_stb=1\n\n...can result in the following messages in the kernel ring buffer:\n\n amd_pmc AMDI0009:00: SMU cmd failed. err: 0xff\n ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff\n WARNING: CPU: 10 PID: 2151 at arch/x86/mm/ioremap.c:217 __ioremap_caller+0x2cd/0x340\n\nFurther debugging reveals that this occurs when the requests for\nS2D_PHYS_ADDR_LOW and S2D_PHYS_ADDR_HIGH return a value of 0,\nindicating that the STB is inaccessible. To prevent the ioremap\nwarning and provide clarity to the user, handle the invalid address\nand display an error message.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53072", "url": "https://www.suse.com/security/cve/CVE-2024-53072" }, { "category": "external", "summary": "SUSE Bug 1233564 for CVE-2024-53072", "url": "https://bugzilla.suse.com/1233564" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53072" }, { "cve": "CVE-2024-53074", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53074" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: don\u0027t leak a link on AP removal\n\nRelease the link mapping resource in AP removal. This impacted devices\nthat do not support the MLD API (9260 and down).\nOn those devices, we couldn\u0027t start the AP again after the AP has been\nalready started and stopped.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53074", "url": "https://www.suse.com/security/cve/CVE-2024-53074" }, { "category": "external", "summary": "SUSE Bug 1233566 for CVE-2024-53074", "url": "https://bugzilla.suse.com/1233566" }, { "category": "external", "summary": "SUSE Bug 1235086 for CVE-2024-53074", "url": "https://bugzilla.suse.com/1235086" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-53074" }, { "cve": "CVE-2024-53076", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53076" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: gts-helper: Fix memory leaks for the error path of iio_gts_build_avail_scale_table()\n\nIf per_time_scales[i] or per_time_gains[i] kcalloc fails in the for loop\nof iio_gts_build_avail_scale_table(), the err_free_out will fail to call\nkfree() each time when i is reduced to 0, so all the per_time_scales[0]\nand per_time_gains[0] will not be freed, which will cause memory leaks.\n\nFix it by checking if i \u003e= 0.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53076", "url": "https://www.suse.com/security/cve/CVE-2024-53076" }, { "category": "external", "summary": "SUSE Bug 1233567 for CVE-2024-53076", "url": "https://bugzilla.suse.com/1233567" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53076" }, { "cve": "CVE-2024-53079", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53079" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/thp: fix deferred split unqueue naming and locking\n\nRecent changes are putting more pressure on THP deferred split queues:\nunder load revealing long-standing races, causing list_del corruptions,\n\"Bad page state\"s and worse (I keep BUGs in both of those, so usually\ndon\u0027t get to see how badly they end up without). The relevant recent\nchanges being 6.8\u0027s mTHP, 6.10\u0027s mTHP swapout, and 6.12\u0027s mTHP swapin,\nimproved swap allocation, and underused THP splitting.\n\nBefore fixing locking: rename misleading folio_undo_large_rmappable(),\nwhich does not undo large_rmappable, to folio_unqueue_deferred_split(),\nwhich is what it does. But that and its out-of-line __callee are mm\ninternals of very limited usability: add comment and WARN_ON_ONCEs to\ncheck usage; and return a bool to say if a deferred split was unqueued,\nwhich can then be used in WARN_ON_ONCEs around safety checks (sparing\ncallers the arcane conditionals in __folio_unqueue_deferred_split()).\n\nJust omit the folio_unqueue_deferred_split() from free_unref_folios(), all\nof whose callers now call it beforehand (and if any forget then bad_page()\nwill tell) - except for its caller put_pages_list(), which itself no\nlonger has any callers (and will be deleted separately).\n\nSwapout: mem_cgroup_swapout() has been resetting folio-\u003ememcg_data 0\nwithout checking and unqueueing a THP folio from deferred split list;\nwhich is unfortunate, since the split_queue_lock depends on the memcg\n(when memcg is enabled); so swapout has been unqueueing such THPs later,\nwhen freeing the folio, using the pgdat\u0027s lock instead: potentially\ncorrupting the memcg\u0027s list. __remove_mapping() has frozen refcount to 0\nhere, so no problem with calling folio_unqueue_deferred_split() before\nresetting memcg_data.\n\nThat goes back to 5.4 commit 87eaceb3faa5 (\"mm: thp: make deferred split\nshrinker memcg aware\"): which included a check on swapcache before adding\nto deferred queue, but no check on deferred queue before adding THP to\nswapcache. That worked fine with the usual sequence of events in reclaim\n(though there were a couple of rare ways in which a THP on deferred queue\ncould have been swapped out), but 6.12 commit dafff3f4c850 (\"mm: split\nunderused THPs\") avoids splitting underused THPs in reclaim, which makes\nswapcache THPs on deferred queue commonplace.\n\nKeep the check on swapcache before adding to deferred queue? Yes: it is\nno longer essential, but preserves the existing behaviour, and is likely\nto be a worthwhile optimization (vmstat showed much more traffic on the\nqueue under swapping load if the check was removed); update its comment.\n\nMemcg-v1 move (deprecated): mem_cgroup_move_account() has been changing\nfolio-\u003ememcg_data without checking and unqueueing a THP folio from the\ndeferred list, sometimes corrupting \"from\" memcg\u0027s list, like swapout. \nRefcount is non-zero here, so folio_unqueue_deferred_split() can only be\nused in a WARN_ON_ONCE to validate the fix, which must be done earlier:\nmem_cgroup_move_charge_pte_range() first try to split the THP (splitting\nof course unqueues), or skip it if that fails. Not ideal, but moving\ncharge has been requested, and khugepaged should repair the THP later:\nnobody wants new custom unqueueing code just for this deprecated case.\n\nThe 87eaceb3faa5 commit did have the code to move from one deferred list\nto another (but was not conscious of its unsafety while refcount non-0);\nbut that was removed by 5.6 commit fac0516b5534 (\"mm: thp: don\u0027t need care\ndeferred split queue in memcg charge move path\"), which argued that the\nexistence of a PMD mapping guarantees that the THP cannot be on a deferred\nlist. As above, false in rare cases, and now commonly false.\n\nBackport to 6.11 should be straightforward. Earlier backports must take\ncare that other _deferred_list fixes and dependencies are included. There\nis not a strong case for backports, but they can fix cornercases.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53079", "url": "https://www.suse.com/security/cve/CVE-2024-53079" }, { "category": "external", "summary": "SUSE Bug 1233570 for CVE-2024-53079", "url": "https://bugzilla.suse.com/1233570" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "low" } ], "title": "CVE-2024-53079" }, { "cve": "CVE-2024-53081", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53081" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ar0521: don\u0027t overflow when checking PLL values\n\nThe PLL checks are comparing 64 bit integers with 32 bit\nones, as reported by Coverity. Depending on the values of\nthe variables, this may underflow.\n\nFix it ensuring that both sides of the expression are u64.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53081", "url": "https://www.suse.com/security/cve/CVE-2024-53081" }, { "category": "external", "summary": "SUSE Bug 1233572 for CVE-2024-53081", "url": "https://bugzilla.suse.com/1233572" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53081" }, { "cve": "CVE-2024-53082", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53082" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Add hash_key_length check\n\nAdd hash_key_length check in virtnet_probe() to avoid possible out of\nbound errors when setting/reading the hash key.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53082", "url": "https://www.suse.com/security/cve/CVE-2024-53082" }, { "category": "external", "summary": "SUSE Bug 1233573 for CVE-2024-53082", "url": "https://bugzilla.suse.com/1233573" }, { "category": "external", "summary": "SUSE Bug 1233677 for CVE-2024-53082", "url": "https://bugzilla.suse.com/1233677" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-53082" }, { "cve": "CVE-2024-53085", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53085" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Lock TPM chip in tpm_pm_suspend() first\n\nSetting TPM_CHIP_FLAG_SUSPENDED in the end of tpm_pm_suspend() can be racy\naccording, as this leaves window for tpm_hwrng_read() to be called while\nthe operation is in progress. The recent bug report gives also evidence of\nthis behaviour.\n\nAadress this by locking the TPM chip before checking any chip-\u003eflags both\nin tpm_pm_suspend() and tpm_hwrng_read(). Move TPM_CHIP_FLAG_SUSPENDED\ncheck inside tpm_get_random() so that it will be always checked only when\nthe lock is reserved.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53085", "url": "https://www.suse.com/security/cve/CVE-2024-53085" }, { "category": "external", "summary": "SUSE Bug 1233577 for CVE-2024-53085", "url": "https://bugzilla.suse.com/1233577" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53085" }, { "cve": "CVE-2024-53088", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53088" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: fix race condition by adding filter\u0027s intermediate sync state\n\nFix a race condition in the i40e driver that leads to MAC/VLAN filters\nbecoming corrupted and leaking. Address the issue that occurs under\nheavy load when multiple threads are concurrently modifying MAC/VLAN\nfilters by setting mac and port VLAN.\n\n1. Thread T0 allocates a filter in i40e_add_filter() within\n i40e_ndo_set_vf_port_vlan().\n2. Thread T1 concurrently frees the filter in __i40e_del_filter() within\n i40e_ndo_set_vf_mac().\n3. Subsequently, i40e_service_task() calls i40e_sync_vsi_filters(), which\n refers to the already freed filter memory, causing corruption.\n\nReproduction steps:\n1. Spawn multiple VFs.\n2. Apply a concurrent heavy load by running parallel operations to change\n MAC addresses on the VFs and change port VLANs on the host.\n3. Observe errors in dmesg:\n\"Error I40E_AQ_RC_ENOSPC adding RX filters on VF XX,\n\tplease set promiscuous on manually for VF XX\".\n\nExact code for stable reproduction Intel can\u0027t open-source now.\n\nThe fix involves implementing a new intermediate filter state,\nI40E_FILTER_NEW_SYNC, for the time when a filter is on a tmp_add_list.\nThese filters cannot be deleted from the hash list directly but\nmust be removed using the full process.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53088", "url": "https://www.suse.com/security/cve/CVE-2024-53088" }, { "category": "external", "summary": "SUSE Bug 1233580 for CVE-2024-53088", "url": "https://bugzilla.suse.com/1233580" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53088" }, { "cve": "CVE-2024-53093", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53093" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-multipath: defer partition scanning\n\nWe need to suppress the partition scan from occuring within the\ncontroller\u0027s scan_work context. If a path error occurs here, the IO will\nwait until a path becomes available or all paths are torn down, but that\naction also occurs within scan_work, so it would deadlock. Defer the\npartion scan to a different context that does not block scan_work.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53093", "url": "https://www.suse.com/security/cve/CVE-2024-53093" }, { "category": "external", "summary": "SUSE Bug 1233640 for CVE-2024-53093", "url": "https://bugzilla.suse.com/1233640" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53093" }, { "cve": "CVE-2024-53094", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53094" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES\n\nWhile running ISER over SIW, the initiator machine encounters a warning\nfrom skb_splice_from_iter() indicating that a slab page is being used in\nsend_page. To address this, it is better to add a sendpage_ok() check\nwithin the driver itself, and if it returns 0, then MSG_SPLICE_PAGES flag\nshould be disabled before entering the network stack.\n\nA similar issue has been discussed for NVMe in this thread:\nhttps://lore.kernel.org/all/20240530142417.146696-1-ofir.gal@volumez.com/\n\n WARNING: CPU: 0 PID: 5342 at net/core/skbuff.c:7140 skb_splice_from_iter+0x173/0x320\n Call Trace:\n tcp_sendmsg_locked+0x368/0xe40\n siw_tx_hdt+0x695/0xa40 [siw]\n siw_qp_sq_process+0x102/0xb00 [siw]\n siw_sq_resume+0x39/0x110 [siw]\n siw_run_sq+0x74/0x160 [siw]\n kthread+0xd2/0x100\n ret_from_fork+0x34/0x40\n ret_from_fork_asm+0x1a/0x30", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53094", "url": "https://www.suse.com/security/cve/CVE-2024-53094" }, { "category": "external", "summary": "SUSE Bug 1233641 for CVE-2024-53094", "url": "https://bugzilla.suse.com/1233641" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53094" }, { "cve": "CVE-2024-53095", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53095" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free of network namespace.\n\nRecently, we got a customer report that CIFS triggers oops while\nreconnecting to a server. [0]\n\nThe workload runs on Kubernetes, and some pods mount CIFS servers\nin non-root network namespaces. The problem rarely happened, but\nit was always while the pod was dying.\n\nThe root cause is wrong reference counting for network namespace.\n\nCIFS uses kernel sockets, which do not hold refcnt of the netns that\nthe socket belongs to. That means CIFS must ensure the socket is\nalways freed before its netns; otherwise, use-after-free happens.\n\nThe repro steps are roughly:\n\n 1. mount CIFS in a non-root netns\n 2. drop packets from the netns\n 3. destroy the netns\n 4. unmount CIFS\n\nWe can reproduce the issue quickly with the script [1] below and see\nthe splat [2] if CONFIG_NET_NS_REFCNT_TRACKER is enabled.\n\nWhen the socket is TCP, it is hard to guarantee the netns lifetime\nwithout holding refcnt due to async timers.\n\nLet\u0027s hold netns refcnt for each socket as done for SMC in commit\n9744d2bf1976 (\"smc: Fix use-after-free in tcp_write_timer_handler().\").\n\nNote that we need to move put_net() from cifs_put_tcp_session() to\nclean_demultiplex_info(); otherwise, __sock_create() still could touch a\nfreed netns while cifsd tries to reconnect from cifs_demultiplex_thread().\n\nAlso, maybe_get_net() cannot be put just before __sock_create() because\nthe code is not under RCU and there is a small chance that the same\naddress happened to be reallocated to another netns.\n\n[0]:\nCIFS: VFS: \\\\XXXXXXXXXXX has not responded in 15 seconds. Reconnecting...\nCIFS: Serverclose failed 4 times, giving up\nUnable to handle kernel paging request at virtual address 14de99e461f84a07\nMem abort info:\n ESR = 0x0000000096000004\n EC = 0x25: DABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x04: level 0 translation fault\nData abort info:\n ISV = 0, ISS = 0x00000004\n CM = 0, WnR = 0\n[14de99e461f84a07] address between user and kernel address ranges\nInternal error: Oops: 0000000096000004 [#1] SMP\nModules linked in: cls_bpf sch_ingress nls_utf8 cifs cifs_arc4 cifs_md4 dns_resolver tcp_diag inet_diag veth xt_state xt_connmark nf_conntrack_netlink xt_nat xt_statistic xt_MASQUERADE xt_mark xt_addrtype ipt_REJECT nf_reject_ipv4 nft_chain_nat nf_nat xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 xt_comment nft_compat nf_tables nfnetlink overlay nls_ascii nls_cp437 sunrpc vfat fat aes_ce_blk aes_ce_cipher ghash_ce sm4_ce_cipher sm4 sm3_ce sm3 sha3_ce sha512_ce sha512_arm64 sha1_ce ena button sch_fq_codel loop fuse configfs dmi_sysfs sha2_ce sha256_arm64 dm_mirror dm_region_hash dm_log dm_mod dax efivarfs\nCPU: 5 PID: 2690970 Comm: cifsd Not tainted 6.1.103-109.184.amzn2023.aarch64 #1\nHardware name: Amazon EC2 r7g.4xlarge/, BIOS 1.0 11/1/2018\npstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : fib_rules_lookup+0x44/0x238\nlr : __fib_lookup+0x64/0xbc\nsp : ffff8000265db790\nx29: ffff8000265db790 x28: 0000000000000000 x27: 000000000000bd01\nx26: 0000000000000000 x25: ffff000b4baf8000 x24: ffff00047b5e4580\nx23: ffff8000265db7e0 x22: 0000000000000000 x21: ffff00047b5e4500\nx20: ffff0010e3f694f8 x19: 14de99e461f849f7 x18: 0000000000000000\nx17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\nx14: 0000000000000000 x13: 0000000000000000 x12: 3f92800abd010002\nx11: 0000000000000001 x10: ffff0010e3f69420 x9 : ffff800008a6f294\nx8 : 0000000000000000 x7 : 0000000000000006 x6 : 0000000000000000\nx5 : 0000000000000001 x4 : ffff001924354280 x3 : ffff8000265db7e0\nx2 : 0000000000000000 x1 : ffff0010e3f694f8 x0 : ffff00047b5e4500\nCall trace:\n fib_rules_lookup+0x44/0x238\n __fib_lookup+0x64/0xbc\n ip_route_output_key_hash_rcu+0x2c4/0x398\n ip_route_output_key_hash+0x60/0x8c\n tcp_v4_connect+0x290/0x488\n __inet_stream_connect+0x108/0x3d0\n inet_stream_connect+0x50/0x78\n kernel_connect+0x6c/0xac\n generic_ip_conne\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53095", "url": "https://www.suse.com/security/cve/CVE-2024-53095" }, { "category": "external", "summary": "SUSE Bug 1233642 for CVE-2024-53095", "url": "https://bugzilla.suse.com/1233642" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53095" }, { "cve": "CVE-2024-53096", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53096" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: resolve faulty mmap_region() error path behaviour\n\nThe mmap_region() function is somewhat terrifying, with spaghetti-like\ncontrol flow and numerous means by which issues can arise and incomplete\nstate, memory leaks and other unpleasantness can occur.\n\nA large amount of the complexity arises from trying to handle errors late\nin the process of mapping a VMA, which forms the basis of recently\nobserved issues with resource leaks and observable inconsistent state.\n\nTaking advantage of previous patches in this series we move a number of\nchecks earlier in the code, simplifying things by moving the core of the\nlogic into a static internal function __mmap_region().\n\nDoing this allows us to perform a number of checks up front before we do\nany real work, and allows us to unwind the writable unmap check\nunconditionally as required and to perform a CONFIG_DEBUG_VM_MAPLE_TREE\nvalidation unconditionally also.\n\nWe move a number of things here:\n\n1. We preallocate memory for the iterator before we call the file-backed\n memory hook, allowing us to exit early and avoid having to perform\n complicated and error-prone close/free logic. We carefully free\n iterator state on both success and error paths.\n\n2. The enclosing mmap_region() function handles the mapping_map_writable()\n logic early. Previously the logic had the mapping_map_writable() at the\n point of mapping a newly allocated file-backed VMA, and a matching\n mapping_unmap_writable() on success and error paths.\n\n We now do this unconditionally if this is a file-backed, shared writable\n mapping. If a driver changes the flags to eliminate VM_MAYWRITE, however\n doing so does not invalidate the seal check we just performed, and we in\n any case always decrement the counter in the wrapper.\n\n We perform a debug assert to ensure a driver does not attempt to do the\n opposite.\n\n3. We also move arch_validate_flags() up into the mmap_region()\n function. This is only relevant on arm64 and sparc64, and the check is\n only meaningful for SPARC with ADI enabled. We explicitly add a warning\n for this arch if a driver invalidates this check, though the code ought\n eventually to be fixed to eliminate the need for this.\n\nWith all of these measures in place, we no longer need to explicitly close\nthe VMA on error paths, as we place all checks which might fail prior to a\ncall to any driver mmap hook.\n\nThis eliminates an entire class of errors, makes the code easier to reason\nabout and more robust.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53096", "url": "https://www.suse.com/security/cve/CVE-2024-53096" }, { "category": "external", "summary": "SUSE Bug 1233756 for CVE-2024-53096", "url": "https://bugzilla.suse.com/1233756" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53096" }, { "cve": "CVE-2024-53100", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53100" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: tcp: avoid race between queue_lock lock and destroy\n\nCommit 76d54bf20cdc (\"nvme-tcp: don\u0027t access released socket during\nerror recovery\") added a mutex_lock() call for the queue-\u003equeue_lock\nin nvme_tcp_get_address(). However, the mutex_lock() races with\nmutex_destroy() in nvme_tcp_free_queue(), and causes the WARN below.\n\nDEBUG_LOCKS_WARN_ON(lock-\u003emagic != lock)\nWARNING: CPU: 3 PID: 34077 at kernel/locking/mutex.c:587 __mutex_lock+0xcf0/0x1220\nModules linked in: nvmet_tcp nvmet nvme_tcp nvme_fabrics iw_cm ib_cm ib_core pktcdvd nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables qrtr sunrpc ppdev 9pnet_virtio 9pnet pcspkr netfs parport_pc parport e1000 i2c_piix4 i2c_smbus loop fuse nfnetlink zram bochs drm_vram_helper drm_ttm_helper ttm drm_kms_helper xfs drm sym53c8xx floppy nvme scsi_transport_spi nvme_core nvme_auth serio_raw ata_generic pata_acpi dm_multipath qemu_fw_cfg [last unloaded: ib_uverbs]\nCPU: 3 UID: 0 PID: 34077 Comm: udisksd Not tainted 6.11.0-rc7 #319\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014\nRIP: 0010:__mutex_lock+0xcf0/0x1220\nCode: 08 84 d2 0f 85 c8 04 00 00 8b 15 ef b6 c8 01 85 d2 0f 85 78 f4 ff ff 48 c7 c6 20 93 ee af 48 c7 c7 60 91 ee af e8 f0 a7 6d fd \u003c0f\u003e 0b e9 5e f4 ff ff 48 b8 00 00 00 00 00 fc ff df 4c 89 f2 48 c1\nRSP: 0018:ffff88811305f760 EFLAGS: 00010286\nRAX: 0000000000000000 RBX: ffff88812c652058 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000004 RDI: 0000000000000001\nRBP: ffff88811305f8b0 R08: 0000000000000001 R09: ffffed1075c36341\nR10: ffff8883ae1b1a0b R11: 0000000000010498 R12: 0000000000000000\nR13: 0000000000000000 R14: dffffc0000000000 R15: ffff88812c652058\nFS: 00007f9713ae4980(0000) GS:ffff8883ae180000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fcd78483c7c CR3: 0000000122c38000 CR4: 00000000000006f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \u003cTASK\u003e\n ? __warn.cold+0x5b/0x1af\n ? __mutex_lock+0xcf0/0x1220\n ? report_bug+0x1ec/0x390\n ? handle_bug+0x3c/0x80\n ? exc_invalid_op+0x13/0x40\n ? asm_exc_invalid_op+0x16/0x20\n ? __mutex_lock+0xcf0/0x1220\n ? nvme_tcp_get_address+0xc2/0x1e0 [nvme_tcp]\n ? __pfx___mutex_lock+0x10/0x10\n ? __lock_acquire+0xd6a/0x59e0\n ? nvme_tcp_get_address+0xc2/0x1e0 [nvme_tcp]\n nvme_tcp_get_address+0xc2/0x1e0 [nvme_tcp]\n ? __pfx_nvme_tcp_get_address+0x10/0x10 [nvme_tcp]\n nvme_sysfs_show_address+0x81/0xc0 [nvme_core]\n dev_attr_show+0x42/0x80\n ? __asan_memset+0x1f/0x40\n sysfs_kf_seq_show+0x1f0/0x370\n seq_read_iter+0x2cb/0x1130\n ? rw_verify_area+0x3b1/0x590\n ? __mutex_lock+0x433/0x1220\n vfs_read+0x6a6/0xa20\n ? lockdep_hardirqs_on+0x78/0x100\n ? __pfx_vfs_read+0x10/0x10\n ksys_read+0xf7/0x1d0\n ? __pfx_ksys_read+0x10/0x10\n ? __x64_sys_openat+0x105/0x1d0\n do_syscall_64+0x93/0x180\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? __pfx_ksys_read+0x10/0x10\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? do_syscall_64+0x9f/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f9713f55cfa\nCode: 55 48 89 e5 48 83 ec 20 48 89 55 e8 48 89 75 f0 89 7d f8 e8 e8 74 f8 ff 48 8b 55 e8 48 8b 75 f0 4\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53100", "url": "https://www.suse.com/security/cve/CVE-2024-53100" }, { "category": "external", "summary": "SUSE Bug 1233771 for CVE-2024-53100", "url": "https://bugzilla.suse.com/1233771" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53100" }, { "cve": "CVE-2024-53101", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53101" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: Fix uninitialized value issue in from_kuid and from_kgid\n\nocfs2_setattr() uses attr-\u003eia_mode, attr-\u003eia_uid and attr-\u003eia_gid in\na trace point even though ATTR_MODE, ATTR_UID and ATTR_GID aren\u0027t set.\n\nInitialize all fields of newattrs to avoid uninitialized variables, by\nchecking if ATTR_MODE, ATTR_UID, ATTR_GID are initialized, otherwise 0.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53101", "url": "https://www.suse.com/security/cve/CVE-2024-53101" }, { "category": "external", "summary": "SUSE Bug 1233769 for CVE-2024-53101", "url": "https://bugzilla.suse.com/1233769" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53101" }, { "cve": "CVE-2024-53104", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53104" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format\n\nThis can lead to out of bounds writes since frames of this type were not\ntaken into account when calculating the size of the frames buffer in\nuvc_parse_streaming.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53104", "url": "https://www.suse.com/security/cve/CVE-2024-53104" }, { "category": "external", "summary": "SUSE Bug 1234025 for CVE-2024-53104", "url": "https://bugzilla.suse.com/1234025" }, { "category": "external", "summary": "SUSE Bug 1236783 for CVE-2024-53104", "url": "https://bugzilla.suse.com/1236783" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "important" } ], "title": "CVE-2024-53104" }, { "cve": "CVE-2024-53106", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53106" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nima: fix buffer overrun in ima_eventdigest_init_common\n\nFunction ima_eventdigest_init() calls ima_eventdigest_init_common()\nwith HASH_ALGO__LAST which is then used to access the array\nhash_digest_size[] leading to buffer overrun. Have a conditional\nstatement to handle this.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53106", "url": "https://www.suse.com/security/cve/CVE-2024-53106" }, { "category": "external", "summary": "SUSE Bug 1234083 for CVE-2024-53106", "url": "https://bugzilla.suse.com/1234083" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53106" }, { "cve": "CVE-2024-53108", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53108" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Adjust VSDB parser for replay feature\n\nAt some point, the IEEE ID identification for the replay check in the\nAMD EDID was added. However, this check causes the following\nout-of-bounds issues when using KASAN:\n\n[ 27.804016] BUG: KASAN: slab-out-of-bounds in amdgpu_dm_update_freesync_caps+0xefa/0x17a0 [amdgpu]\n[ 27.804788] Read of size 1 at addr ffff8881647fdb00 by task systemd-udevd/383\n\n...\n\n[ 27.821207] Memory state around the buggy address:\n[ 27.821215] ffff8881647fda00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 27.821224] ffff8881647fda80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 27.821234] \u003effff8881647fdb00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 27.821243] ^\n[ 27.821250] ffff8881647fdb80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n[ 27.821259] ffff8881647fdc00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 27.821268] ==================================================================\n\nThis is caused because the ID extraction happens outside of the range of\nthe edid lenght. This commit addresses this issue by considering the\namd_vsdb_block size.\n\n(cherry picked from commit b7e381b1ccd5e778e3d9c44c669ad38439a861d8)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53108", "url": "https://www.suse.com/security/cve/CVE-2024-53108" }, { "category": "external", "summary": "SUSE Bug 1234081 for CVE-2024-53108", "url": "https://bugzilla.suse.com/1234081" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53108" }, { "cve": "CVE-2024-53110", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53110" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvp_vdpa: fix id_table array not null terminated error\n\nAllocate one extra virtio_device_id as null terminator, otherwise\nvdpa_mgmtdev_get_classes() may iterate multiple times and visit\nundefined memory.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53110", "url": "https://www.suse.com/security/cve/CVE-2024-53110" }, { "category": "external", "summary": "SUSE Bug 1234085 for CVE-2024-53110", "url": "https://bugzilla.suse.com/1234085" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53110" }, { "cve": "CVE-2024-53112", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53112" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: uncache inode which has failed entering the group\n\nSyzbot has reported the following BUG:\n\nkernel BUG at fs/ocfs2/uptodate.c:509!\n...\nCall Trace:\n \u003cTASK\u003e\n ? __die_body+0x5f/0xb0\n ? die+0x9e/0xc0\n ? do_trap+0x15a/0x3a0\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ? do_error_trap+0x1dc/0x2c0\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ? __pfx_do_error_trap+0x10/0x10\n ? handle_invalid_op+0x34/0x40\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ? exc_invalid_op+0x38/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? ocfs2_set_new_buffer_uptodate+0x2e/0x160\n ? ocfs2_set_new_buffer_uptodate+0x144/0x160\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ocfs2_group_add+0x39f/0x15a0\n ? __pfx_ocfs2_group_add+0x10/0x10\n ? __pfx_lock_acquire+0x10/0x10\n ? mnt_get_write_access+0x68/0x2b0\n ? __pfx_lock_release+0x10/0x10\n ? rcu_read_lock_any_held+0xb7/0x160\n ? __pfx_rcu_read_lock_any_held+0x10/0x10\n ? smack_log+0x123/0x540\n ? mnt_get_write_access+0x68/0x2b0\n ? mnt_get_write_access+0x68/0x2b0\n ? mnt_get_write_access+0x226/0x2b0\n ocfs2_ioctl+0x65e/0x7d0\n ? __pfx_ocfs2_ioctl+0x10/0x10\n ? smack_file_ioctl+0x29e/0x3a0\n ? __pfx_smack_file_ioctl+0x10/0x10\n ? lockdep_hardirqs_on_prepare+0x43d/0x780\n ? __pfx_lockdep_hardirqs_on_prepare+0x10/0x10\n ? __pfx_ocfs2_ioctl+0x10/0x10\n __se_sys_ioctl+0xfb/0x170\n do_syscall_64+0xf3/0x230\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n...\n \u003c/TASK\u003e\n\nWhen \u0027ioctl(OCFS2_IOC_GROUP_ADD, ...)\u0027 has failed for the particular\ninode in \u0027ocfs2_verify_group_and_input()\u0027, corresponding buffer head\nremains cached and subsequent call to the same \u0027ioctl()\u0027 for the same\ninode issues the BUG() in \u0027ocfs2_set_new_buffer_uptodate()\u0027 (trying\nto cache the same buffer head of that inode). Fix this by uncaching\nthe buffer head with \u0027ocfs2_remove_from_cache()\u0027 on error path in\n\u0027ocfs2_group_add()\u0027.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53112", "url": "https://www.suse.com/security/cve/CVE-2024-53112" }, { "category": "external", "summary": "SUSE Bug 1234087 for CVE-2024-53112", "url": "https://bugzilla.suse.com/1234087" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53112" }, { "cve": "CVE-2024-53114", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53114" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client\n\nA number of Zen4 client SoCs advertise the ability to use virtualized\nVMLOAD/VMSAVE, but using these instructions is reported to be a cause\nof a random host reboot.\n\nThese instructions aren\u0027t intended to be advertised on Zen4 client\nso clear the capability.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53114", "url": "https://www.suse.com/security/cve/CVE-2024-53114" }, { "category": "external", "summary": "SUSE Bug 1234072 for CVE-2024-53114", "url": "https://bugzilla.suse.com/1234072" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53114" }, { "cve": "CVE-2024-53121", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53121" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: fs, lock FTE when checking if active\n\nThe referenced commits introduced a two-step process for deleting FTEs:\n\n- Lock the FTE, delete it from hardware, set the hardware deletion function\n to NULL and unlock the FTE.\n- Lock the parent flow group, delete the software copy of the FTE, and\n remove it from the xarray.\n\nHowever, this approach encounters a race condition if a rule with the same\nmatch value is added simultaneously. In this scenario, fs_core may set the\nhardware deletion function to NULL prematurely, causing a panic during\nsubsequent rule deletions.\n\nTo prevent this, ensure the active flag of the FTE is checked under a lock,\nwhich will prevent the fs_core layer from attaching a new steering rule to\nan FTE that is in the process of deletion.\n\n[ 438.967589] MOSHE: 2496 mlx5_del_flow_rules del_hw_func\n[ 438.968205] ------------[ cut here ]------------\n[ 438.968654] refcount_t: decrement hit 0; leaking memory.\n[ 438.969249] WARNING: CPU: 0 PID: 8957 at lib/refcount.c:31 refcount_warn_saturate+0xfb/0x110\n[ 438.970054] Modules linked in: act_mirred cls_flower act_gact sch_ingress openvswitch nsh mlx5_vdpa vringh vhost_iotlb vdpa mlx5_ib mlx5_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm ib_uverbs ib_core zram zsmalloc fuse [last unloaded: cls_flower]\n[ 438.973288] CPU: 0 UID: 0 PID: 8957 Comm: tc Not tainted 6.12.0-rc1+ #8\n[ 438.973888] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 438.974874] RIP: 0010:refcount_warn_saturate+0xfb/0x110\n[ 438.975363] Code: 40 66 3b 82 c6 05 16 e9 4d 01 01 e8 1f 7c a0 ff 0f 0b c3 cc cc cc cc 48 c7 c7 10 66 3b 82 c6 05 fd e8 4d 01 01 e8 05 7c a0 ff \u003c0f\u003e 0b c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 90\n[ 438.976947] RSP: 0018:ffff888124a53610 EFLAGS: 00010286\n[ 438.977446] RAX: 0000000000000000 RBX: ffff888119d56de0 RCX: 0000000000000000\n[ 438.978090] RDX: ffff88852c828700 RSI: ffff88852c81b3c0 RDI: ffff88852c81b3c0\n[ 438.978721] RBP: ffff888120fa0e88 R08: 0000000000000000 R09: ffff888124a534b0\n[ 438.979353] R10: 0000000000000001 R11: 0000000000000001 R12: ffff888119d56de0\n[ 438.979979] R13: ffff888120fa0ec0 R14: ffff888120fa0ee8 R15: ffff888119d56de0\n[ 438.980607] FS: 00007fe6dcc0f800(0000) GS:ffff88852c800000(0000) knlGS:0000000000000000\n[ 438.983984] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 438.984544] CR2: 00000000004275e0 CR3: 0000000186982001 CR4: 0000000000372eb0\n[ 438.985205] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 438.985842] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 438.986507] Call Trace:\n[ 438.986799] \u003cTASK\u003e\n[ 438.987070] ? __warn+0x7d/0x110\n[ 438.987426] ? refcount_warn_saturate+0xfb/0x110\n[ 438.987877] ? report_bug+0x17d/0x190\n[ 438.988261] ? prb_read_valid+0x17/0x20\n[ 438.988659] ? handle_bug+0x53/0x90\n[ 438.989054] ? exc_invalid_op+0x14/0x70\n[ 438.989458] ? asm_exc_invalid_op+0x16/0x20\n[ 438.989883] ? refcount_warn_saturate+0xfb/0x110\n[ 438.990348] mlx5_del_flow_rules+0x2f7/0x340 [mlx5_core]\n[ 438.990932] __mlx5_eswitch_del_rule+0x49/0x170 [mlx5_core]\n[ 438.991519] ? mlx5_lag_is_sriov+0x3c/0x50 [mlx5_core]\n[ 438.992054] ? xas_load+0x9/0xb0\n[ 438.992407] mlx5e_tc_rule_unoffload+0x45/0xe0 [mlx5_core]\n[ 438.993037] mlx5e_tc_del_fdb_flow+0x2a6/0x2e0 [mlx5_core]\n[ 438.993623] mlx5e_flow_put+0x29/0x60 [mlx5_core]\n[ 438.994161] mlx5e_delete_flower+0x261/0x390 [mlx5_core]\n[ 438.994728] tc_setup_cb_destroy+0xb9/0x190\n[ 438.995150] fl_hw_destroy_filter+0x94/0xc0 [cls_flower]\n[ 438.995650] fl_change+0x11a4/0x13c0 [cls_flower]\n[ 438.996105] tc_new_tfilter+0x347/0xbc0\n[ 438.996503] ? __\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53121", "url": "https://www.suse.com/security/cve/CVE-2024-53121" }, { "category": "external", "summary": "SUSE Bug 1234078 for CVE-2024-53121", "url": "https://bugzilla.suse.com/1234078" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53121" }, { "cve": "CVE-2024-53138", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53138" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: kTLS, Fix incorrect page refcounting\n\nThe kTLS tx handling code is using a mix of get_page() and\npage_ref_inc() APIs to increment the page reference. But on the release\npath (mlx5e_ktls_tx_handle_resync_dump_comp()), only put_page() is used.\n\nThis is an issue when using pages from large folios: the get_page()\nreferences are stored on the folio page while the page_ref_inc()\nreferences are stored directly in the given page. On release the folio\npage will be dereferenced too many times.\n\nThis was found while doing kTLS testing with sendfile() + ZC when the\nserved file was read from NFS on a kernel with NFS large folios support\n(commit 49b29a573da8 (\"nfs: add support for large folios\")).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53138", "url": "https://www.suse.com/security/cve/CVE-2024-53138" }, { "category": "external", "summary": "SUSE Bug 1234223 for CVE-2024-53138", "url": "https://bugzilla.suse.com/1234223" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.20.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.20.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.20.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-12-13T15:24:02Z", "details": "moderate" } ], "title": "CVE-2024-53138" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…